RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2014-3514Highactiverecord: Active Record subject to strong parameters protection bypassCVE-2014-7818Mediumactionpack: actionpack vulnerable to Path TraversalCVE-2014-7819Mediumsprockets: sprockets vulnerable to Path TraversalCVE-2014-7829Mediumactionpack: Directory traversal vulnerability in actionpackCVE-2014-9490Mediumsentry-raven: sentry-raven allows remote attackers to cause a denial of service via a large exponent value in a scientific numberCVE-2015-1840Mediumjquery-rails: jquery-rails and jquery-ujs subject to Exposure of Sensitive InformationCVE-2015-2963Mediumpaperclip: paperclip Cross-site Scripting vulnerabilityCVE-2015-3224Mediumweb-console: Web Console (Ruby gem) contains whitelisted_ips bypassCVE-2015-3225Mediumrack: Rack vulnerable to Denial of Service via large parameter depth requestCVE-2015-3226Mediumactivesupport: activesupport Cross-site Scripting vulnerabilityCVE-2015-3227Mediumactivesupport: activesupport vulnerable to Denial of Service via large XML document depthCVE-2015-3448Lowrest-client: rest-client allows local users to obtain sensitive information by reading the logCVE-2015-7541Criticalcolorscore: colorscore Command Injection vulnerabilityCVE-2015-7576Lowactionpack: actionpack is vulnerable to remote bypass authenticationCVE-2015-7577Mediumactiverecord: Active Record Improper Access ControlCVE-2015-7578Mediumrails-html-sanitizer: rails-html-sanitizer Cross-site Scripting vulnerabilityCVE-2015-7579Mediumrails-html-sanitizer: rails-html-sanitizer Cross-site Scripting vulnerabilityCVE-2015-7580Mediumrails-html-sanitizer: rails-html-sanitizer Cross-site Scripting vulnerabilityCVE-2015-7581Highactionpack: actionpack is vulnerable to denial of service because of a wildcard controller routeCVE-2015-8857Criticaluglify-js: Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-jsCVE-2015-9097Mediummail: Mail Gem CRLF Injection vulnerabilityCVE-2016-0751Highactionpack: actionpack is vulnerable to denial of service via a crafted HTTP Accept headerCVE-2016-0752Highactionview: Directory traversal vulnerability in Action View in Ruby on RailsCVE-2016-0753Mediumactivemodel: activemodel contains Improper Input ValidationCVE-2016-10173Higharchive-tar-minitar: archive-tar-minitar and minitar vulnerable to Path Traversal

Stop the waste.
Protect your environment with Kodem.