Rubygems
889 CVEs tracked since 2006. Since Jan 2020, 1 of them reached CISA KEV.
Rubygems CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-01 | 7 | 0 |
| 2020-02 | 10 | 0 |
| 2020-03 | 4 | 0 |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | 10 | 0 |
| 2020-07 | null or fewer | |
| 2020-08 | 4 | 0 |
| 2020-09 | 5 | 0 |
| 2020-10 | 4 | 0 |
| 2020-11 | 3 | 0 |
| 2020-12 | null or fewer | |
| 2021-01 | 4 | 0 |
| 2021-02 | 11 | 0 |
| 2021-03 | null or fewer | |
| 2021-04 | 6 | 0 |
| 2021-05 | 8 | 0 |
| 2021-06 | 7 | 0 |
| 2021-07 | 4 | 0 |
| 2021-08 | null or fewer | |
| 2021-09 | 3 | 0 |
| 2021-10 | 12 | 0 |
| 2021-11 | 12 | 0 |
| 2021-12 | 5 | 0 |
| 2022-01 | 5 | 0 |
| 2022-02 | 5 | 0 |
| 2022-03 | 7 | 0 |
| 2022-04 | 11 | 0 |
| 2022-05 | 15 | 0 |
| 2022-06 | 13 | 0 |
| 2022-07 | 3 | 0 |
| 2022-08 | null or fewer | |
| 2022-09 | 6 | 0 |
| 2022-10 | 6 | 0 |
| 2022-11 | 4 | 0 |
| 2022-12 | 17 | 0 |
| 2023-01 | 13 | 0 |
| 2023-02 | 13 | 1 |
| 2023-03 | null or fewer | |
| 2023-04 | 6 | 0 |
| 2023-05 | null or fewer | |
| 2023-06 | 10 | 0 |
| 2023-07 | 5 | 0 |
| 2023-08 | 5 | 0 |
| 2023-09 | null or fewer | |
| 2023-10 | 5 | 0 |
| 2023-11 | null or fewer | |
| 2023-12 | 12 | 0 |
| 2024-01 | 19 | 0 |
| 2024-02 | 14 | 0 |
| 2024-03 | 7 | 0 |
| 2024-04 | null or fewer | |
| 2024-05 | 9 | 0 |
| 2024-06 | null or fewer | |
| 2024-07 | 9 | 0 |
| 2024-08 | 6 | 0 |
| 2024-09 | 16 | 0 |
| 2024-10 | 12 | 0 |
| 2024-11 | null or fewer | |
| 2024-12 | 7 | 0 |
| 2025-01 | 6 | 0 |
| 2025-02 | 5 | 0 |
| 2025-03 | 16 | 0 |
| 2025-04 | null or fewer | |
| 2025-05 | 5 | 0 |
| 2025-06 | 6 | 0 |
| 2025-07 | 7 | 0 |
| 2025-08 | 6 | 0 |
| 2025-09 | null or fewer | |
| 2025-10 | 6 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | 7 | 0 |
| 2026-01 | 8 | 0 |
| 2026-02 | 12 | 0 |
| 2026-03 | null or fewer | |
| 2026-04 | 10 | 0 |
| 2026-05 | null or fewer | |
| 2026-06 | 10 | 0 |
| 2026-07 | 7 | 0 |
Products
The products that kept showing up in Rubygems's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Rubygems.
- CVE-2023-46035The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.5.9
- GHSA-pmwx-rm49-xv39ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal—
- GHSA-53g2-mvcc-q9x3Trix: Stored XSS via HTMLParser attribute injection on paste—
- GHSA-cj75-f6xr-r4g7Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations—
- GHSA-5qhf-9phg-95m2Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons—
- GHSA-9wjq-cp2p-hrgfLoofah: SVG `href` attribute bypasses local-reference restriction—
- GHSA-8whx-365g-h9vvLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references—
- GHSA-mjgf-xj26-9qf9pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier—
- GHSA-mqq5-j7w8-2hghAlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content—
- GHSA-phwj-rprq-35ppNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`—
- GHSA-wfpw-mmfh-qq69Nokogiri: Possible Use-After-Free in XInclude Processing—
- GHSA-p67v-3w7g-wjg7Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime—
- GHSA-wjv4-x9w8-wm3hNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type—
- GHSA-5prr-v3j2-97mhNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`—
- GHSA-9cv2-cfxc-v4v2Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes—
The record
- Peak rank
- #9 in Apr 2013
- Busiest month shown
- Jan 2024, 19 CVEs
- Months with a KEV entry
- 1 since Jan 2020
- Monthly snapshots
- 138 since 2006