Brand
Ruby on Rails: actively exploited vulnerabilities
3 vulnerabilities in Ruby on Rails products (Ruby on Rails) are in CISA’s catalog of exploited vulnerabilities. Last added: July 7, 2025.
-
0 vulnerabilities added in the last 12 months
-
3 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Ruby on Rails category to your radar, or open its page.
- Frameworks and libraries 3 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Ruby on Rails3 vulnerabilities, Frameworks
Name used by CISA: Rails. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Ruby on Rails list.
- Rank 1
Ruby on RailsCVE-2019-5418
Rails Ruby on Rails Path Traversal Vulnerability
CVE from 2019, added in 2025
CVSS severity 7.5high
Added Jul 7, 2025
- Rank 2
Ruby on RailsCVE-2014-0130
Ruby on Rails Directory Traversal Vulnerability
CVE from 2014, added in 2022
CVSS severity 7.5high
Added Mar 25, 2022
- Rank 3
Ruby on RailsCVE-2016-0752
Ruby on Rails Directory Traversal Vulnerability
CVE from 2016, added in 2022
CVSS severity 7.5high
Added Mar 25, 2022
Follow and verify
Indicative classification, based on the vendor and product names given by CISA. How products are classified.