Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Sensitive Information Disclosure Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity RubyGems Improper Input Validation Vulnerability (CVE-2018-1000077) CVE-2018-1000077 CWE-20 CWE-20 Medium RubyGems Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-1000079) CVE-2018-1000079 CWE-22 CWE-22 Medium RubyGems Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1000078) CVE-2018-1000078 CWE-707 CWE-707 Medium RubyGems Other Vulnerability (CVE-2012-2125) CVE-2012-2125 Medium Ruby Improper Authentication Vulnerability (CVE-2007-5162) CVE-2007-5162 CWE-287 CWE-287 Medium Ruby Improper Authentication Vulnerability (CVE-2007-5770) CVE-2007-5770 CWE-287 CWE-287 Medium Ruby Improper Authentication Vulnerability (CVE-2008-3905) CVE-2008-3905 CWE-287 CWE-287 Medium Ruby Improper Authentication Vulnerability (CVE-2009-0642) CVE-2009-0642 CWE-287 CWE-287 Medium Ruby Improper Input Validation Vulnerability (CVE-2008-3790) CVE-2008-3790 CWE-20 CWE-20 Medium Ruby Improper Input Validation Vulnerability (CVE-2009-4492) CVE-2009-4492 CWE-20 CWE-20 Medium Ruby Improper Input Validation Vulnerability (CVE-2011-2705) CVE-2011-2705 CWE-20 CWE-20 Medium Ruby Improper Input Validation Vulnerability (CVE-2013-1821) CVE-2013-1821 CWE-20 CWE-20 Medium Ruby Improper Input Validation Vulnerability (CVE-2015-1855) CVE-2015-1855 CWE-20 CWE-20 Medium Ruby Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-1891) CVE-2008-1891 CWE-22 CWE-22 Medium Ruby Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2011-1004) CVE-2011-1004 CWE-59 CWE-59 Medium Ruby Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') Vulnerability (CVE-2017-17742) CVE-2017-17742 CWE-113 CWE-113 Medium Ruby Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-0256) CVE-2013-0256 CWE-707 CWE-707 Medium Ruby Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2011-3624) CVE-2011-3624 CWE-138 CWE-138 Medium Ruby Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2019-16254) CVE-2019-16254 CWE-138 CWE-138 Medium Ruby Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2013-4164) CVE-2013-4164 CWE-119 CWE-119 Medium Ruby Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2014-4975) CVE-2014-4975 CWE-119 CWE-119 Medium Ruby Numeric Errors Vulnerability (CVE-2009-1904) CVE-2009-1904 Medium Ruby Numeric Errors Vulnerability (CVE-2011-0188) CVE-2011-0188 Medium Ruby on Rails Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2007-6077) CVE-2007-6077 CWE-362 CWE-362 Medium Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-5189) CVE-2008-5189 CWE-352 CWE-352 Medium Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-0447) CVE-2011-0447 CWE-352 CWE-352 Medium Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-8166) CVE-2020-8166 CWE-352 CWE-352 Medium Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-8167) CVE-2020-8167 CWE-352 CWE-352 Medium Ruby on Rails CVE-2015-3227 Vulnerability (CVE-2015-3227) CVE-2015-3227 Medium Ruby on Rails CVE-2018-16477 Vulnerability (CVE-2018-16477) CVE-2018-16477 Medium Ruby on Rails CVE-2022-23633 Vulnerability (CVE-2022-23633) CVE-2022-23633 Medium Ruby on Rails CVE-2022-23634 Vulnerability (CVE-2022-23634) CVE-2022-23634 Medium Ruby on Rails CVE-2024-26144 Vulnerability (CVE-2024-26144) CVE-2024-26144 Medium Ruby on Rails Data Processing Errors Vulnerability (CVE-2014-3916) CVE-2014-3916 Medium Ruby on Rails Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3086) CVE-2009-3086 CWE-200 CWE-200 Medium Ruby on Rails Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6497) CVE-2012-6497 CWE-200 CWE-200 Medium Ruby on Rails Improper Access Control Vulnerability (CVE-2015-7577) CVE-2015-7577 CWE-284 CWE-284 Medium Ruby on Rails Improper Authentication Vulnerability (CVE-2012-3424) CVE-2012-3424 CWE-287 CWE-287 Medium Ruby on Rails Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-3186) CVE-2011-3186 CWE-94 CWE-94 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2008-7248) CVE-2008-7248 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2010-3933) CVE-2010-3933 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2011-2929) CVE-2011-2929 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2011-3187) CVE-2011-3187 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-1854) CVE-2013-1854 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-1856) CVE-2013-1856 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-3221) CVE-2013-3221 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-6414) CVE-2013-6414 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2014-0082) CVE-2014-0082 CWE-20 CWE-20 Medium Ruby on Rails Improper Input Validation Vulnerability (CVE-2016-0753) CVE-2016-0753 CWE-20 CWE-20 Medium Ruby on Rails Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-0130) CVE-2014-0130 CWE-22 CWE-22 Medium Ruby on Rails Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-7818) CVE-2014-7818 CWE-22 CWE-22 Medium Ruby on Rails Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-7829) CVE-2014-7829 CWE-22 CWE-22 Medium Ruby on Rails Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2016-2097) CVE-2016-2097 CWE-22 CWE-22 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2007-3227) CVE-2007-3227 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-3009) CVE-2009-3009 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-4214) CVE-2009-4214 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-0446) CVE-2011-0446 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-1497) CVE-2011-1497 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-2197) CVE-2011-2197 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-2931) CVE-2011-2931 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-2932) CVE-2011-2932 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4319) CVE-2011-4319 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-1098) CVE-2012-1098 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-1099) CVE-2012-1099 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-3463) CVE-2012-3463 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-3464) CVE-2012-3464 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-3465) CVE-2012-3465 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-1855) CVE-2013-1855 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-1857) CVE-2013-1857 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-4491) CVE-2013-4491 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-6415) CVE-2013-6415 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-6416) CVE-2013-6416 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-0081) CVE-2014-0081 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-3226) CVE-2015-3226 CWE-707 CWE-707 Medium Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-6316) CVE-2016-6316 CWE-707 CWE-707 Medium 1...89909192...108 90 / 108