Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
rubyonrails rails 4.0.2 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-0080
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors...
Rubyonrails Rails 4.0.2
Rubyonrails Rails 4.0.1
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.0.0
NA
CVE-2014-3514
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls....
Rubyonrails Rails 4.0.0
Rubyonrails Rails 4.0.2
Rubyonrails Rails 4.0.3
Rubyonrails Rails 4.0.7
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.1.3
Rubyonrails Rails 4.1.4
Rubyonrails Rails 4.0.8
Rubyonrails Rails 4.0.1
Rubyonrails Rails 4.0.6
Rubyonrails Rails 4.1.2
Rubyonrails Rails 4.0.4
Rubyonrails Rails 4.0.5
Rubyonrails Rails 4.1.1
1 Github repository available
7.5
CVSSv3
CVE-2016-0751
actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a...
Rubyonrails Rails 4.2.5
Rubyonrails Rails 4.2.4
Rubyonrails Rails 4.2.1
Rubyonrails Rails 4.2.0
Rubyonrails Rails 4.1.5
Rubyonrails Rails 4.1.6
Rubyonrails Rails 4.1.13
Rubyonrails Rails 4.1.12
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.0.1
Rubyonrails Rails 4.0.0
Rubyonrails Rails 4.0.5
Rubyonrails Rails 4.0.10
Rubyonrails Ruby On Rails 4.0.11.1
Rubyonrails Rails 4.1.8
Rubyonrails Rails 4.1.7
Rubyonrails Rails 4.1.10
Rubyonrails Rails 4.1.9
Rubyonrails Rails 4.0.4
Rubyonrails Rails 4.0.3
Rubyonrails Rails 4.0.6
Rubyonrails Ruby On Rails 4.0.13
Rubyonrails Rails 5.0.0
Rubyonrails Rails 4.2.2
Rubyonrails Rails 4.1.2
Rubyonrails Rails 4.1.1
Rubyonrails Rails 4.0.7
Rubyonrails Ruby On Rails 4.0.12
Rubyonrails Ruby On Rails
Rubyonrails Rails 4.2.3
Rubyonrails Rails 4.1.4
Rubyonrails Rails 4.1.3
Rubyonrails Ruby On Rails 4.1.11
Rubyonrails Ruby On Rails 4.0.10
Rubyonrails Rails 4.0.9
Rubyonrails Rails 4.0.8
Rubyonrails Ruby On Rails 4.0.11
Rubyonrails Rails 4.0.2
3 Github repositories available
NA
CVE-2014-3483
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging...
Rubyonrails Rails 4.0.5
Rubyonrails Rails 4.0.1
Rubyonrails Rails 4.0.6
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.0.4
Rubyonrails Rails 4.0.3
Rubyonrails Rails 4.0.2
Rubyonrails Rails 4.1.2
Rubyonrails Rails 4.1.1
Rubyonrails Rails 4.0.0
5.3
CVSSv3
CVE-2015-7577
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote...
Rubyonrails Rails 4.2.4
Rubyonrails Rails 4.2.1
Rubyonrails Rails 4.2.0
Rubyonrails Rails 4.1.14
Rubyonrails Ruby On Rails 4.1.11
Rubyonrails Rails 4.1.10
Rubyonrails Rails 4.1.8
Rubyonrails Rails 4.1.7.1
Rubyonrails Rails 4.1.7
Rubyonrails Rails 4.1.2
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.0.10
Rubyonrails Rails 4.0.9
Rubyonrails Rails 4.0.5
Rubyonrails Rails 4.0.4
Rubyonrails Rails 4.0.1
Rubyonrails Rails 5.0.0
Rubyonrails Rails 4.2.5
Rubyonrails Rails 4.2.2
Rubyonrails Rails 4.1.13
Rubyonrails Rails 4.1.6
Rubyonrails Rails 4.1.5
Rubyonrails Rails 4.1.1
Rubyonrails Ruby On Rails 4.0.12
Rubyonrails Ruby On Rails 4.0.11.1
Rubyonrails Rails 4.0.6
Rubyonrails Rails 4.0.2
Rubyonrails Rails 4.0.0
Rubyonrails Ruby On Rails
Rubyonrails Rails 4.1.12
Rubyonrails Rails 4.1.9
Rubyonrails Rails 4.1.4
Rubyonrails Rails 4.1.3
Rubyonrails Ruby On Rails 4.0.11
Rubyonrails Ruby On Rails 4.0.10
Rubyonrails Rails 4.2.3
Rubyonrails Ruby On Rails 4.0.13
Rubyonrails Rails 4.0.8
Rubyonrails Rails 4.0.7
Rubyonrails Rails 4.0.3
NA
CVE-2013-4491
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string...
Rubyonrails Rails 4.0.1
Rubyonrails Rails
Rubyonrails Rails 4.0.0
Rubyonrails Rails 3.2.6
Rubyonrails Rails 3.2.5
Rubyonrails Rails 3.2.2
Rubyonrails Ruby On Rails 3.2.15
Rubyonrails Rails 3.2.13
Rubyonrails Rails 3.2.12
Rubyonrails Rails 3.1.9
Rubyonrails Rails 3.1.8
Rubyonrails Rails 3.1.3
Rubyonrails Rails 3.1.2
Rubyonrails Rails 3.1.1
Rubyonrails Rails 3.1.0
Rubyonrails Rails 3.0.9
Rubyonrails Rails 3.0.8
Rubyonrails Rails 3.0.6
Rubyonrails Rails 3.0.3
Rubyonrails Rails 3.0.20
Rubyonrails Rails 3.0.14
Rubyonrails Rails 3.0.13
Rubyonrails Rails 3.0.1
Rubyonrails Rails 3.0.0
Rubyonrails Rails 3.2.8
Rubyonrails Rails 3.2.7
Rubyonrails Rails 3.2.3
Rubyonrails Rails 3.2.0
Rubyonrails Rails 3.1.4
Rubyonrails Rails 3.0.7
Rubyonrails Ruby On Rails 3.0.4
Rubyonrails Rails 3.0.17
Rubyonrails Rails 3.0.16
Rubyonrails Rails 3.0.10
Rubyonrails Rails 3.2.9
Rubyonrails Ruby On Rails 3.2.14
Rubyonrails Rails 3.2.1
Rubyonrails Rails 3.1.5
Rubyonrails Rails 3.1.10
Rubyonrails Rails 3.0.5
Rubyonrails Rails 3.0.4
Rubyonrails Rails 3.0.19
Rubyonrails Rails 3.0.18
Rubyonrails Rails 3.0.11
Rubyonrails Rails 3.2.4
Rubyonrails Ruby On Rails
Rubyonrails Rails 3.2.11
Rubyonrails Rails 3.2.10
Rubyonrails Rails 3.1.7
Rubyonrails Rails 3.1.6
Rubyonrails Ruby On Rails 3.1.11
Rubyonrails Rails 3.0.2
Rubyonrails Rails 3.0.12
NA
CVE-2014-0130
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to...
Redhat Subscription Asset Manager
Rubyonrails Rails 4.1.0
Rubyonrails Ruby On Rails
Rubyonrails Rails 3.2.0
Rubyonrails Rails 3.2.1
Rubyonrails Rails 3.2.4
Rubyonrails Rails 3.2.5
Rubyonrails Rails 3.2.6
Rubyonrails Rails 4.0.3
Rubyonrails Rails 4.0.0
Rubyonrails Rails 4.0.1
Rubyonrails Rails 4.0.2
Rubyonrails Rails 3.2.11
Rubyonrails Rails 3.2.13
Rubyonrails Rails 3.2.2
Rubyonrails Rails 3.2.3
Rubyonrails Rails 3.2.8
Rubyonrails Rails 3.2.15
Rubyonrails Rails 3.2.16
Rubyonrails Rails 4.0.4
Rubyonrails Rails 3.2.10
Rubyonrails Rails 3.2.12
Rubyonrails Rails 3.2.7
Rubyonrails Rails 3.2.9
5 Github repositories available
NA
CVE-2014-7829
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to...
Opensuse Opensuse 12.3
Opensuse Opensuse 13.1
Opensuse Opensuse 13.2
Rubyonrails Rails 3.0.0
Rubyonrails Rails 3.0.1
Rubyonrails Rails 3.0.10
Rubyonrails Rails 3.0.14
Rubyonrails Rails 3.0.16
Rubyonrails Ruby On Rails 3.0.4
Rubyonrails Rails 3.0.4
Rubyonrails Rails 3.0.7
Rubyonrails Rails 3.0.9
Rubyonrails Rails 3.1.0
Rubyonrails Rails 3.1.1
Rubyonrails Rails 3.1.4
Rubyonrails Rails 3.1.5
Rubyonrails Rails 3.2.0
Rubyonrails Rails 3.2.15
Rubyonrails Rails 3.2.16
Rubyonrails Rails 3.2.3
Rubyonrails Rails 4.0.0
Rubyonrails Rails 4.0.1
Rubyonrails Rails 4.0.10
Rubyonrails Rails 4.0.6
Rubyonrails Rails 4.0.7
Rubyonrails Rails 4.1.1
Rubyonrails Rails 4.1.2
Rubyonrails Rails 4.1.6
Rubyonrails Rails 3.0.12
Rubyonrails Rails 3.0.2
Rubyonrails Rails 3.0.5
Rubyonrails Rails 3.0.6
Rubyonrails Rails 3.0.8
Rubyonrails Rails 3.1.2
Rubyonrails Rails 3.1.7
Rubyonrails Rails 3.1.8
Rubyonrails Rails 3.2.11
Rubyonrails Rails 3.2.12
Rubyonrails Ruby On Rails 3.2.19
Rubyonrails Ruby On Rails 3.2.20
Rubyonrails Rails 3.2.5
Rubyonrails Rails 3.2.6
Rubyonrails Rails 4.0.4
Rubyonrails Rails 4.0.5
Rubyonrails Ruby On Rails 4.0.11
Rubyonrails Rails 4.1.3
Rubyonrails Rails 4.2.0
Rubyonrails Rails 3.0.13
Rubyonrails Rails 3.0.20
Rubyonrails Rails 3.0.3
Rubyonrails Rails 3.1.3
Rubyonrails Rails 3.1.9
Rubyonrails Rails 3.2.13
Rubyonrails Rails 3.2.2
Rubyonrails Rails 3.2.7
Rubyonrails Rails 3.2.8
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.1.4
Rubyonrails Rails 4.1.5
Rubyonrails Rails 3.0.11
Rubyonrails Rails 3.0.17
Rubyonrails Rails 3.0.18
Rubyonrails Rails 3.0.19
Rubyonrails Rails 3.1.10
Rubyonrails Rails 3.1.6
Rubyonrails Rails 3.2.1
Rubyonrails Rails 3.2.10
Rubyonrails Rails 3.2.17
Rubyonrails Rails 3.2.18
Rubyonrails Rails 3.2.4
Rubyonrails Rails 4.0.2
Rubyonrails Rails 4.0.3
Rubyonrails Rails 4.0.8
Rubyonrails Rails 4.0.9
Rubyonrails Rails 4.1.7
1 Github repository available
7.5
CVSSv3
CVE-2015-7581
actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a...
Rubyonrails Rails 5.0.0
Rubyonrails Rails 4.2.5
Rubyonrails Rails 4.1.7
Rubyonrails Rails 4.1.6
Rubyonrails Rails 4.1.5
Rubyonrails Rails 4.1.1
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.0.6
Rubyonrails Rails 4.0.1
Rubyonrails Rails 4.2.0
Rubyonrails Rails 4.1.8
Rubyonrails Rails 4.1.2
Rubyonrails Rails 4.0.10
Rubyonrails Rails 4.0.0
Rubyonrails Rails 4.2.4
Rubyonrails Rails 4.2.3
Rubyonrails Rails 4.1.4
Rubyonrails Rails 4.1.3
Rubyonrails Rails 4.0.9
Rubyonrails Rails 4.0.5
Rubyonrails Rails 4.0.4
Rubyonrails Rails 4.2.2
Rubyonrails Rails 4.2.1
Rubyonrails Rails 4.0.8
Rubyonrails Rails 4.0.7
Rubyonrails Rails 4.0.3
Rubyonrails Rails 4.0.2
1 Github repository available
5.3
CVSSv3
CVE-2016-2097
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE:...
Rubyonrails Rails 4.0.4
Rubyonrails Rails 4.1.9
Rubyonrails Rails 4.1.4
Rubyonrails Rails 4.1.3
Rubyonrails Rails 4.1.12
Rubyonrails Rails 4.1.10
Rubyonrails Rails 4.1.0
Rubyonrails Rails 4.0.6
Rubyonrails Rails 4.0.5
Rubyonrails Rails 4.0.1
Rubyonrails Ruby On Rails
Rubyonrails Rails 4.1.6
Rubyonrails Rails 4.1.5
Rubyonrails Rails 4.1.14
Rubyonrails Rails 4.1.13
Rubyonrails Rails 4.0.10
Rubyonrails Rails 4.0.0
Rubyonrails Rails 4.1.7
Rubyonrails Rails 4.1.2
Rubyonrails Rails 4.1.1
Rubyonrails Rails 4.0.8
Rubyonrails Rails 4.0.7
Rubyonrails Rails 4.0.3
Rubyonrails Rails 4.0.2
Rubyonrails Rails 4.1.8
Rubyonrails Rails 4.1.7.1
Rubyonrails Rails 4.0.9
Rubyonrails Ruby On Rails 4.1.14.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
arbitrary
CVE-2022-2257
CVE-2013-4585
CVE-2013-4493
CVE-2022-26134
brute force
SQL
CVE-2022-30333
CVE-2022-33327
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »