rubygems
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 41 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 14, 2012 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →60 malicious Ruby gems downloaded 275,000 times steal credentials
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Denial of service when publishing a package on rubygems.org
rubygems.org MFA Bypass through password reset function could allow account takeover
Unauthorized gem replacement for full names ending in numbers on rubygems.org
RubyGems allows creation of users with arbitrary unverified emails
Unauthorized takeover for new versions of some platform-specific gems
Unauthorized gem takeover for some gems on rubygems.org
Monitor rubygems in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.