RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2012-3867Mediumpuppet: Pupper does not properly restrict characters in Common Name field of Certificate Signing RequestCVE-2012-6109Mediumrack: Rack vulnerable to REDoSCVE-2012-6134Mediumomniauth-oauth2: omniauth-oauth2 Cross-Site Request Forgery vulnerabilityCVE-2012-6496Highactiverecord: Active Record contains SQL InjectionCVE-2012-6662Mediumjquery-ui: jquery-ui Tooltip widget vulnerable to XSSCVE-2012-6684Mediumredcloth: RedCloth Cross-site Scripting vulnerabilityCVE-2013-0155Mediumactiverecord: Active Record allows bypassing of database-query restrictionsCVE-2013-0156Highactionpack: actionpack Improper Input Validation vulnerabilityCVE-2013-0175Highmulti_xml: Improper Input Validation in multi_xmlCVE-2013-0183Mediumrack: Rack rubygems receiving excessively long lines triggers out-of-memory errorCVE-2013-0233Mediumdevise: Devise does not properly perform type conversion when performing database queriesCVE-2013-0256Mediumrdoc: RDoc contains XSS vulnerabilityCVE-2013-0262Mediumrack: Rack Vulnerable to Path TraversalCVE-2013-0269Highjson: JSON gem has Improper Input Validation vulnerabilityCVE-2013-0276Mediumactiverecord: ActiveRecord vulnerable to modification of protected model attributesCVE-2013-0277Criticalactiverecord: Active Record contains deserialization of arbitrary YAMLCVE-2013-0284Mediumnewrelic_rpm: newrelic_rpm Gem Discloses Sensitive InformationCVE-2013-0285Highnori: nori contains Improper Input ValidationCVE-2013-0333Highactivesupport: activesupport in Rails vulnerable to incorrect data conversionCVE-2013-1655Highpuppet: Puppet Improper Input Validation vulnerabilityCVE-2013-1656Mediumspree: Spree Improper Input Validation vulnerabilityCVE-2013-1756Highdragonfly: Dragonfly Code Injection vulnerabilityCVE-2013-1800Highcrack: crack does not properly restrict casts of string valuesCVE-2013-1801Highhttparty: HTTParty does not restrict casts of string valuesCVE-2013-1802Highextlib: extlib does not properly restrict casts of string values

Stop the waste.
Protect your environment with Kodem.