Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2604▼ 298 respecto a la semana anterior
Críticas / altas1343▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 9.7% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption)… | |
| Modificada | Alta (7.5) | 6.7% | — | Rubyonrails Rails | 16/2/2016 | 17/6/2026 | actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route. | |
| Modificada | Media (6.1) | 2.2% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node. | |
| Modificada | Media (6.1) | 2.6% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class. | |
| Modificada | Media (6.1) | 2.5% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes. | |
| Modificada | Media (5.3) | 4.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change… | |
| Modificada | Baja (3.7) | 4.9% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time… | |
| Modificada | Media (4.3) | 3.5% | — | Oracle SolarisRubygems | 25/8/2015 | 17/6/2026 | RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a domain that is suffixed with the original domain name, aka a… | |
| Modificada | Media (5) | 4.3% | — | OpensuseRubyonrails Rails | 26/7/2015 | 17/6/2026 | The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth. | |
| Modificada | Media (4.3) | 2.8% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 26/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding. | |
| Modificada | Media (4.3) | 45% | — | Rubyonrails WEB Console | 26/7/2015 | 17/6/2026 | request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request. | |
| Modificada | Media (5) | 4.5% | — | Fedoraproject FedoraRubyonrails Jquery-railsRubyonrails Jquery-ujsOpensuse | 26/7/2015 | 17/6/2026 | jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL… | |
| Modificada | Media (5) | 8.9% | — | Ruby-lang RubyRubygemsOracle SolarisRedhat Enterprise Linux | 24/6/2015 | 17/6/2026 | RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack." | |
| Modificada | Media (5) | 2.4% | — | Getsentry Raven-ruby | 20/1/2015 | 17/6/2026 | The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number. | |
| Modificada | Media (5) | 5.6% | — | Ruby-lang Ruby | 21/11/2014 | 17/6/2026 | The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity… | |
| Modificada | Media (5) | 4.2% | — | OpensuseRubyonrails RailsRubyonrails Ruby ON Rails | 18/11/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the… | |
| Modificada | Media (5) | 1.4% | — | Rubyonrails Rails | 16/11/2014 | 17/6/2026 | The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string. | |
| Modificada | Media (5) | 3.5% | — | Ruby-lang RubyRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+3 | 15/11/2014 | 17/6/2026 | Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow. | |
| Modificada | Media (4.3) | 3.5% | — | Rubyonrails RailsRubyonrails Ruby ON RailsOpensuse | 8/11/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the… | |
| Modificada | Media (5) | 5.5% | — | OpensuseCanonical Ubuntu LinuxRuby-lang RubyRedhat Enterprise Linux | 3/11/2014 | 17/6/2026 | The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack. | |
| Modificada | Media (5.4) | 0.27% | — | Rubycell Piano Teacher | 9/9/2014 | 17/6/2026 | The Piano Teacher (aka com.rubycell.pianisthd) application 20140730 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.8% | — | Rubyonrails Rails | 20/8/2014 | 17/6/2026 | activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls. | |
| Modificada | Alta (7.5) | 4.2% | — | Rubyonrails Rails | 7/7/2014 | 17/6/2026 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting. | |
| Modificada | Alta (7.5) | 4.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/7/2014 | 17/6/2026 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting. | |
| Analizada | Alta (7.5) | 54% | ⚠ Explotación activa | Redhat Subscription Asset ManagerRedhat Enterprise Linux ServerRubyonrails Rails | 7/5/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request. |