Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ruby On Rails

First CVE: Aug 14, 2006Active for: 20 yearsTotal CVEs: 146

Ruby On Rails is a widely adopted web-application framework where disclosed vulnerabilities concentrate in code-injection attack vectors, reflecting the risks inherent to dynamic templating and string interpolation in application-layer rapid-development environments. Current severity, exploitation, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
146
Total CVEs
Bottom 1%
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
2.1%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ruby On Rails over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2006
19 years ago
Most Recent CVE
Mar 26, 2026
120 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (146 CVEs).

146 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5418HIGH
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar
Mar 27, 20197.599YESYES
CVE-2016-0752HIGH
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote
Feb 16, 20167.597YESYES
CVE-2019-5420CRITICAL
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. Thi
Mar 27, 20199.890NOYES
CVE-2013-0156HIGH
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of st
Jan 13, 20137.589NOYES
CVE-2013-0333HIGH
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML pars
Jan 30, 20137.588NOYES
CVE-2016-2098HIGH
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's un
Apr 7, 20167.384NOYES
CVE-2014-0130HIGH
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x
May 7, 20147.583YESNO
CVE-2020-8163HIGH
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
Jul 2, 20208.882NOYES
CVE-2021-22881MEDIUM
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "
Feb 11, 20216.178NOYES
CVE-2015-3224MEDIUM
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address,
Jul 26, 20154.369NOYES
View all 146 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products146 CVEs
64%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network81 (55.5%)
Unknown65 (44.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low74 (50.7%)
High7 (4.8%)
Unknown65 (44.5%)
User Interaction
None48 (32.9%)
Unknown65 (44.5%)
Required33 (22.6%)
Privileges Required
Low4 (2.7%)
High1 (0.7%)
None76 (52.1%)
Unknown65 (44.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (146 CVEs).

CISA KEV
3 CVEs
2.1% of CVEs· Bottom 1%
Metasploit
8 CVEs
5.5% of CVEs· Bottom 1%
Nuclei
5 CVEs
3.4% of CVEs· Bottom 1%
ExploitDB
11 CVEs
7.5% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ruby On Rails.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ruby On Rails — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ruby On Rails's Products

View all 5 CNAs →

Top CWEs