Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ruby On Rails HIGH 8.1
CVE-2017-17919

SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via th…

Fix: after 5.1.4
Fix from $1,950 2017-12-29
Ruby On Rails HIGH 8.1
CVE-2017-17920

SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via …

Fix: after 5.1.4
Fix from $1,950 2017-12-29
Rails HIGH 7.5
CVE-2016-6317

Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component …

Mitigation only
Fix from $1,950 2016-09-07
Rails MEDIUM 6.1
CVE-2016-6316

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow …

Mitigation only
Fix from $1,600 2016-09-07
Rails MEDIUM 5.3
CVE-2016-2097

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary f…

Fix: after 3.2.22.1
Fix from $1,600 2016-04-07
Rails MEDIUM 5.3
CVE-2016-0753EPSS 7%

Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers fo…

Fix: 4.1.14.1 / 4.2.5.1+
Fix from $1,600 2016-02-16
Rails HIGH 7.5
CVE-2016-0752 KEVEPSS 96%

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x bef…

Fix: 3.2.22.1 / 4.1.14.1+
Fix from $1,950 2016-02-16
Rails HIGH 7.5
CVE-2016-0751EPSS 10%

actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5…

Fix: after 3.2.22
Fix from $1,950 2016-02-16
Rails HIGH 7.5
CVE-2015-7581EPSS 7%

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote att…

Mitigation only
Fix from $1,950 2016-02-16
Html Sanitizer MEDIUM 6.1
CVE-2015-7579

Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbi…

Fix: after 1.0.2
Fix from $1,600 2016-02-16
Html Sanitizer MEDIUM 6.1
CVE-2015-7580

Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x …

Fix: after 1.0.2
Fix from $1,600 2016-02-16
Html Sanitizer MEDIUM 6.1
CVE-2015-7578

Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inje…

Fix: after 1.0.2
Fix from $1,600 2016-02-16
Rails MEDIUM 5.3
CVE-2015-7577

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.…

Fix: after 3.2.22
Fix from $1,600 2016-02-16
Rails MEDIUM 5.0
CVE-2015-3227

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, a…

Mitigation only
Fix from $1,600 2015-07-26
Rails MEDIUM 5.0
CVE-2014-7829

Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x bef…

No fix yet
Fix from $1,600 2014-11-18
Rails MEDIUM 5.0
CVE-2014-3916

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation faul…

Mitigation only
Fix from $1,600 2014-11-16
Rails HIGH 7.5
CVE-2014-3514

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote at…

Mitigation only
Fix from $1,950 2014-08-20
Rails HIGH 7.5
CVE-2014-3482

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record i…

Mitigation only
Fix from $1,950 2014-07-07
Rails HIGH 7.5
CVE-2014-3483

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record i…

Mitigation only
Fix from $1,950 2014-07-07
Rails MEDIUM 5.0
CVE-2014-0082EPSS 6%

actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the…

Fix: after 3.2.16
Fix from $1,600 2014-02-20
Rails MEDIUM 6.8
CVE-2014-0080

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4…

Mitigation only
Fix from $1,600 2014-02-20
Rails MEDIUM 6.4
CVE-2013-6417

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in paramete…

Fix: after 3.2.15
Fix from $1,600 2013-12-07
Rails MEDIUM 5.0
CVE-2013-6414EPSS 21%

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause …

Fix: after 4.0.1
Fix from $1,600 2013-12-07
Rails MEDIUM 6.4
CVE-2013-3221

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used …

No fix yet
Fix from $1,600 2013-04-22
Rails MEDIUM 5.8
CVE-2013-1856

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x befor…

Mitigation only
Fix from $1,600 2013-03-19
Rails MEDIUM 5.0
CVE-2013-1854

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by convertin…

Mitigation only
Fix from $1,600 2013-03-19
Rails HIGH 10.0
CVE-2013-0277EPSS 7%

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via c…

Patch available
Fix from $1,950 2013-02-13
Rails HIGH 7.5
CVE-2013-0333EPSS 95%

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML dat…

Mitigation only
Fix from $1,950 2013-01-30
Rails HIGH 7.5
CVE-2013-0156EPSS 99%

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does no…

Fix: 2.3.15 / 3.0.19+
Fix from $1,950 2013-01-13
Rails MEDIUM 6.4
CVE-2013-0155EPSS 8%

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between …

Fix: 3.0.19 / 3.1.10+
Fix from $1,600 2013-01-13