RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-7981Criticalgeocoder: SQL Injection in GeocoderCVE-2020-7663Highwebsocket-extensions: Regular Expression Denial of Service in websocket-extensions (RubyGem)CVE-2020-11082Mediumkaminari: Cross-Site Scripting in KaminariCVE-2020-8166Mediumactionpack: Ability to forge per-form CSRF tokens in RailsCVE-2020-8162Highactivestorage: Circumvention of file size limits in ActiveStorageCVE-2020-8164Highactionpack: Possible Strong Parameters Bypass in ActionPackCVE-2020-8165Criticalactivesupport: ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStoreCVE-2020-11077Mediumpuma: HTTP Smuggling via Transfer-Encoding Header in PumaCVE-2020-11076Highpuma: HTTP Smuggling via Transfer-Encoding Header in PumaCVE-2020-8151Highactiveresource: Information disclosure issue in Active ResourceCVE-2020-7656Mediumjquery-rails: Cross-Site Scripting in jqueryCVE-2020-8159Criticalactionpack-page_caching: Arbitrary file write in actionpack-page_caching gemCVE-2020-11052Highsorcery: Improper Restriction of Excessive Authentication Attempts in SorceryCVE-2020-10187Highdoorkeeper: Exposure of Sensitive Information to an Unauthorized Actor in DoorkeeperCVE-2020-11023Mediumjquery: Potential XSS vulnerability in jQueryCVE-2020-11022Mediumjquery-rails: Potential XSS vulnerability in jQueryCVE-2020-11020Highfaye: Authentication and extension bypass in FayeCVE-2015-4411Highbson: BSON rubygem contains potential denial of serviceCVE-2020-5267Mediumactionview: Cross site scripting vulnerability in ActionViewCVE-2020-5257Highadministrate: Sort order SQL injection in AdministrateGHSA-PCQQ-5962-HVCWHighuser_agent_parser: Denial of Service in uap-core when processing crafted User-Agent stringsCVE-2020-5249Mediumpuma: HTTP Response Splitting (Early Hints) in PumaCVE-2020-8130Mediumrake: OS Command Injection in RakeCVE-2020-5247Mediumpuma: HTTP Response Splitting in PumaCVE-2020-7595Highnokogiri: libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation

Stop the waste.
Protect your environment with Kodem.