Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.3%—RubygemsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+431/8/201717/6/2026
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
ModificadaCrítica (9.8)11%—RubygemsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+431/8/201717/6/2026
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
ModificadaCrítica (9.8)9.4%—Ruby-lang RubyDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+531/8/201717/6/2026
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning a pointer to a string of length zero, which is not the length stored…
ModificadaCrítica (9.8)1.7%—Ruby-lang Ruby19/7/201717/6/2026
The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script, related to the parser_tokadd_utf8 function in parse.y. NOTE: this might have security relevance as a bypass of a $SAFE…
ModificadaMedia (6.1)3.7%—Ruby-lang Ruby12/6/201717/6/2026
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
ModificadaAlta (7.8)0.97%—MrubyDebian Linux11/6/201717/6/2026
The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.
ModificadaAlta (7.5)5.1%—Oniguruma Project OnigurumaPHPRuby-lang Ruby24/5/201717/6/2026
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in left_adjust_char_head() during regular expression compilation. Invalid handling of reg->dmax in forward_search_range() could result in an invalid pointer dereference,…
ModificadaCrítica (9.8)3.1%—Oniguruma Project OnigurumaPHPRuby-lang Ruby24/5/201717/6/2026
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code point 0xFFFFFFFF is not properly handled in unicode_unfold_key().…
ModificadaCrítica (9.8)6.2%—Smalruby-editor28/4/201717/6/2026
smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
ModificadaAlta (7.5)3.6%—Ruby-lang Ruby3/4/201717/6/2026
The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted regular expression.
ModificadaAlta (7.3)7.8%—Ruby-lang Ruby29/3/201716/6/2026
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
ModificadaCrítica (9.8)2.4%—Espeak-ruby Project Espeak-ruby3/3/201717/6/2026
The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the speak, save, bytes or bytes_wav method in lib/espeak/speech.rb.
ModificadaCrítica (9.8)3.4%—Rubyzip Project RubyzipDebian Linux27/2/201717/6/2026
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.
ModificadaAlta (7.5)3.2%—Ruby-lang OpensslDebian Linux30/1/201717/6/2026
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
ModificadaAlta (7.5)1.2%—Onelogin Ruby-saml23/1/201717/6/2026
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
ModificadaCrítica (9.8)5.1%—Ruby-lang Ruby6/1/201717/6/2026
An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array…
ModificadaCrítica (9.8)6.2%—Ruby-lang Ruby6/1/201717/6/2026
Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.
ModificadaCrítica (9.8)3.4%—Ruby-lang Ruby6/1/201717/6/2026
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.
ModificadaAlta (7.5)3.9%—Rubyonrails Rails7/9/201617/6/2026
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a…
ModificadaMedia (6.1)3.4%—Rubyonrails RailsRubyonrails Ruby ON RailsDebian Linux7/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.
ModificadaAlta (7.3)81%—Debian LinuxRubyonrails RailsRubyonrails Ruby ON Rails7/4/201617/6/2026
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
ModificadaMedia (5.3)4.4%—Rubyonrails RailsRubyonrails Ruby ON Rails7/4/201617/6/2026
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an…
ModificadaAlta (8.4)0.50%—Apple MAC OS XRuby-lang Ruby24/3/201617/6/2026
The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application…
ModificadaMedia (5.3)7.2%—Rubyonrails RailsDebian LinuxFedoraproject FedoraOpensuse Leap16/2/201617/6/2026
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
AnalizadaAlta (7.5)96%⚠ Explotación activaRubyonrails RailsOpensuse LeapOpensuseSuse Linux Enterprise Module FOR Containers+216/2/201617/6/2026
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a…