Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
RubyGems/devise — 6 CVEs · VulnScope
pkg:RubyGems/
devise
6 total CVEs
CRITICAL
1
HIGH
1
MEDIUM
3
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2019-5421
devise Time-of-check Time-of-use Race Condition vulnerability
from 0, < 4.6.0
HIGH
7.5
CVE-2015-8314
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
from 0, < 3.5.4
MEDIUM
6.1
CVE-2026-40295
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
from 0, < 5.0.4
MEDIUM
5.3
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
from 0, < 5.0.3
MEDIUM
5.3
Authentication Bypass in Devise
from 0, < 4.7.1
—
Devise does not properly perform type conversion when performing database queries
>= 2.2.0, < 2.2.3
CVE-2026-32700
CVE-2019-16109
CVE-2013-0233