Products: 1
Vulnerabilities: 3
Known Exploited: 0
0
Critical Level Threats
1
High Level Threats
2
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-40295
Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
Last Modified: May 29, 2026
Published: May 22, 2026
CVE-2026-32700
Devise has a confirmable "change email" race condition that permits user to confirm email they have no access to
Last Modified: Mar 27, 2026
Published: Mar 18, 2026
CVE-2015-8314
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
Last Modified: May 27, 2025
Published: Dec 12, 2023
Items Per Page
