RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-4761Mediumpuppet: Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type serviceCVE-2013-5647Highsounder: Sounder Contains Arbitrary Command Execution VulnerabilityCVE-2013-5671Highdragonfly: Code injection in dragonfly gemCVE-2013-6414Mediumactionpack: actionpack Improper Input Validation vulnerabilityCVE-2013-6415Mediumactionpack: actionpack vulnerable to Cross-site ScriptingCVE-2013-6416Mediumactionpack: actionpack Cross-site Scripting vulnerabilityCVE-2013-6417Mediumactionpack: actionpack allows bypass of database-query restrictionsCVE-2013-6421Highsprout: sprout Arbitrary Code Execution vulnerabilityCVE-2013-6459Mediumwill_paginate: will_paginate Cross-site Scripting vulnerabilityCVE-2013-7086Highwebbynode: Webbynode Code Injection vulnerabilityCVE-2013-7111Mediumbio-basespace-sdk: Exposure of Sensitive Information in bio-basespace-sdkCVE-2013-7463Highaescrypt: Aescrypt does not sufficiently use random valuesCVE-2014-0036Mediumrbovirt: rbovirt uses the rest-client gem with SSL verification disabledCVE-2014-0080Mediumactiverecord: Array data injection vulnerability in activerecordCVE-2014-0081Mediumrails: Rails vulnerable to Cross-site ScriptingCVE-2014-0082Mediumactionpack: actionpack Improper Input Validation vulnerabilityCVE-2014-0130Highactionpack: actionpack Path Traversal vulnerabilityCVE-2014-1233Lowparatrooper-pingdom: Local API Login Credentials Disclosure in paratrooper-pingdomCVE-2014-1234Lowparatrooper-newrelic: Paratrooper-newrelic Exposes of Sensitive Information to an Unauthorized ActorCVE-2014-2322Higharabic-prawn: Arabic Prawn allows remote attackers to execute arbitrary commands via shell metacharactersCVE-2014-2538Mediumrack-ssl: rack-ssl Cross-site Scripting vulnerabilityCVE-2014-2888Highsfpagent: sfpagent Command Injection vulnerabilityCVE-2014-3248Mediumfacter: facter, hiera, mcollective-client, and puppet affected by untrusted search path vulnerabilityCVE-2014-3482Highactiverecord: SQL Injection in Active RecordCVE-2014-3483Highactiverecord: Active Record contains SQL Injection via improper range quoting

Stop the waste.
Protect your environment with Kodem.