Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2017-17919 SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via th… Ruby On Rails after 5.1.4 Fix from $1,9502017-12-29 HIGH 8.1 CVE-2017-17920 SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via … Ruby On Rails after 5.1.4 Fix from $1,9502017-12-29 HIGH 7.5 CVE-2016-6317 Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component … Rails Mitigation only Fix from $1,9502016-09-07 MEDIUM 6.1 CVE-2016-6316 Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow … Rails Mitigation only Fix from $1,6002016-09-07 MEDIUM 5.3 CVE-2016-2097 Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary f… Rails after 3.2.22.1 Fix from $1,6002016-04-07 MEDIUM 5.3 CVE-2016-0753EPSS 7% Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers fo… Rails 4.1.14.1 / 4.2.5.1+ Fix from $1,6002016-02-16 HIGH 7.5 CVE-2016-0752 KEVEPSS 96% Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x bef… Rails 3.2.22.1 / 4.1.14.1+ Fix from $1,9502016-02-16 HIGH 7.5 CVE-2016-0751EPSS 10% actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5… Rails after 3.2.22 Fix from $1,9502016-02-16 HIGH 7.5 CVE-2015-7581EPSS 7% actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote att… Rails Mitigation only Fix from $1,9502016-02-16 MEDIUM 6.1 CVE-2015-7579 Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbi… Html Sanitizer after 1.0.2 Fix from $1,6002016-02-16 MEDIUM 6.1 CVE-2015-7580 Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x … Html Sanitizer after 1.0.2 Fix from $1,6002016-02-16 MEDIUM 6.1 CVE-2015-7578 Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inje… Html Sanitizer after 1.0.2 Fix from $1,6002016-02-16 MEDIUM 5.3 CVE-2015-7577 activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.… Rails after 3.2.22 Fix from $1,6002016-02-16 MEDIUM 5.0 CVE-2015-3227 The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, a… Rails Mitigation only Fix from $1,6002015-07-26 MEDIUM 5.0 CVE-2014-7829 Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x bef… Rails No fix yet Fix from $1,6002014-11-18 MEDIUM 5.0 CVE-2014-3916 The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation faul… Rails Mitigation only Fix from $1,6002014-11-16 HIGH 7.5 CVE-2014-3514 activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote at… Rails Mitigation only Fix from $1,9502014-08-20 HIGH 7.5 CVE-2014-3482 SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record i… Rails Mitigation only Fix from $1,9502014-07-07 HIGH 7.5 CVE-2014-3483 SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record i… Rails Mitigation only Fix from $1,9502014-07-07 MEDIUM 5.0 CVE-2014-0082EPSS 6% actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the… Rails after 3.2.16 Fix from $1,6002014-02-20 MEDIUM 6.8 CVE-2014-0080 SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4… Rails Mitigation only Fix from $1,6002014-02-20 MEDIUM 6.4 CVE-2013-6417 actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in paramete… Rails after 3.2.15 Fix from $1,6002013-12-07 MEDIUM 5.0 CVE-2013-6414EPSS 21% actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause … Rails after 4.0.1 Fix from $1,6002013-12-07 MEDIUM 6.4 CVE-2013-3221 The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used … Rails No fix yet Fix from $1,6002013-04-22 MEDIUM 5.8 CVE-2013-1856 The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x befor… Rails Mitigation only Fix from $1,6002013-03-19 MEDIUM 5.0 CVE-2013-1854 The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by convertin… Rails Mitigation only Fix from $1,6002013-03-19 HIGH 10.0 CVE-2013-0277EPSS 7% ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via c… Rails Patch available Fix from $1,9502013-02-13 HIGH 7.5 CVE-2013-0333EPSS 95% lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML dat… Rails Mitigation only Fix from $1,9502013-01-30 HIGH 7.5 CVE-2013-0156EPSS 99% active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does no… Rails 2.3.15 / 3.0.19+ Fix from $1,9502013-01-13 MEDIUM 6.4 CVE-2013-0155EPSS 8% Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between … Rails 3.0.19 / 3.1.10+ Fix from $1,6002013-01-13