RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-23337Highlodash: Command Injection in lodashCVE-2021-28966Hightmpdir: Tempfile on Windows path traversal vulnerabilityCVE-2021-22904Highactionpack: Possible DoS Vulnerability in Action Controller Token AuthenticationCVE-2021-22885Highactionpack: Action Pack contains Information Disclosure / Unintended Method Execution vulnerabilityCVE-2021-22903Mediumactionpack: Possible Open Redirect Vulnerability in Action PackCVE-2021-22902Highactionpack: Denial of Service in Action DispatchCVE-2021-28965Highrexml: REXML round-trip instabilityCVE-2020-25739Mediumgon: Gon gem lack of escaping certain input when outputting as JSONCVE-2021-31671Highpgsync: Pgsync Contains Cleartext Transmission of Sensitive InformationCVE-2016-11086Highoauth: Improper Certificate Validation in oauth ruby gemCVE-2021-29435Hightrestle-auth: Cross-Site Request Forgery (CSRF) in trestle-authCVE-2020-24393Mediumtweetstream: Improper Certificate Validation in TweetStreamCVE-2020-7942Mediumpuppet: Improper Certificate Validation in PuppetCVE-2020-8264Mediumactionpack: Cross-site scripting in actionpackCVE-2021-28834Highkramdown: Remote code execution in KramdownCVE-2020-24392Mediumtwitter-stream: Improper Certificate Validation in twitter-streamCVE-2019-25025Mediumactiverecord-session_store: Activerecord-session_store Vulnerable to Timing AttackCVE-2021-22881Mediumactionpack: Actionpack Open Redirect Vulnerability CVE-2021-22880Highactiverecord: Active Record subject to Regular Expression Denial-of-Service (ReDoS)CVE-2021-21305Highcarrierwave: Code Injection vulnerability in CarrierWave::RMagickCVE-2021-21288Mediumcarrierwave: Server-side request forgery in CarrierWaveCVE-2021-21289Highmechanize: Command Injection Vulnerability in MechanizeCVE-2020-36190Mediumrails_admin: rails_admin ruby gem XSS vulnerabilityCVE-2020-26298Mediumredcarpet: Injection/XSS in RedcarpetCVE-2020-26247Mediumnokogiri: Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability

Stop the waste.
Protect your environment with Kodem.