rubygems
954 tracked vulnerabilities.
CVE-2017-17718
MEDIUM
net-ldap < 0.16.0 - Improper Certificate Validation
Dec 17, 2017
CVSS 5.9
EPSS 0.00
CVE-2017-16355
MEDIUM
Phusion Passenger 5.1.10 - Info Disclosure
Dec 14, 2017
CVSS 4.7
EPSS 0.00
CVE-2017-10906
CRITICAL
Fluentd 0.12.29-0.12.40 - Escape Sequence Injection
Dec 08, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-17042
HIGH
YARD < 0.9.11 - Path Traversal via Relative Path Handling
Nov 28, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-16932
HIGH
libxml2 < 2.9.5 - Denial of Service via Infinite Recursion in Parameter Entities
Nov 23, 2017
CVSS 7.5
EPSS 0.22
CVE-2017-1000248
CRITICAL
Redis-store <=v1.3.0 - Info Disclosure
Nov 17, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-0909
CRITICAL
Private_address_check <0.4.1 - SSRF
Nov 16, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-16833
MEDIUM
gemirro < 0.16.0 - Stored Cross-Site Scripting via Crafted JavaScript URL in Gemspec Homepage
Nov 15, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-0905
CRITICAL
Recurly Client Ruby Library <2.0.13-2.11.3 - SSRF
Nov 13, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-0904
HIGH
Private_address_check <0.4.0 - SSRF
Nov 13, 2017
CVSS 8.1
EPSS 0.01
CVE-2017-0889
CRITICAL
Paperclip 3.1.4-5.1.9 - Server-Side Request Forgery via UriAdapter
Nov 13, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-16792
MEDIUM
geminabox < 0.13.10 - Stored Cross-Site Scripting via Gemspec Homepage Value
Nov 13, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-16516
HIGH
yajl-ruby 1.3.0 - Memory Corruption
Nov 03, 2017
CVSS 7.5
EPSS 0.02
CVE-2017-15928
HIGH
OX < 2.8.1 - Improper Input Validation
Oct 27, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-15364
MEDIUM
Ccsv - Use-After-Free in foreach Function
Oct 15, 2017
CVSS 5.5
EPSS 0.00
CVE-2017-0903
CRITICAL
RubyGems 2.0.0-2.6.13 - Remote Code Execution via YAML Deserialization
Oct 11, 2017
CVSS 9.8
EPSS 0.06
CVE-2017-14683
HIGH
geminabox < 0.13.7 - Cross-Site Request Forgery via Unintended Gem Upload
Sep 25, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-14506
MEDIUM
geminabox < 0.13.6 - Cross-Site Scripting via Crafted Gem Homepage Value
Sep 25, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-14033
HIGH
Ruby < 2.2.8, 2.3.x < 2.3.5, 2.4.x <= 2.4.1 - Denial of Service via OpenSSL::ASN1 Decode Method
Sep 19, 2017
CVSS 7.5
EPSS 0.08
CVE-2017-10784
HIGH
Ruby < 2.2.8, 2.3.x < 2.3.5, 2.4.x <= 2.4.1 - Command Injection via WEBrick Basic Authentication
Sep 19, 2017
CVSS 8.8
EPSS 0.02
CVE-2017-0902
HIGH
RubyGems < 2.6.12 - DNS Hijacking via MITM Attack
Aug 31, 2017
CVSS 8.1
EPSS 0.05
CVE-2017-0901
HIGH
RubyGems < 2.6.13 - Arbitrary File Write via Specification Name Validation Bypass
Aug 31, 2017
CVSS 7.5
EPSS 0.21
CVE-2017-0900
HIGH
RubyGems < 2.6.12 - Denial of Service via Malicious Gem Specification
Aug 31, 2017
CVSS 7.5
EPSS 0.14
CVE-2017-0899
CRITICAL
RubyGems < 2.6.13 - Terminal Escape Sequence Injection via Gem Specification
Aug 31, 2017
CVSS 9.8
EPSS 0.10
CVE-2017-7540
CRITICAL
rubygem-safemode <1.3.2 - Privilege Escalation
Jul 21, 2017
CVSS 9.8
EPSS 0.00
Products
actionpack 63
rack 50
nokogiri 34
rubygems 25
rubygems-update 25
activerecord 23
puppet 23
activesupport 17
publify_core 15
passenger 14
rails-html-sanitizer 14
actionview 13
decidim 12
puma 12
camaleon_cms 11
fat_free_crm 11
rails 11
activestorage 10
ruby-saml 10
jquery-rails 9
openc3 8
rexml 8
bootstrap 7
bootstrap-sass 7
jquery-ui-rails 7
katello 7
lodash-rails 7
net-imap 7
spree 7
avo 6
Quick Filters