Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ruby vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2013-2512
The ftpd gem 0.2.1 for Ruby allows remote malicious users to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.
Ftpd Project Ftpd 0.2.1
9.8
CVSSv3
CVE-2020-35458
An issue exists in ClusterLabs Hawk 2.x up to and including 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote malicious users to execute code a...
Clusterlabs Hawk 2.2.0-12
Clusterlabs Hawk 2.3.0-12
9.8
CVSSv3
CVE-2020-14001
The kramdown gem prior to 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="...
Kramdown Project Kramdown
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Canonical Ubuntu Linux 20.04
9.8
CVSSv3
CVE-2020-8159
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an malicious user to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
Rubyonrails Actionpack Page-caching
Debian Debian Linux 9.0
9.8
CVSSv3
CVE-2020-11020
Faye (NPM, RubyGem) versions greater than 0.5.0 and prior to 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass checks put in place by server-side extensions, by appending extra segments to th...
Faye Project Faye
9.8
CVSSv3
CVE-2013-1607
Ruby PDFKit gem before 0.5.3 has a Code Execution Vulnerability
Pdfkit Project Pdfkit
9.8
CVSSv3
CVE-2019-17268
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions up to and including 0.4.5, and 0.5.1 and later, are unaffected.
Omniauth-weibo-oauth2 Project Omniauth-weibo-oauth2 0.4.6
1 Github repository
9.8
CVSSv3
CVE-2020-7981
sql.rb in Geocoder prior to 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
Rubygeocoder Geocoder
9.8
CVSSv3
CVE-2019-10780
BibTeX-ruby prior to 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open.
Bibtex-ruby Project Bibtex-ruby
9.8
CVSSv3
CVE-2015-2784
The papercrop gem prior to 0.3.0 for Ruby on Rails does not properly handle crop input.
Papercrop Project Papercrop
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »