CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-46727 HIGH

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo i…

CVSS 8.1 EPSS 0.49% May 22, 2026
CVE-2026-42258 MEDIUM

net-imap: Command Injection via unvalidated Symbol inputs

CVSS 5.8 EPSS 1.25% May 9, 2026
CVE-2026-42257 MEDIUM

net-imap: Command Injection via "raw" arguments to multiple commands

CVSS 5.8 EPSS 0.52% May 9, 2026
CVE-2026-42256 MEDIUM

net-imap: Denial of service via high iteration count for `SCRAM-*` authentication

CVSS 6.0 EPSS 0.52% May 9, 2026
CVE-2026-42245 LOW

net-imap: Quadratic complexity when reading response literals

CVSS 2.3 EPSS 0.70% May 9, 2026
CVE-2026-42246 HIGH

net-imap vulnerable to STARTTLS stripping via invalid response timing

CVSS 7.6 EPSS 0.40% May 9, 2026
CVE-2026-27820 MEDIUM

zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

CVSS 5.9 EPSS 0.75% Apr 16, 2026
CVE-2026-33210 HIGH

Ruby JSON has a format string injection vulnerability

CVSS 8.3 EPSS 1.01% Mar 20, 2026
CVE-2025-61594 LOW

URI Credential Leakage Bypass over CVE-2025-27221

CVSS 2.7 EPSS 0.56% Dec 30, 2025
CVE-2025-58767 LOW

REXML has a DoS condition when parsing malformed XML file

CVSS 1.2 EPSS 0.25% Sep 17, 2025
CVE-2025-6442 MEDIUM

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability

CVSS 5.9 EPSS 0.50% Jun 25, 2025
CVE-2025-43857 MEDIUM

net-imap rubygem vulnerable to possible DoS by memory exhaustion

CVSS 6.0 EPSS 0.49% Apr 28, 2025
CVE-2025-27788 HIGH

Ruby JSON Parser has Out-of-bounds Read

CVSS 7.5 EPSS 0.71% Mar 12, 2025
CVE-2025-27221 LOW

uri: userinfo leakage in URI#join, URI#merge and URI#+

CVSS 2.1 EPSS 0.51% Mar 3, 2025
CVE-2025-27220 MEDIUM

CGI: ReDoS in CGI::Util#escapeElement

CVSS 6.3 EPSS 0.76% Mar 3, 2025
CVE-2025-27219 MEDIUM

CGI: Denial of Service in CGI::Cookie.parse

CVSS 6.3 EPSS 0.85% Mar 3, 2025
CVE-2024-49761 MEDIUM

REXML ReDoS vulnerability

CVSS 6.6 EPSS 1.42% Oct 28, 2024
CVE-2024-43398 HIGH

REXML denial of service vulnerability

CVSS 8.2 EPSS 1.21% Aug 22, 2024
CVE-2024-41946 MEDIUM

REXML DoS vulnerability

CVSS 6.9 EPSS 1.19% Aug 1, 2024
CVE-2024-41123 MEDIUM

REXML DoS vulnerability

CVSS 6.9 EPSS 1.28% Aug 1, 2024
CVE-2024-39908 MEDIUM

Denial of service in REXML

CVSS 6.9 EPSS 1.49% Jul 16, 2024
CVE-2024-35176 MEDIUM

REXML contains a denial of service vulnerability

CVSS 5.3 EPSS 2.06% May 16, 2024
CVE-2024-27280 CRITICAL

ruby: Buffer overread vulnerability in StringIO

CVSS 9.3 EPSS 2.36% May 8, 2024
CVE-2023-36617 MEDIUM

rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755

CVSS 5.3 EPSS 1.70% Jun 29, 2023
CVE-2023-28756 HIGH

ruby: ReDoS vulnerability in Time

CVSS 7.5 EPSS 2.45% Mar 31, 2023

Showing 1 to 25 CVEs · page 1 (more available)