Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.0%—Ruby-openid10/6/201917/6/2026
Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their…
ModificadaAlta (7.4)4.2%—Rubygems6/6/201917/6/2026
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary…
ModificadaMedia (5.5)0.55%—Ruby-lang Webrick10/5/201917/6/2026
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore it is "not a problem.
ModificadaCrítica (9.8)2.5%—Onelogin Ruby-saml17/4/201917/6/2026
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service…
ModificadaCrítica (9.8)89%—Rubyonrails RailsDebian LinuxFedoraproject Fedora27/3/201917/6/2026
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
ModificadaAlta (7.5)8.8%—Rubyonrails RailsDebian LinuxRedhat CloudformsRedhat Software Collections+227/3/201917/6/2026
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
AnalizadaAlta (7.5)99%⚠ Explotación activaRubyonrails RailsDebian LinuxRedhat CloudformsOpensuse Leap+227/3/201917/6/2026
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
ModificadaMedia (6.5)1.3%—Rubyonrails Rails30/11/201817/6/2026
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and have them executed inline. Additionally, if combined with other techniques such as cookie bombing and…
ModificadaAlta (7.5)2.9%—Rubyonrails RailsRedhat Cloudforms30/11/201817/6/2026
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
ModificadaAlta (8.1)8.0%—Ruby-lang RubyCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux16/11/201817/6/2026
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
ModificadaCrítica (9.8)11%—Ruby-lang OpensslRuby-lang RubyCanonical Ubuntu LinuxDebian Linux+116/11/201817/6/2026
An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects are compared using ==, depending on the ordering, non-equal objects may return true. When the first argument is one character longer than…
ModificadaAlta (7.5)1.4%—MrubyDebian Linux17/7/201817/6/2026
The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory access because the mrb_str_resize function in string.c does not check for a negative length.
ModificadaMedia (6.1)1.4%—Ruby-grape Grape5/7/201817/6/2026
ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.
ModificadaCrítica (9.8)4.4%—Rubyzip Project RubyzipDebian LinuxRedhat Cloudforms26/6/201817/6/2026
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains…
ModificadaAlta (7.8)1.4%—Ruby-ffi Project Ruby-ffi22/6/201817/6/2026
ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.
ModificadaAlta (7.5)2.1%—MrubyDebian Linux12/6/201817/6/2026
An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.
ModificadaAlta (7.5)1.5%—Mruby12/6/201817/6/2026
An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does not extend the stack in cases of many arguments to fiber.
ModificadaAlta (7.5)1.6%—Mruby12/6/201817/6/2026
An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usage, because mrb_obj_clone in kernel.c copies flags other than the MRB_FLAG_IS_FROZEN flag (e.g., the embedded flag).
ModificadaCrítica (9.8)2.2%—MrubyDebian Linux5/6/201817/6/2026
The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialized pointer and application crash) or possibly have unspecified other impact.
ModificadaCrítica (9.8)2.3%—Mruby18/4/201817/6/2026
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.
ModificadaCrítica (9.8)2.6%—MrubyDebian Linux17/4/201817/6/2026
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.
ModificadaCrítica (9.1)9.7%—Ruby-lang RubyCanonical Ubuntu LinuxDebian Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
ModificadaAlta (7.5)6.9%—Ruby-lang RubyCanonical Ubuntu LinuxDebian Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
ModificadaAlta (7.5)7.5%—Ruby-lang RubyCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.
ModificadaAlta (7.5)4.5%—Ruby-lang RubyDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of service (memory consumption).