RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2015-3649Highopen-uri-cached: open-uri-cached Gem for Ruby Unsafe Temporary File Creation Enables Code ExecutionCVE-2017-1000026Highmixlib-archive: mixlib-archive Path Traversal vulnerabilityCVE-2018-14040Mediumbootstrap: Bootstrap vulnerable to Cross-Site Scripting (XSS)CVE-2017-10906Criticalfluentd: Fluentd Escape Sequence Injection VulnerabilityCVE-2016-2785Criticalpuppet: Puppet Improper Access ControlCVE-2018-18260Mediumcamaleon_cms: Camaleon CMS vulnerable to Stored Cross-site ScriptingCVE-2017-16932Highnokogiri: Nokogiri gem, via libxml, is affected by DoS vulnerabilitiesCVE-2013-0334Mediumbundler: Bundler may install gems from a different source than expectedCVE-2013-0263Mediumrack: Rack arbitrary code execution via timing attackCVE-2013-0184Mediumrack: Rack vulnerable to Denial of ServiceCVE-2013-0162Lowruby_parser: ruby_parser allows local users to overwrite arbitrary files via symlink attack on temporary file with predictable nameCVE-2013-1607Criticalpdfkit: PDFKit Improper Input Validation vulnerabilityCVE-2013-4318Mediumfeatures: Features file injection vulnerabilityCVE-2013-4593Highomniauth-facebook: omniauth-facebook Improper Authentication vulnerabilityCVE-2013-2095Criticalopenshift-origin-controller: RubyGem openshift-origin-controller is vulnerable to command injectionCVE-2013-6461Mediumnokogiri: Nokogiri vulnerable to DoS while parsing XML entitiesCVE-2013-6460Mediumnokogiri: Nokogiri vulnerable to DoS while parsing XML documentsCVE-2022-28481Criticalcsv-safe: CSV-Safe improperly filters special characters potentially leading to CSV injectionCVE-2022-29970Highsinatra: sinatra does not validate expanded path matchesCVE-2010-0156Lowpuppet: Puppet arbitrary files overwrite via a symlink attackCVE-2008-4310Highwebrick: WEBrick Denial of Service VulnerabilityCVE-2007-6612Mediummongrel: Mongrel vulnerable to directory traversal via double-encoded sequencesCVE-2007-0469Mediumrubygems-update: RubyGems file overwrite vulnerabilityCVE-2022-27777Mediumactionview: XSS Vulnerability in Action View tag helpersCVE-2022-22577Mediumactionpack: Cross-site Scripting Vulnerability in Action Pack

Stop the waste.
Protect your environment with Kodem.