rubygems

954 tracked vulnerabilities.

CVE-2020-8185 MEDIUM
Rails 6.0.0-6.0.3.1 - Unauthenticated Denial of Service via Pending Migration Execution
Jul 02, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-8166 MEDIUM
rails < 5.2.5 and < 6.0.4 - Cross-Site Request Forgery via Per-Form Token Forgery
Jul 02, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-8163 HIGH NUCLEI
Rails < 5.0.1 - Remote Code Execution via Render Locals Argument
Jul 02, 2020
CVSS 8.8
EPSS 0.91
CVE-2020-8161 HIGH
rack < 2.2.0 - Directory Traversal in Rack::Directory
Jul 02, 2020
CVSS 8.6
EPSS 0.01
CVE-2020-8167 MEDIUM
rails <= 6.0.3 - Cross-Site Request Forgery via rails-ujs Module
Jun 19, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-8165 CRITICAL
Rails <5.2.4.3-6.0.3.1 - Deserialization
Jun 19, 2020
CVSS 9.8
EPSS 0.90
CVE-2020-8184 HIGH
rack < 2.1.4 - Cookie Integrity Bypass via Unvalidated Prefix
Jun 19, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-8164 HIGH
Rails <5.2.4.3-6.0.3.1 - Info Disclosure
Jun 19, 2020
CVSS 7.5
EPSS 0.07
CVE-2020-8162 HIGH
Rails <5.2.4.2, <6.0.3.1 - Info Disclosure
Jun 19, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-4054 HIGH
sanitize 3.0.0-5.2.0 - Cross-Site Scripting via Relaxed Config Bypass
Jun 16, 2020
CVSS 7.3
EPSS 0.00
CVE-2020-7671 HIGH
goliath < 1.0.6 - HTTP Request Smuggling via Duplicate Content-Length Header
Jun 10, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7670 HIGH
agoo < 2.14.0 - HTTP Request Smuggling via Incorrect Content-Length and Transfer Encoding Parsing
Jun 10, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7663 HIGH
websocket-extensions < 0.1.5 - Denial of Service via Regex Backtracking in Header Parser
Jun 02, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-7659 HIGH
reel < 0.6.1 - HTTP Request Smuggling via Content-Length and Transfer Encoding Header Parsing
Jun 01, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-11082 MEDIUM
kaminari < 1.2.1 - Cross-Site Scripting via Pagination Links
May 28, 2020
CVSS 6.4
EPSS 0.00
CVE-2020-13482 HIGH
EM-HTTP-Request 1.1.5 - Man-in-the-Middle
May 25, 2020
CVSS 7.4
EPSS 0.00
CVE-2020-11077 MEDIUM
Puma 3.0.0-3.12.5 - HTTP Request Smuggling via Proxy Connection Reuse
May 22, 2020
CVSS 6.8
EPSS 0.01
CVE-2020-11076 HIGH
Puma 3.0.0-3.12.5 and 4.0.0-4.3.3 - HTTP Request Smuggling via Invalid Transfer-Encoding Header
May 22, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-13163 HIGH
em-imap 0.5 - Improper Certificate Validation
May 19, 2020
CVSS 7.4
EPSS 0.00
CVE-2020-7656 MEDIUM
jQuery < 1.9.0 - Cross-Site Scripting via Load Method
May 19, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-8159 CRITICAL
actionpack_page-caching < v1.2.1 - Code Injection
May 12, 2020
CVSS 9.8
EPSS 0.05
CVE-2020-8151 HIGH
Active Resource <v5.1.1 - Info Disclosure
May 12, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-11052 HIGH
Sorcery < 0.15.0 - Brute Force Protection Bypass via Expired Lockout
May 07, 2020
CVSS 8.3
EPSS 0.01
CVE-2020-10187 HIGH
Doorkeeper 5.0.0-5.0.3 - Unauthenticated Information Disclosure via OAuth Authorized Applications Endpoint
May 04, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-11022 MEDIUM
jQuery 1.12.0-3.4.1 - Cross-Site Scripting via DOM Manipulation Methods
Apr 29, 2020
CVSS 6.9
EPSS 0.02