rubygems

954 tracked vulnerabilities.

CVE-2024-56733 MEDIUM
Password Pusher <1.50.3 - Info Disclosure
Dec 30, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-54133 LOW
Action Pack <7.0.8.7, <7.1.5.1, <7.2.2.1, <8.0.0.1 - XSS
Dec 10, 2024
EPSS 0.00
CVE-2024-53988 MEDIUM
rails-html-sanitizer 1.6.0 - Cross-Site Scripting via Allowed Math and Style Elements
Dec 02, 2024
CVSS 6.1
EPSS 0.02
CVE-2024-53987 MEDIUM
rails-html-sanitizer 1.6.0 - Cross-Site Scripting via Style Element Injection
Dec 02, 2024
CVSS 6.1
EPSS 0.02
CVE-2024-53986 MEDIUM
rails-html-sanitizer 1.6.0 - Cross-Site Scripting via HTML5 Sanitization with Allowed math and style Elements
Dec 02, 2024
CVSS 6.1
EPSS 0.03
CVE-2024-53985 MEDIUM
Rails::HTML::Sanitizer <1.16.8 - XSS
Dec 02, 2024
CVSS 6.1
EPSS 0.02
CVE-2024-53989 MEDIUM
rails-html-sanitizer 1.6.0 - Cross-Site Scripting via Noscript Tag Override
Dec 02, 2024
CVSS 6.1
EPSS 0.02
CVE-2024-52796 MEDIUM
Rubygems Pwpush < 1.49.0 - Resource Allocation Without Limits
Nov 20, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-45594 HIGH
Decidim 0.28.0-0.28.2 - Cross-Site Scripting via Meeting Embed URL
Nov 13, 2024
CVSS 7.7
EPSS 0.00
CVE-2024-43415 CRITICAL
decidim-decidim_awesome 0.9.1-0.10.2 and 0.11.0-0.11.1 - Authenticated SQL Injection in papertrail/version Model
Nov 12, 2024
CVSS 9.0
EPSS 0.00
CVE-2024-21510 MEDIUM
sinatra < 4.1.0 - Open Redirect via X-Forwarded-Host Header
Nov 01, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-49771 MEDIUM
MPXJ 8.3.5-13.5.0 - Path Traversal
Oct 28, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-49761 HIGH
REXML < 3.3.9 - Inefficient Regular Expression Complexity in Hex Numeric Character Reference Parsing
Oct 28, 2024
CVSS 7.5
EPSS 0.02
CVE-2024-49376 HIGH
Autolab <3.0.0 - Privilege Escalation
Oct 25, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-48652 MEDIUM
camaleon_cms 2.7.5 - Stored Cross-Site Scripting via Content Group Name Field
Oct 22, 2024
CVSS 4.8
EPSS 0.35
CVE-2024-47889 MEDIUM
Rubygems Actionmailer < 6.1.7.9 - Denial of Service
Oct 16, 2024
EPSS 0.00
CVE-2024-47888 MEDIUM
Rubygems Actiontext < 6.1.7.9 - Denial of Service
Oct 16, 2024
EPSS 0.00
CVE-2024-47887 MEDIUM
Rubygems Actionpack < 6.1.7.9 - Denial of Service
Oct 16, 2024
EPSS 0.00
CVE-2024-41128 MEDIUM
Rubygems Actionpack < 6.1.7.9 - Resource Allocation Without Limits
Oct 16, 2024
EPSS 0.01
CVE-2024-47529 MEDIUM
OpenC3 COSMOS < 5.19.0 - Cleartext Storage of Sensitive Information in LocalStorage
Oct 02, 2024
CVSS 6.5
EPSS 0.01
CVE-2024-46977 MEDIUM
OpenC3 COSMOS < 5.19.0 - Authenticated Path Traversal via LocalMode open_local_file
Oct 02, 2024
CVSS 6.5
EPSS 0.01
CVE-2024-43795 MEDIUM
OpenC3 COSMOS < 5.19.0 - Reflected Cross-Site Scripting in Login Functionality
Oct 02, 2024
CVSS 6.1
EPSS 0.02
CVE-2024-41673 HIGH
Decidim < 0.27.8 - Cross-Site Scripting via Malformed URL in Version Control Feature
Oct 01, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-46488 MEDIUM
sqlite-vec 0.1.1 - Heap-based Buffer Overflow via npy_token_next
Sep 25, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-47220
WEBrick toolkit <1.8.1 - HTTP Request Smuggling
Sep 22, 2024
EPSS 0.00