Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-33658 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's p… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,6002026-03-26 CRITICAL 9.1 CVE-2026-33202 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's … Rails 7.2.3.1 / 8.0.4.1+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-33195 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's … Rails 7.2.3.1 / 8.0.4.1+ Fix from $2,3002026-03-24 HIGH 7.5 CVE-2026-33174 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving file… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33176 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,9502026-03-24 MEDIUM 6.1 CVE-2026-33170 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,6002026-03-24 MEDIUM 5.3 CVE-2026-33169 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a loo… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,6002026-03-24 MEDIUM 5.3 CVE-2026-33173 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsCon… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,6002026-03-24 MEDIUM 6.1 CVE-2026-33167 Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions p… Rails 8.1.2.1+ Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2024-53985 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura… Rails Html Sanitizers Patch available Fix from $1,6002024-12-02 MEDIUM 6.1 CVE-2024-53986 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura… Rails Html Sanitizers Patch available Fix from $1,6002024-12-02 MEDIUM 6.1 CVE-2024-53987 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura… Rails Html Sanitizers Patch available Fix from $1,6002024-12-02 MEDIUM 6.1 CVE-2024-53988 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura… Rails Html Sanitizers Patch available Fix from $1,6002024-12-02 MEDIUM 6.1 CVE-2024-53989 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura… Rails Html Sanitizers Patch available Fix from $1,6002024-12-02 MEDIUM 6.1 CVE-2024-32464 Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area ta… Rails 7.1.3.4+ Fix from $1,6002024-06-04 CRITICAL 9.8 CVE-2024-28103 Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served o… Rails 6.1.7.8 / 7.0.8.4+ Fix from $2,3002024-06-04 HIGH 7.5 CVE-2024-26142 Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Act… Rails 7.1.3.1+ Fix from $1,9502024-02-27 MEDIUM 6.1 CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications usi… Rails 7.0.8.1 / 7.1.3.1+ Fix from $1,6002024-02-27 MEDIUM 5.3 CVE-2024-26144 Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By defau… Rails 6.1.7.7 / 7.1.0+ Fix from $1,6002024-02-27 HIGH 7.5 CVE-2023-22792 A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a sp… Rails 6.0.6.1 / 6.1.7.1+ Fix from $1,9502023-02-09 HIGH 7.5 CVE-2023-22795 A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP I… Rails 6.1.7.1 / 7.0.4.1+ Fix from $1,9502023-02-09 HIGH 7.5 CVE-2023-22799 A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expres… Globalid 1.0.1+ Fix from $1,9502023-02-09 MEDIUM 6.1 CVE-2022-23520 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerabilit… Rails Html Sanitizers 1.4.4+ Fix from $1,6002022-12-14 MEDIUM 6.1 CVE-2022-23519 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with ce… Rails Html Sanitizers 1.4.4+ Fix from $1,6002022-12-14 HIGH 7.5 CVE-2022-23517 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use a… Rails Html Sanitizers 1.4.4+ Fix from $1,9502022-12-14 MEDIUM 6.1 CVE-2022-23518 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scri… Rails Html Sanitizers 1.4.4 / 2.19.1+ Fix from $1,6002022-12-14 MEDIUM 5.4 CVE-2022-3704 A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/mi… Rails Patch available Fix from $1,6002022-10-26 MEDIUM 6.1 CVE-2022-32209EPSS 29% # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.Thi… Rails Html Sanitizers 1.4.3+ Fix from $1,6002022-06-24 CRITICAL 9.8 CVE-2022-21831 A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments. Active Storage 5.2.6.3 / 6.0.4.7+ Fix from $2,3002022-05-26 MEDIUM 6.1 CVE-2022-22577 An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses. Actionpack 5.2.7.1 / 6.0.4.8+ Fix from $1,6002022-05-26