Vulnerabilities
Summary — last 7 days
New vulnerabilities2,534▼ 359 vs. last week
Critical / high1,338▲ 69 vs. last week
New active exploitation (KEV)6▼ 6 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (8.7) | 0.45% | — | Viewcomponent View Component | 7/17/2026 | 7/29/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream… | |
| Analyzed | Medium (6.8) | 0.33% | — | Viewcomponent View Component | 7/17/2026 | 7/29/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects across calls to render_in; if the same component, collection, or spacer component instance is reused across requests,… | |
| Analyzed | High (7.5) | 0.37% | — | Viewcomponent View Component | 5/26/2026 | 7/24/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe… | |
| Deferred | Medium (6.5) | 0.37% | — | Viewcomponent View ComponentAI | 5/26/2026 | 7/24/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls it with public_send. The code does not verify that the requested method is one of the preview examples explicitly… | |
| Modified | Medium (6.1) | 0.50% | — | Viewcomponent View Component | 1/4/2024 | 6/17/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site scripting vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that… | |
| Modified | Medium (6.1) | 1.1% | — | Github Viewcomponent | 3/2/2022 | 6/17/2026 | VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulnerability that has the potential to impact anyone using translations with the view_component gem. Data received via user input and passed as an interpolation argument to… |