Rails Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Rails products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

3

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Rails KEVs Added by Year

Loading...

3 Rails KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2019-5418

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted...

Confirmed In CISA 01 Jun 2026
CVE-2014-0130

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before...

Confirmed In CISA 25 Mar 2022
CVE-2016-0752

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x...

Confirmed In CISA 25 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology