RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-26254Highomniauth-apple: omniauth-apple allows attacker to fake their email address during authenticationCVE-2020-26223Highspree_api: Authorization bypass in SpreeCVE-2020-26222Highdependabot-omnibus: Remote code execution in dependabot-core branch names when cloningCVE-2020-15240Highomniauth-auth0: Regression in JWT Signature ValidationCVE-2020-15269Highspree: Ensure that doorkeeper_token is valid when authenticating requests in API v2 callsCVE-2020-15237Mediumshrine: Possible timing attack in derivation_endpointGHSA-VP9C-FPXX-744VLowpersonnummer: personnummer/ruby vulnerable to Improper Input ValidationCVE-2020-15169Mediumactionview: XSS in Action ViewCVE-2012-6708Mediumjquery: Cross-Site Scripting in jqueryCVE-2015-4410Highmoped: Moped Rubygem Data Injection VulnerabilityCVE-2020-16254Mediumchartkick: CSS Injection in Chartkick gemCVE-2020-14001Criticalkramdown: Unintended read access in kramdown gemCVE-2020-16253Highpghero: PgHero gem allows CSRFCVE-2020-16252Mediumfield_test: Field Test CSRF vulnerabilityCVE-2020-15109Mediumsolidus_frontend: Ability to change order address without triggering address validations in solidusCVE-2020-15133Highfaye-websocket: Missing TLS certificate verification in faye-websocketCVE-2020-15134Highfaye: Missing TLS certificate verificationCVE-2020-10663Highjson: Unsafe object creation in json RubyGemCVE-2020-8203Highlodash: Prototype Pollution in lodashCVE-2020-8163Highactionview: Remote code execution via user-provided local names in ActionViewCVE-2020-8167Mediumactionview: CSRF Vulnerability in rails-ujsCVE-2020-8161Highrack: Directory traversal in Rack::Directory app bundled with RackCVE-2020-8185Mediumactionpack: Untrusted users can run pending migrations in production in RailsCVE-2020-8184Highrack: Rack allows Percent-encoded cookies to overwrite existing prefixed cookie namesCVE-2020-4054Highsanitize: Cross-site Scripting in Sanitize

Stop the waste.
Protect your environment with Kodem.