RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-23634Highpuma: Puma used with Rails may lead to Information ExposureCVE-2022-23633Highactionpack: Exposure of information in Action PackCVE-2022-0524Highpublify_core: Publify Business Logic ErrorsCVE-2022-23837Highsidekiq: Denial of service in sidekiqCVE-2021-41819Highcgi: Cookie Prefix Spoofing in CGI::Cookie.parseCVE-2021-22569Highcom.google.protobuf:protobuf-java: A potential Denial of Service issue in protobuf-javaCVE-2020-28500Mediumlodash: Regular Expression Denial of Service (ReDoS) in lodashCVE-2021-43846Mediumsolidus_frontend: CSRF forgery protection bypass in solidus_frontendCVE-2021-43840Mediummessage_bus: Path traversal when MessageBus::Diagnostics is enabledCVE-2021-41816Criticalcgi: Buffer overrun in CGI.escape_htmlCVE-2021-44528Mediumactionpack: actionpack Open Redirect in Host Authorization MiddlewareCVE-2021-28680Highdevise_masquerade: Improper Privilege Management in devise_masqueradeCVE-2021-43809Mediumbundler: Local Code Execution through Argument Injection via dash leading git url parameter in Gemfile.CVE-2021-43805Highsolidus_core: ReDos vulnerability on guest checkout email validationCVE-2021-27025Mediumpuppet: Silent Configuration Failure in Puppet AgentCVE-2021-27023Mediumpuppet: Unsafe HTTP Redirect in Puppet Agent and Puppet ServerCVE-2021-41275Criticalspree_auth_devise: Spree Auth Devise vulnerability allows for authentication bypass through CSRF weaknessGHSA-5629-8855-GF4GCriticalsolidus_core: Authentication Bypass by CSRF Weakness CVE-2021-41274Criticalsolidus_auth_devise: Authentication Bypass by CSRF WeaknessCVE-2021-41817Highdate: Regular expression denial of service vulnerability (ReDoS) in dateCVE-2021-41263Mediumrails_multisite: Rails Multisite secure/signed cookies share secrets between sites in a multi-site applicationCVE-2021-25973Mediumpublify_core: Publify `guest` role users can self-register even when the admin does not allow itCVE-2021-41186Mediumfluentd: ReDoS vulnerability in parser_apache2CVE-2021-41183Mediumjquery-ui: XSS in `*Text` options of the Datepicker widget in jquery-uiCVE-2021-41184Mediumjquery-ui: XSS in the `of` option of the `.position()` util in jquery-ui

Stop the waste.
Protect your environment with Kodem.