RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2011-0995Lowsqlite3-ruby: sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privilegesCVE-2011-2197Mediumactionpack: rails Cross-site Scripting vulnerabilityCVE-2011-2929Mediumactionpack: actionpack Improper Input Validation vulnerabilityCVE-2011-2930Highactiverecord: activerecord vulnerable to SQL InjectionCVE-2011-2931Mediumactionpack: actionpack Cross-site Scripting vulnerabilityCVE-2011-2932Mediumactivesupport: activesupport Cross-site Scripting vulnerabilityCVE-2011-3186Mediumactionpack: actionpack CRLF injection vulnerabilityCVE-2011-3187Mediumactionpack: actionpack Improper Input Validation vulnerabilityCVE-2011-4319Mediumactionpack: Cross-site Scripting vulnerability in i18n translations helper methodCVE-2012-1098Mediumactivesupport: activesupport Cross-site Scripting vulnerabilityCVE-2012-1099Mediumactionpack: Cross-site Scripting in actionpackCVE-2012-1989Lowpuppet: Puppet allows local users to overwrite arbitrary files via a symlink attackCVE-2012-2139Mediummail: Mail Gem Path Traversal vulnerabilityCVE-2012-2140Highmail: Mail Gem Improper Input Validation vulnerabilityCVE-2012-2660Mediumactionpack: Action Pack contains database-query restrictions bypassCVE-2012-2661Mediumactiverecord: Active Record vulnerable to SQL Injection via nested query parametersCVE-2012-2694Mediumactionpack: actionpack allows remote attackers to bypass database-query restrictions, perform NULL checks via crafted requestCVE-2012-2695Highactiverecord: activerecord vulnerable to SQL InjectionCVE-2012-3408Lowpuppet: Puppet supports use of IP addresses in certnames without warning of potential risksCVE-2012-3424Mediumactionpack: actionpack Improper Authentication vulnerabilityCVE-2012-3463Mediumactionpack: actionpack Cross-site Scripting vulnerabilityCVE-2012-3464Mediumactivesupport: activesupport Cross-site Scripting vulnerabilityCVE-2012-3465Mediumactionpack: actionpack Cross-site Scripting vulnerabilityCVE-2012-3865Lowpuppet: Puppet vulnerable to Path TraversalCVE-2012-3866Lowpuppet: Puppet allows local users to obtain sensitive configuration information

Stop the waste.
Protect your environment with Kodem.