Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-33658
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1
Active Storage's p…
Rails
7.2.3.1 / 8.0.4.1+
CRITICAL 9.1
CVE-2026-33202
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's …
Rails
7.2.3.1 / 8.0.4.1+
CRITICAL 9.8
CVE-2026-33195
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's …
Rails
7.2.3.1 / 8.0.4.1+
HIGH 7.5
CVE-2026-33174
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving file…
Rails
7.2.3.1 / 8.0.4.1+
HIGH 7.5
CVE-2026-33176
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…
Rails
7.2.3.1 / 8.0.4.1+
MEDIUM 6.1
CVE-2026-33170
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…
Rails
7.2.3.1 / 8.0.4.1+
MEDIUM 5.3
CVE-2026-33169
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a loo…
Rails
7.2.3.1 / 8.0.4.1+
MEDIUM 5.3
CVE-2026-33173
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsCon…
Rails
7.2.3.1 / 8.0.4.1+
MEDIUM 6.1
CVE-2026-33167
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions p…
Rails
8.1.2.1+
MEDIUM 6.1
CVE-2024-53985
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…
Rails Html Sanitizers
Patch available
MEDIUM 6.1
CVE-2024-53986
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…
Rails Html Sanitizers
Patch available
MEDIUM 6.1
CVE-2024-53987
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…
Rails Html Sanitizers
Patch available
MEDIUM 6.1
CVE-2024-53988
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…
Rails Html Sanitizers
Patch available
MEDIUM 6.1
CVE-2024-53989
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…
Rails Html Sanitizers
Patch available
MEDIUM 6.1
CVE-2024-32464
Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area ta…
Rails
7.1.3.4+
CRITICAL 9.8
CVE-2024-28103
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served o…
Rails
6.1.7.8 / 7.0.8.4+
HIGH 7.5
CVE-2024-26142
Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Act…
Rails
7.1.3.1+
MEDIUM 6.1
CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications usi…
Rails
7.0.8.1 / 7.1.3.1+
MEDIUM 5.3
CVE-2024-26144
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By defau…
Rails
6.1.7.7 / 7.1.0+
HIGH 7.5
CVE-2023-22792
A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a sp…
Rails
6.0.6.1 / 6.1.7.1+
HIGH 7.5
CVE-2023-22795
A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP I…
Rails
6.1.7.1 / 7.0.4.1+
HIGH 7.5
CVE-2023-22799
A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expres…
Globalid
1.0.1+
MEDIUM 6.1
CVE-2022-23520
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerabilit…
Rails Html Sanitizers
1.4.4+
MEDIUM 6.1
CVE-2022-23519
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with ce…
Rails Html Sanitizers
1.4.4+
HIGH 7.5
CVE-2022-23517
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use a…
Rails Html Sanitizers
1.4.4+
MEDIUM 6.1
CVE-2022-23518
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scri…
Rails Html Sanitizers
1.4.4 / 2.19.1+
MEDIUM 5.4
CVE-2022-3704
A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/mi…
Rails
Patch available
MEDIUM 6.1
CVE-2022-32209EPSS 29%
# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.Thi…
Rails Html Sanitizers
1.4.3+
CRITICAL 9.8
CVE-2022-21831
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
Active Storage
5.2.6.3 / 6.0.4.7+
MEDIUM 6.1
CVE-2022-22577
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
Actionpack
5.2.7.1 / 6.0.4.8+