Dependency scanning
Check whether activerecord is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2022-32224
Active Record RCE bug with Serialized Columns
CVE-2025-55193
Active Record logging vulnerable to ANSI escape injection
CVE-2013-3221
Active Record component in Ruby on Rails has a data-type injection vulnerability
CVE-2022-44566
Denial of Service Vulnerability in ActiveRecord's PostgreSQL adapter
CVE-2011-2930
activerecord vulnerable to SQL Injection
CVE-2014-3482
SQL Injection in Active Record
CVE-2012-6496
Active Record contains SQL Injection
CVE-2012-2695
activerecord vulnerable to SQL Injection
CVE-2014-0080
Array data injection vulnerability in activerecord
CVE-2010-3933
Rails activerecord gem has Improper Input Validation vulnerability
CVE-2008-4094
Rails ActiveRecord gem vulnerable to SQL injection
CVE-2012-2661
Active Record vulnerable to SQL Injection via nested query parameters
CVE-2013-0277
Active Record contains deserialization of arbitrary YAML
GHSA-7phj-gmgx-2r66
Moderate severity vulnerability that affects activerecord
GHSA-m8h6-m9p5-p2f8
Moderate severity vulnerability that affects activerecord
GHSA-hm48-76wh-q86v
High severity vulnerability that affects activerecord
CVE-2014-3514
Active Record subject to strong parameters protection bypass
CVE-2013-1854
Active Record Improper Input Validation
CVE-2013-0276
ActiveRecord vulnerable to modification of protected model attributes
CVE-2013-0155
Active Record allows bypassing of database-query restrictions
CVE-2014-3483
Active Record contains SQL Injection via improper range quoting
CVE-2011-0448
activerecord vulnerable to SQL Injection
CVE-2023-22794
SQL Injection Vulnerability via ActiveRecord comments
CVE-2016-6317
ActiveRecord in Ruby on Rails allows database-query bypass
CVE-2021-22880
Active Record subject to Regular Expression Denial-of-Service (ReDoS)
CVE-2015-7577
Active Record Improper Access Control
Browse more RubyGems advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes