rubygems

954 tracked vulnerabilities.

CVE-2019-1010191 CRITICAL
marginalia < 1.6.0 - SQL Injection via User Controller Argument
Jul 24, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-1010266 MEDIUM
lodash < 4.17.11 - Denial of Service via Date Handler Regular Expression
Jul 17, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-1010306 CRITICAL
Slanger < 0.6.1 - Unauthenticated Remote Code Execution via Deserialization
Jul 15, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-13589 CRITICAL
paranoid2 gem <1.1.6 - Code Injection
Jul 14, 2019
CVSS 9.8
EPSS 0.06
CVE-2019-13574 HIGH
MiniMagick < 4.9.4 - Remote Code Execution via Image.open Kernel#open Command Injection
Jul 12, 2019
CVSS 7.8
EPSS 0.29
CVE-2019-13146 MEDIUM
field_test 0.3.0 - Improper Input Validation
Jul 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-13354 CRITICAL
strong_password 0.0.7 - Remote Code Execution via Malicious Gem
Jul 08, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-13118 MEDIUM
libxslt 1.1.33 - Type Confusion in Number Formatting
Jul 01, 2019
CVSS 5.3
EPSS 0.01
CVE-2019-13117 MEDIUM
libxslt 1.1.33 - Information Disclosure via Uninitialized Read in xsltNumberFormatInsertNumbers
Jul 01, 2019
CVSS 5.3
EPSS 0.04
CVE-2019-8323 HIGH
RubyGems 2.6.0-3.0.2 - Escape Sequence Injection via API Response Output
Jun 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8322 HIGH
RubyGems 2.6.0-3.0.2 - Escape Sequence Injection via gem owner Command
Jun 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8321 HIGH
RubyGems 2.6.0-3.0.2 - Escape Sequence Injection via Gem::UserInteraction#verbose
Jun 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8325 HIGH
RubyGems 2.6.0-3.0.2 - Escape Sequence Injection via Error Message Handling
Jun 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8324 HIGH
RubyGems 2.6.0-3.0.2 - Remote Code Execution via Multi-Line Gem Name Injection
Jun 17, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-10226 MEDIUM
Fat Free CRM v0.19.0 - HTML Injection
Jun 10, 2019
CVSS 5.4
EPSS 0.02
CVE-2019-11027 CRITICAL
ruby-openid < 2.8.0 - Remote Code Execution
Jun 10, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-8320 HIGH
RubyGems 2.7.6-3.0.2 - Path Traversal via Symlink Deletion
Jun 06, 2019
CVSS 7.4
EPSS 0.06
CVE-2019-12732 MEDIUM
Chartkick < 3.1.0 - Cross-Site Scripting
Jun 06, 2019
CVSS 4.7
EPSS 0.00
CVE-2019-11358 MEDIUM
jQuery < 3.4.0 - Prototype Pollution via jQuery.extend
Apr 20, 2019
CVSS 6.1
EPSS 0.02
CVE-2019-11068 CRITICAL
libxslt <= 1.1.33 - Protection Mechanism Bypass via Crafted URL
Apr 10, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-10842 CRITICAL
bootstrap-sass 3.2.0.3 - Unauthenticated Remote Code Execution via ___cfduid Cookie
Apr 04, 2019
CVSS 9.8
EPSS 0.09
CVE-2019-5421 CRITICAL
Plataformatec Devise <4.5.0 - Info Disclosure
Apr 03, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-5420 CRITICAL
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
Mar 27, 2019
CVSS 9.8
EPSS 0.94
CVE-2019-5419 HIGH
Action View (Rails) <5.2.2.1-5.0.7.2 - DoS
Mar 27, 2019
CVSS 7.5
EPSS 0.12
CVE-2019-5418 HIGH KEVNUCLEI
Ruby On Rails File Content Disclosure (
Mar 27, 2019
CVSS 7.5
EPSS 0.94