rubygems
954 tracked vulnerabilities.
CVE-2020-8185
MEDIUM
Rails 6.0.0-6.0.3.1 - Unauthenticated Denial of Service via Pending Migration Execution
Jul 02, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-8166
MEDIUM
rails < 5.2.5 and < 6.0.4 - Cross-Site Request Forgery via Per-Form Token Forgery
Jul 02, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-8163
HIGH
NUCLEI
Rails < 5.0.1 - Remote Code Execution via Render Locals Argument
Jul 02, 2020
CVSS 8.8
EPSS 0.91
CVE-2020-8161
HIGH
rack < 2.2.0 - Directory Traversal in Rack::Directory
Jul 02, 2020
CVSS 8.6
EPSS 0.01
CVE-2020-8167
MEDIUM
rails <= 6.0.3 - Cross-Site Request Forgery via rails-ujs Module
Jun 19, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-8165
CRITICAL
Rails <5.2.4.3-6.0.3.1 - Deserialization
Jun 19, 2020
CVSS 9.8
EPSS 0.90
CVE-2020-8184
HIGH
rack < 2.1.4 - Cookie Integrity Bypass via Unvalidated Prefix
Jun 19, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-8164
HIGH
Rails <5.2.4.3-6.0.3.1 - Info Disclosure
Jun 19, 2020
CVSS 7.5
EPSS 0.07
CVE-2020-8162
HIGH
Rails <5.2.4.2, <6.0.3.1 - Info Disclosure
Jun 19, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-4054
HIGH
sanitize 3.0.0-5.2.0 - Cross-Site Scripting via Relaxed Config Bypass
Jun 16, 2020
CVSS 7.3
EPSS 0.00
CVE-2020-7671
HIGH
goliath < 1.0.6 - HTTP Request Smuggling via Duplicate Content-Length Header
Jun 10, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7670
HIGH
agoo < 2.14.0 - HTTP Request Smuggling via Incorrect Content-Length and Transfer Encoding Parsing
Jun 10, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7663
HIGH
websocket-extensions < 0.1.5 - Denial of Service via Regex Backtracking in Header Parser
Jun 02, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-7659
HIGH
reel < 0.6.1 - HTTP Request Smuggling via Content-Length and Transfer Encoding Header Parsing
Jun 01, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-11082
MEDIUM
kaminari < 1.2.1 - Cross-Site Scripting via Pagination Links
May 28, 2020
CVSS 6.4
EPSS 0.00
CVE-2020-13482
HIGH
EM-HTTP-Request 1.1.5 - Man-in-the-Middle
May 25, 2020
CVSS 7.4
EPSS 0.00
CVE-2020-11077
MEDIUM
Puma 3.0.0-3.12.5 - HTTP Request Smuggling via Proxy Connection Reuse
May 22, 2020
CVSS 6.8
EPSS 0.01
CVE-2020-11076
HIGH
Puma 3.0.0-3.12.5 and 4.0.0-4.3.3 - HTTP Request Smuggling via Invalid Transfer-Encoding Header
May 22, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-13163
HIGH
em-imap 0.5 - Improper Certificate Validation
May 19, 2020
CVSS 7.4
EPSS 0.00
CVE-2020-7656
MEDIUM
jQuery < 1.9.0 - Cross-Site Scripting via Load Method
May 19, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-8159
CRITICAL
actionpack_page-caching < v1.2.1 - Code Injection
May 12, 2020
CVSS 9.8
EPSS 0.05
CVE-2020-8151
HIGH
Active Resource <v5.1.1 - Info Disclosure
May 12, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-11052
HIGH
Sorcery < 0.15.0 - Brute Force Protection Bypass via Expired Lockout
May 07, 2020
CVSS 8.3
EPSS 0.01
CVE-2020-10187
HIGH
Doorkeeper 5.0.0-5.0.3 - Unauthenticated Information Disclosure via OAuth Authorized Applications Endpoint
May 04, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-11022
MEDIUM
jQuery 1.12.0-3.4.1 - Cross-Site Scripting via DOM Manipulation Methods
Apr 29, 2020
CVSS 6.9
EPSS 0.02
Products
actionpack 63
rack 50
nokogiri 34
rubygems 25
rubygems-update 25
activerecord 23
puppet 23
activesupport 17
publify_core 15
passenger 14
rails-html-sanitizer 14
actionview 13
decidim 12
puma 12
camaleon_cms 11
fat_free_crm 11
rails 11
activestorage 10
ruby-saml 10
jquery-rails 9
openc3 8
rexml 8
bootstrap 7
bootstrap-sass 7
jquery-ui-rails 7
katello 7
lodash-rails 7
net-imap 7
spree 7
avo 6
Quick Filters