rubygems
954 tracked vulnerabilities.
CVE-2013-4562
omniauth-facebook 1.4.1-1.5.0 - Cross-Site Request Forgery via State Parameter
May 13, 2014
EPSS 0.00
CVE-2013-5671
fog-dragonfly 0.8.2 - Remote Code Execution
May 12, 2014
EPSS 0.02
CVE-2013-7111
BaseSpace Ruby SDK 0.1.7 - Info Disclosure
Apr 29, 2014
EPSS 0.00
CVE-2013-2105
show_in_browser gem 0.0.3 - Symlink Attack via /tmp/browser.html
Apr 22, 2014
EPSS 0.00
CVE-2013-4413
wicked < 1.0.1 - Path Traversal via Step Parameter
Mar 11, 2014
EPSS 0.01
CVE-2013-2119
Phusion Passenger < 3.0.21 and 4.0.x < 4.0.5 - Denial of Service and Privilege Escalation via Temporary Config File
Jan 03, 2014
EPSS 0.00
CVE-2013-7249
Fat Free CRM <0.12.1 - Info Disclosure
Jan 02, 2014
EPSS 0.01
CVE-2013-7225
Fat Free CRM <0.12.1 - SQL Injection
Jan 02, 2014
EPSS 0.01
CVE-2013-7224
Fat Free CRM <0.12.1 - Info Disclosure
Jan 02, 2014
EPSS 0.01
CVE-2013-7223
Fat Free CRM < 0.12.1 - Cross-Site Request Forgery
Jan 02, 2014
EPSS 0.00
CVE-2013-7222
Fat Free CRM <0.12.1 - Info Disclosure
Jan 02, 2014
EPSS 0.01
CVE-2013-6459
will_paginate < 3.0.5 - Cross-Site Scripting via Pagination Links
Dec 31, 2013
EPSS 0.00
CVE-2013-7086
Webbynode <1.0.5.3 - Command Injection
Dec 19, 2013
EPSS 0.02
CVE-2013-6421
sprout 0.7.246 - OS Command Injection via Archive Filename or Path
Dec 12, 2013
EPSS 0.01
CVE-2013-1812
Fedora < 2.2.1 - Resource Management Error
Dec 12, 2013
EPSS 0.01
CVE-2013-4479
Sup < 0.13.2.1 and 0.14.x < 0.14.1.1 - Remote Code Execution via Email Attachment Content-Type
Dec 07, 2013
EPSS 0.01
CVE-2013-4478
sup < 0.13.2.1 and 0.14.x < 0.14.1.1 - Remote Code Execution via Email Attachment Filename
Dec 07, 2013
EPSS 0.00
CVE-2013-6417
Ruby on Rails 3.x < 3.2.16 and 4.x < 4.0.2 - SQL Query Manipulation via JSON Parameter Handling
Dec 07, 2013
EPSS 0.01
CVE-2013-6416
Ruby on Rails < 4.0.2 - Cross-Site Scripting via simple_format Helper
Dec 07, 2013
EPSS 0.00
CVE-2013-6415
Ruby on Rails < 3.2.16 and 4.x < 4.0.2 - Cross-Site Scripting via number_to_currency Helper Unit Parameter
Dec 07, 2013
EPSS 0.02
CVE-2013-6414
Ruby on Rails 3.x < 3.2.16 and 4.x < 4.0.2 - Denial of Service via Invalid MIME Type Header
Dec 07, 2013
EPSS 0.71
CVE-2013-4492
I18n < 0.6.5 - XSS
Dec 07, 2013
EPSS 0.00
CVE-2013-4491
Ruby on Rails 3.x < 3.2.16 and 4.x < 4.0.2 - Cross-Site Scripting via i18n Fallback String
Dec 07, 2013
EPSS 0.01
CVE-2013-4457
Cocaine gem 0.4.0-0.5.2 - OS Command Injection via Recursive Variable Interpolation
Nov 02, 2013
EPSS 0.00
CVE-2013-4363
RubyGems < 1.8.23.2, 1.8.24-1.8.26, 2.0.x < 2.0.10, 2.1.x < 2.1.5 - Denial of Service via Version Regex Backtracking
Oct 17, 2013
EPSS 0.01
Products
actionpack 63
rack 50
nokogiri 34
rubygems 25
rubygems-update 25
activerecord 23
puppet 23
activesupport 17
publify_core 15
passenger 14
rails-html-sanitizer 14
actionview 13
decidim 12
puma 12
camaleon_cms 11
fat_free_crm 11
rails 11
activestorage 10
ruby-saml 10
jquery-rails 9
openc3 8
rexml 8
bootstrap 7
bootstrap-sass 7
jquery-ui-rails 7
katello 7
lodash-rails 7
net-imap 7
spree 7
avo 6
Quick Filters