Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-21654 Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in th… Rubygems.org 2024-01-08+ Fix from $2,3002024-01-12 HIGH 7.5 CVE-2023-40165 rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any upl… Rubygems.org 2023-08-14+ Fix from $1,9502023-08-17 HIGH 8.8 CVE-2022-36073 RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org acco… Rubygems 2022-08-31+ Fix from $1,9502022-09-07 HIGH 7.5 CVE-2022-29218 RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allo… Rubygems.org No fix yet Fix from $1,9502022-05-13 HIGH 7.5 CVE-2022-29176 Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any Ruby… Rubygems.org Mitigation only Fix from $1,9502022-05-05 HIGH 7.4 CVE-2019-8320 A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now incl… Rubygems after 3.0.2 Fix from $1,9502019-06-06 HIGH 7.8 CVE-2018-1000074 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a… Rubygems after 2.5.0 Fix from $1,9502018-03-13 HIGH 7.5 CVE-2018-1000073 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a… Rubygems after 2.5.0 Fix from $1,9502018-03-13 MEDIUM 5.5 CVE-2018-1000079 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a… Rubygems after 2.5.0 Fix from $1,6002018-03-13 MEDIUM 5.8 CVE-2012-2125 RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installat… Rubygems after 1.8.22 Fix from $1,6002013-10-01 HIGH 7.5 CVE-2013-2615 lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. Fastreader No fix yet Fix from $1,9502013-03-20 HIGH 7.5 CVE-2013-2616 lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. Mini Magick No fix yet Fix from $1,9502013-03-20 HIGH 7.5 CVE-2013-1875 command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename. Command Wrap No fix yet Fix from $1,9502013-03-20 HIGH 7.5 CVE-2013-0269EPSS 14% The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consump… Json Gem Mitigation only Fix from $1,9502013-02-13 HIGH 7.5 CVE-2012-2140 The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim deliv… Mail Gem after 2.4.1 Fix from $1,9502012-07-18 MEDIUM 5.0 CVE-2012-2139 Directory traversal vulnerability in lib/mail/network/delivery_methods/file_delivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers… Mail Gem after 2.4.3 Fix from $1,6002012-07-18