Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Critical
Apache Struts
Apache Struts 2
Command Injection
>= 2.3.5 - <2.3.31, >=2.5 - <2.5.10
Mar 16, 2017
High
Apache Struts
Apache Struts
Remote Code Execution
>=2.3.19 <2.3.20.3, >=2.3.21 <2.3.24.3, >=2.3.25 <2.3.28.1
Apr 20, 2016
High
Rails
Ruby on Rails Framework
Remote Code Execution
<= 3.2.22.1 <= 4.1.14.1 <= 4.2.5.1
Apr 7, 2016
High
Rails
Ruby on Rails Framework
Cross-Site Scripting
< 5.0.0.beta1 <= 4.2.5.0 <= 4.1.14.0
Feb 15, 2016
High
Rails
Ruby on Rails Framework
Denial of Service
<=4.0.6 <=4.1.3 Only for instances using PostgreSQL
Jul 7, 2014
High
Spring
Spring Security
Authorization Bypass
>=3.1.0 <3.1.6, >=3.2.0 <3.2.2
Mar 11, 2014
Medium
Apache Struts
Apache Struts
Remote Code Execution
>=2.0.0, <2.3.16.2
Mar 6, 2014
Critical
Rails
Ruby on Rails Framework
Remote Code Execution
3.0.0 - <3.1.0 2.0.0 - <2.3.17
Feb 12, 2013
High
Rails
Ruby on Rails Framework
Remote Code Execution
<= 2.3.15 <= 3.0.19 <= 3.1.9 <= 3.2.10 Not affected: • applications using the yajl gem
Jan 13, 2013
Medium
Spring
Spring Security
Authorization Bypass
<2.0.9, >=3.0.0, <3.0.9, >=3.1.0, <3.1.4
Dec 12, 2012
High
Rails
Ruby on Rails Framework
Command Injection
<=3.2.5 <=3.1.5 <=3.0.13
Jun 22, 2012
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.