Vulnerabilities > Rubyonrails > Ruby ON Rails > High

DATE CVE VULNERABILITY TITLE RISK
2017-12-29 CVE-2017-17920 SQL Injection vulnerability in Rubyonrails Ruby on Rails
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter.
network
high complexity
rubyonrails CWE-89
8.1
2017-12-29 CVE-2017-17919 SQL Injection vulnerability in Rubyonrails Ruby on Rails
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter.
network
high complexity
rubyonrails CWE-89
8.1
2016-04-07 CVE-2016-2098 Improper Input Validation vulnerability in multiple products
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
network
low complexity
debian rubyonrails CWE-20
7.3
2016-02-16 CVE-2016-0751 Resource Management Errors vulnerability in Rubyonrails Ruby on Rails
actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.
network
low complexity
rubyonrails CWE-399
7.5