Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nokogiri MEDIUM 6.6
CVE-2026-57438

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML:…

Fix: 1.19.4+
Fix from $1,600 2026-06-25
Nokogiri HIGH 7.5
CVE-2026-57435

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a R…

Fix: 1.19.4+
Fix from $1,950 2026-06-25
Nokogiri MEDIUM 5.3
CVE-2026-57436

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that…

Fix: 1.19.4+
Fix from $1,600 2026-06-25
Nokogiri MEDIUM 5.3
CVE-2026-57437

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its sour…

Fix: 1.19.4+
Fix from $1,600 2026-06-25
Nokogiri HIGH 8.2
CVE-2026-57235

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) …

Fix: 1.19.4+
Fix from $1,950 2026-06-25
Nokogiri HIGH 8.2
CVE-2026-57236

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encodi…

Fix: 1.19.4+
Fix from $1,950 2026-06-25
Nokogiri HIGH 7.5
CVE-2026-57434

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain meth…

Fix: 1.19.4+
Fix from $1,950 2026-06-25
Nokogiri HIGH 7.5
CVE-2022-23476

Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from…

Patch available
Fix from $1,950 2022-12-08
Nokogiri HIGH 8.2
CVE-2022-29181

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX …

Fix: 1.13.6 / 13.1+
Fix from $1,950 2022-05-20
Nokogiri HIGH 7.5
CVE-2022-24836

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to exce…

Fix: 1.13.4 / 13.1+
Fix from $1,950 2022-04-11
Nokogiri HIGH 7.5
CVE-2018-25032EPSS 52%

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Fix: 1.2.12 / 1.13.4+
Fix from $1,950 2022-03-25
Nokogiri HIGH 7.5
CVE-2021-41098

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby onl…

Fix: 1.12.5+
Fix from $1,950 2021-09-27