Rails
Vendor:
First CVE: Aug 14, 2006 · Active for 19 years
117
Total CVEs
More Total CVEs than 99% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Rails over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2006
19 years ago
Most Recent CVE
Mar 26, 2026
124 days ago
CVE Severity & Scoring
Rails117 CVEs
63%
32%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network55 (47.0%)
Unknown62 (53.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (42.7%)
High5 (4.3%)
Unknown62 (53.0%)
User Interaction
None39 (33.3%)
Unknown62 (53.0%)
Required16 (13.7%)
Privileges Required
Low4 (3.4%)
High0 (0.0%)
None51 (43.6%)
Unknown62 (53.0%)
Top CVEs
Signals from CVEs in this product scope (117 CVEs).
117 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5418HIGH There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar | Mar 27, 2019 | 7.5 | 99 | YES | YES |
CVE-2016-0752HIGH Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote | Feb 16, 2016 | 7.5 | 97 | YES | YES |
CVE-2019-5420CRITICAL A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. Thi | Mar 27, 2019 | 9.8 | 90 | NO | YES |
CVE-2013-0156HIGH active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of st | Jan 13, 2013 | 7.5 | 89 | NO | YES |
CVE-2013-0333HIGH lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML pars | Jan 30, 2013 | 7.5 | 88 | NO | YES |
CVE-2016-2098HIGH Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's un | Apr 7, 2016 | 7.3 | 84 | NO | YES |
CVE-2014-0130HIGH Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x | May 7, 2014 | 7.5 | 83 | YES | NO |
CVE-2020-8163HIGH The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. | Jul 2, 2020 | 8.8 | 82 | NO | YES |
CVE-2021-22881MEDIUM The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain " | Feb 11, 2021 | 6.1 | 78 | NO | YES |
CVE-2020-8264MEDIUM In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a special | Jan 6, 2021 | 6.1 | 59 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (117 CVEs).
CISA KEV
3 CVEs
2.6% of CVEs· 98th percentile
Metasploit
7 CVEs
6.0% of CVEs· 97th percentile
Nuclei
4 CVEs
3.4% of CVEs· 97th percentile
ExploitDB
10 CVEs
8.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (117 CVEs).
Media Mentions
Signals from CVEs in this product scope (117 CVEs).
Top CNAs Publishing CVEs For Rails
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.2.0 | 2 | 8.0 | 0.5% | 0 | 0 |
| 7.0.0 | 1 | 6.1 | 4.2% | 0 | 1 |
| 6.1.4.2 | 1 | 6.1 | 4.2% | 0 | 1 |
| 6.1.0 | 1 | 6.1 | 1.2% | 0 | 0 |
| 6.0.4.2 | 1 | 6.1 | 4.2% | 0 | 1 |
| 6.0.0 | 1 | 9.8 | 92.1% | 0 | 1 |
| 5.0.0 | 7 | 6.1 | 11.7% | 1 | 1 |
| 4.2.7 | 2 | 6.8 | 3.7% | 0 | 0 |
| 4.2.6 | 2 | 6.8 | 3.7% | 0 | 0 |
| 4.2.5.2 | 2 | 6.8 | 3.7% | 0 | 0 |
| 4.2.5.1 | 3 | 7.0 | 29.6% | 0 | 1 |
| 4.2.5 | 7 | 6.3 | 17.3% | 0 | 1 |
| 4.2.4 | 7 | 6.3 | 17.1% | 0 | 1 |
| 4.2.3 | 7 | 6.3 | 17.1% | 0 | 1 |
| 4.2.2 | 7 | 6.4 | 16.3% | 0 | 1 |
| 4.2.1 | 9 | 6.2 | 16.7% | 0 | 1 |
| 4.2.0 | 11 | 6.0 | 14.9% | 0 | 1 |
| 4.1.9 | 6 | 5.6 | 13.4% | 0 | 1 |
| 4.1.8 | 9 | 5.8 | 13.5% | 0 | 1 |
| 4.1.7.1 | 5 | 5.5 | 19.7% | 0 | 1 |