ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-16254
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).

The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).

NVD description · AI analysis pending
6.1<1% PoC
  • chartkick project chartkick
CVE-2019-18841
Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.

Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.

NVD description · AI analysis pending
7.31%
  • chartkick chartkick.js
CVE-2019-12732
The Chartkick gem through 3.1.0 for Ruby allows XSS.

The Chartkick gem through 3.1.0 for Ruby allows XSS.

NVD description · AI analysis pending
4.7<1% PoC
  • chartkick project chartkick