| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-29034 | CarrierWave's Content-Type allowlist bypass vulnerability which possibly leads to XSS remained | carrierwaveuploader | carrierwave | Medium | 6.8 | 2024-03-24 19:27:36 | Deep Dive |
| CVE-2023-49090 | CarrierWave has a content-type allowlist bypass vulnerability, possibly leading to XSS | carrierwaveuploader | carrierwave | Medium | 6.8 | 2023-11-29 14:38:52 | Deep Dive |
| CVE-2021-21305 | Code Injection vulnerability in CarrierWave | carrierwaveuploader | carrierwave | High | 7.4 | 2021-02-08 19:20:14 | Deep Dive |
| CVE-2021-21288 | Server-side request forgery in CarrierWave | carrierwaveuploader | carrierwave | Medium | 4.3 | 2021-02-08 19:15:16 | Deep Dive |