RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-41182Mediumjquery-ui: XSS in the `altField` option of the Datepicker widget in jquery-uiCVE-2013-2512Criticalftpd: OS Command Injection in ftpdCVE-2021-41136Lowpuma: Puma with proxy which forwards LF characters as line endings could allow HTTP request smugglingCVE-2021-33575Criticalruby-jss: Remote code execution in ruby-jssCVE-2021-30151Mediumsidekiq: Cross-site Scripting in SidekiqCVE-2021-41098Highnokogiri: Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRubyCVE-2021-23435Highclearance: Clearance Gem Open Redirect VulnerabilityCVE-2021-39197Mediumbetter_errors: Older releases of better_errors open to Cross-Site Request Forgery attackCVE-2021-31799Highrdoc: Arbitrary Code Execution in RdocCVE-2021-22942Mediumactionpack: Open Redirect in ActionPackCVE-2021-28796Mediumqiita-markdown: Cross-Site Scripting in Qiita-MarkdownCVE-2021-28833Mediumqiita-markdown: qiita-markdown Cross-site Scripting vulnerabilityCVE-2021-32740Highaddressable: Regular Expression Denial of Service in Addressable templatesCVE-2021-35514Highnarou: Code injection in NarouCVE-2021-32823Mediumbindata: Potential Denial-of-Service in bindataCVE-2021-20259Highforeman_fog_proxmox: Exposure of Sensitive Information to an Unauthorized Actor in foreman_fog_proxmoxCVE-2021-33564Criticaldragonfly: Dragonfly contains remote code execution vulnerabilityCVE-2020-7671Highgoliath: HTTP Request Smuggling in goliathCVE-2020-7659Highreel: HTTP Request Smuggling in reelCVE-2020-13482Highem-http-request: Improper Certificate Validation in EM-HTTP-RequestCVE-2020-36327Highbundler: Dependency Confusion in BundlerCVE-2020-13163Highem-imap: Improper certificate validation in em-imapCVE-2021-29509Highpuma: Puma's Keepalive Connections Causing Denial Of ServiceGHSA-7RRM-V45F-JP64Mediumnokogiri: Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12CVE-2019-3881Highbundler: Insecure path handling in Bundler

Stop the waste.
Protect your environment with Kodem.