Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rails MEDIUM 6.5
CVE-2026-33658

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's p…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,600 2026-03-26
Rails CRITICAL 9.1
CVE-2026-33202

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's …

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $2,300 2026-03-24
Rails CRITICAL 9.8
CVE-2026-33195

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's …

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $2,300 2026-03-24
Rails HIGH 7.5
CVE-2026-33174

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving file…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,950 2026-03-24
Rails HIGH 7.5
CVE-2026-33176

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,950 2026-03-24
Rails MEDIUM 6.1
CVE-2026-33170

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,600 2026-03-24
Rails MEDIUM 5.3
CVE-2026-33169

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a loo…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,600 2026-03-24
Rails MEDIUM 5.3
CVE-2026-33173

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsCon…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,600 2026-03-24
Rails MEDIUM 6.1
CVE-2026-33167

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions p…

Fix: 8.1.2.1+
Fix from $1,600 2026-03-23
Rails Html Sanitizers MEDIUM 6.1
CVE-2024-53985

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…

Patch available
Fix from $1,600 2024-12-02
Rails Html Sanitizers MEDIUM 6.1
CVE-2024-53986

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…

Patch available
Fix from $1,600 2024-12-02
Rails Html Sanitizers MEDIUM 6.1
CVE-2024-53987

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…

Patch available
Fix from $1,600 2024-12-02
Rails Html Sanitizers MEDIUM 6.1
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…

Patch available
Fix from $1,600 2024-12-02
Rails Html Sanitizers MEDIUM 6.1
CVE-2024-53989

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…

Patch available
Fix from $1,600 2024-12-02
Rails MEDIUM 6.1
CVE-2024-32464

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area ta…

Fix: 7.1.3.4+
Fix from $1,600 2024-06-04
Rails CRITICAL 9.8
CVE-2024-28103

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served o…

Fix: 6.1.7.8 / 7.0.8.4+
Fix from $2,300 2024-06-04
Rails HIGH 7.5
CVE-2024-26142

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Act…

Fix: 7.1.3.1+
Fix from $1,950 2024-02-27
Rails MEDIUM 6.1
CVE-2024-26143

Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications usi…

Fix: 7.0.8.1 / 7.1.3.1+
Fix from $1,600 2024-02-27
Rails MEDIUM 5.3
CVE-2024-26144

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By defau…

Fix: 6.1.7.7 / 7.1.0+
Fix from $1,600 2024-02-27
Rails HIGH 7.5
CVE-2023-22792

A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a sp…

Fix: 6.0.6.1 / 6.1.7.1+
Fix from $1,950 2023-02-09
Rails HIGH 7.5
CVE-2023-22795

A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP I…

Fix: 6.1.7.1 / 7.0.4.1+
Fix from $1,950 2023-02-09
Globalid HIGH 7.5
CVE-2023-22799

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expres…

Fix: 1.0.1+
Fix from $1,950 2023-02-09
Rails Html Sanitizers MEDIUM 6.1
CVE-2022-23520

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerabilit…

Fix: 1.4.4+
Fix from $1,600 2022-12-14
Rails Html Sanitizers MEDIUM 6.1
CVE-2022-23519

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with ce…

Fix: 1.4.4+
Fix from $1,600 2022-12-14
Rails Html Sanitizers HIGH 7.5
CVE-2022-23517

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use a…

Fix: 1.4.4+
Fix from $1,950 2022-12-14
Rails Html Sanitizers MEDIUM 6.1
CVE-2022-23518

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scri…

Fix: 1.4.4 / 2.19.1+
Fix from $1,600 2022-12-14
Rails MEDIUM 5.4
CVE-2022-3704

A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/mi…

Patch available
Fix from $1,600 2022-10-26
Rails Html Sanitizers MEDIUM 6.1
CVE-2022-32209EPSS 29%

# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.Thi…

Fix: 1.4.3+
Fix from $1,600 2022-06-24
Active Storage CRITICAL 9.8
CVE-2022-21831

A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

Fix: 5.2.6.3 / 6.0.4.7+
Fix from $2,300 2022-05-26
Actionpack MEDIUM 6.1
CVE-2022-22577

An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.

Fix: 5.2.7.1 / 6.0.4.8+
Fix from $1,600 2022-05-26