Ruby on Rails Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Ruby on Rails products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

2

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Ruby on Rails KEVs Added by Year

Loading...

2 Ruby on Rails KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2014-0130

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before...

Confirmed In CISA 25 Mar 2022
CVE-2016-0752

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x...

Confirmed In CISA 25 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology