RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-27311Criticalgibbon: Server side request forgery in gibbonCVE-2012-6685Highnokogiri: Nokogiri is vulnerable to XML External Entity (XXE) attackCVE-2012-6135Highpassenger: RubyGems passenger gem allows remote attackers to delete filesCVE-2011-1497Mediumactionpack: Cross site scripting in actionpack RubygemCVE-2022-29498Highblazer: SQL injection in blazerCVE-2022-25648Criticalgit: Command injection in ruby-gitGHSA-GX8X-G87M-H5Q6Highnokogiri: Denial of Service (DoS) in Nokogiri on JRubyGHSA-XXX9-3XCR-GJJ3Mediumnokogiri: XML Injection in Xerces Java affects NokogiriGHSA-V6GP-9MMM-C6P5Highnokogiri: Out-of-bounds Write in zlib affects NokogiriCVE-2022-24836Highnokogiri: Nokogiri Inefficient Regular Expression ComplexityCVE-2021-43177Mediumdevise-two-factor: Improper one time password handling in devise-two-factorCVE-2022-24795Mediumyajl-ruby: Buffer Overflow in yajl-rubyCVE-2022-21223Highcocoapods-downloader: Command injection in cocoapods-downloaderCVE-2022-24440Highcocoapods-downloader: Command injection in cocoapods-downloaderCVE-2022-24803Criticalasciidoctor-include-ext: Command Injection vulnerability in asciidoctor-include-extCVE-2022-24790Criticalpuma: Puma vulnerable to HTTP Request SmugglingCVE-2018-25032Highnokogiri: Nokogiri affected by zlib's Out-of-bounds Write vulnerabilityCVE-2022-0759Highkubeclient: Improper Certificate Validation in kubeclientCVE-2021-3589Highforeman_ansible: Missing Authentication for Critical Function in Foreman AnsibleCVE-2022-21831Criticalactivestorage: Possible code injection vulnerability in Rails / Active StorageCVE-2024-22051Highcommonmarker: Integer overflow in cmark-gfm table parsing extension leads to heap memory corruptionCVE-2022-24722Highview_component: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in view_componentCVE-2022-24720Criticalimage_processing: Remote shell execution vulnerability in image_processingGHSA-FQ42-C5RG-92C2Highnokogiri: Vulnerable dependencies in NokogiriCVE-2014-0177Mediumgithub.com/github/hub: Hub Package Arbitrary File Overwrite

Stop the waste.
Protect your environment with Kodem.