Loading HuntDB...

Rails

9 Products 33 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
4
Medium
14
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 16 CVEs

Recent CVEs

View all
CVE-2023-23913 MEDIUM 8 months ago

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned th…

CVE-2023-27531 MEDIUM 8 months ago

There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

CVE-2023-27539 MEDIUM 8 months ago

There is a denial of service vulnerability in the header parsing component of Rack.

CVE-2023-28362 MEDIUM 8 months ago

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potenti…

CVE-2023-38037 MEDIUM 8 months ago

ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user…

CVE-2023-28120 MEDIUM 8 months ago

There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.

CVE-2024-54133 UNKNOWN 9 months ago

Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content…

CVE-2024-53985 UNKNOWN 9 months, 1 week ago

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…

CVE-2024-53987 UNKNOWN 9 months, 1 week ago

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…

CVE-2024-53986 UNKNOWN 9 months, 1 week ago

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configura…