Rubyonrails
150 known vulnerabilities
Top Products
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToD
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can c
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execut
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute
SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute
SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execut
Frequently Asked Questions
How many CVEs affect Rubyonrails?
Rubyonrails has 150 CVE records in our database, including 4 critical and 17 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Rubyonrails vulnerabilities?
Rubyonrails has 4 critical severity (CVSS 9.0+) and 17 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Rubyonrails vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Rubyonrails products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Rubyonrails Vulnerabilities
CyberStrike scans your infrastructure for Rubyonrails vulnerabilities and provides real-time remediation guidance.
Get Started