CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-80213 MEDIUM

resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames

CVSS 4.0 EPSS 0.35% Aug 27, 2026
CVE-2026-80212 HIGH

resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses

CVSS 7.5 EPSS 0.40% Aug 27, 2026
CVE-2026-71847 HIGH

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

CVSS 8.7 EPSS 0.43% Aug 7, 2026
CVE-2026-54696 LOW

Ruby JSON: JSON generator heap buffer overflow when streaming to an IO

CVSS 3.7 EPSS 0.38% Jun 30, 2026
CVE-2026-47242 MEDIUM

Net::IMAP: Command Injection via ID command argument

CVSS 5.8 EPSS 0.18% Jun 22, 2026
CVE-2026-47240 MEDIUM

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

CVSS 5.8 EPSS 0.83% Jun 22, 2026
CVE-2026-47241 LOW

Net::IMAP: Denial of Service via incomplete raw argument validation

CVSS 2.1 EPSS 0.38% Jun 22, 2026
CVE-2026-42258 MEDIUM

net-imap: Command Injection via unvalidated Symbol inputs

CVSS 5.8 EPSS 1.25% May 9, 2026
CVE-2026-42257 MEDIUM

net-imap: Command Injection via "raw" arguments to multiple commands

CVSS 5.8 EPSS 0.52% May 9, 2026
CVE-2026-42256 MEDIUM

net-imap: Denial of service via high iteration count for `SCRAM-*` authentication

CVSS 6.0 EPSS 0.52% May 9, 2026
CVE-2026-42245 LOW

net-imap: Quadratic complexity when reading response literals

CVSS 2.3 EPSS 0.70% May 9, 2026
CVE-2026-42246 HIGH

net-imap vulnerable to STARTTLS stripping via invalid response timing

CVSS 7.6 EPSS 0.40% May 9, 2026
CVE-2026-41316 HIGH

ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

CVSS 8.1 EPSS 1.31% Apr 24, 2026
CVE-2026-27820 MEDIUM

zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

CVSS 5.9 EPSS 0.75% Apr 16, 2026
CVE-2026-33210 HIGH

Ruby JSON has a format string injection vulnerability

CVSS 8.3 EPSS 1.01% Mar 20, 2026
CVE-2025-61594 LOW

URI Credential Leakage Bypass over CVE-2025-27221

CVSS 2.7 EPSS 0.56% Dec 30, 2025
CVE-2025-58767 LOW

REXML has a DoS condition when parsing malformed XML file

CVSS 1.2 EPSS 0.25% Sep 17, 2025
CVE-2025-24294 MEDIUM

resolv: Denial of Service in resolv gem

CVSS 6.6 EPSS 0.56% Jul 12, 2025
CVE-2025-6442 MEDIUM

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability

CVSS 5.9 EPSS 0.50% Jun 25, 2025
CVE-2025-43857 MEDIUM

net-imap rubygem vulnerable to possible DoS by memory exhaustion

CVSS 6.0 EPSS 0.49% Apr 28, 2025
CVE-2025-27788 HIGH

Ruby JSON Parser has Out-of-bounds Read

CVSS 7.5 EPSS 0.71% Mar 12, 2025
CVE-2025-25186 MEDIUM

Net::IMAP vulnerable to possible DoS by memory exhaustion

CVSS 6.0 EPSS 0.63% Feb 10, 2025
CVE-2024-49761 MEDIUM

REXML ReDoS vulnerability

CVSS 6.6 EPSS 1.42% Oct 28, 2024
CVE-2024-43398 HIGH

REXML denial of service vulnerability

CVSS 8.2 EPSS 1.21% Aug 22, 2024
CVE-2024-41946 MEDIUM

REXML DoS vulnerability

CVSS 6.9 EPSS 1.19% Aug 1, 2024

Showing 1 to 25 CVEs · page 1 (more available)