Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.5% | — | Basespace Ruby SDK Project Basespace Ruby SDK | 29/4/2014 | 17/6/2026 | The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote attackers to obtain sensitive information by listing the processes. | |
| Modificada | Media (5.8) | 5.3% | — | Ruby-lang Ruby | 24/4/2014 | 17/6/2026 | The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which allows remote attackers to spoof signatures within the context of a Ruby script that attempts signature verification after performing a certain sequence of filesystem operations. NOTE: this issue… | |
| Modificada | Media (5) | 6.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 20/2/2014 | 17/6/2026 | actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers. | |
| Modificada | Media (4.3) | 4.0% | — | Rubyonrails RailsRubyonrails Ruby ON RailsOpensuseOpensuse Project Opensuse+2 | 20/2/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to… | |
| Modificada | Media (6.8) | 1.3% | — | Rubyonrails Rails | 20/2/2014 | 17/6/2026 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not… | |
| Modificada | Media (4.3) | 2.1% | — | Fedoraproject FedoraJanrain Ruby-openid | 12/12/2013 | 16/6/2026 | The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. | |
| Modificada | Media (6.4) | 2.4% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL… | |
| Modificada | Media (4.3) | 2.0% | — | Rubyonrails Rails | 7/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute. | |
| Modificada | Media (4.3) | 3.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter. | |
| Modificada | Media (5) | 21% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching. | |
| Modificada | Media (4.3) | 2.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback… | |
| Modificada | Media (6.8) | 35% | — | Ruby-lang Ruby | 23/11/2013 | 16/6/2026 | Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a string that is converted to a floating point… | |
| Modificada | Media (6.4) | 2.5% | — | OpensuseRuby-lang Ruby | 2/11/2013 | 16/6/2026 | (1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions. | |
| Modificada | Media (4.3) | 1.7% | — | RubygemsRuby-lang Ruby | 17/10/2013 | 16/6/2026 | Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via… | |
| Modificada | Media (4.3) | 3.3% | — | Redhat Enterprise LinuxRubygemsRuby-lang Ruby | 17/10/2013 | 16/6/2026 | Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted… | |
| Modificada | Media (4.3) | 3.1% | — | Rubyonrails RailsOpensuseDebian Linux | 17/10/2013 | 16/6/2026 | Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message. | |
| Modificada | Media (4.3) | 1.4% | — | Rubygems | 1/10/2013 | 16/6/2026 | RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack. | |
| Modificada | Media (5.8) | 2.5% | — | Rubygems | 1/10/2013 | 16/6/2026 | RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack. | |
| Modificada | Media (6.8) | 2.8% | — | Ruby-lang Ruby | 18/8/2013 | 16/6/2026 | The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers… | |
| Modificada | Media (4.3) | 1.9% | — | Ruby-lang Ruby | 2/5/2013 | 16/6/2026 | The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005. | |
| Modificada | Media (5) | 2.6% | — | Ruby-lang Ruby | 25/4/2013 | 16/6/2026 | Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the name_err_mesg_to_str API function, which marks the string as tainted, a different vulnerability than CVE-2011-1005. | |
| Modificada | Media (5) | 2.2% | — | Ruby-lang Ruby | 25/4/2013 | 16/6/2026 | Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the (1) exc_to_s or (2) name_err_to_s API function, which marks the string as tainted, a different vulnerability than CVE-2012-4466. NOTE: this issue… | |
| Modificada | Media (6.4) | 2.0% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 22/4/2013 | 16/6/2026 | The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on… | |
| Modificada | Media (5) | 6.7% | — | Ruby-lang Ruby | 9/4/2013 | 16/6/2026 | lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack. | |
| Modificada | Media (5) | 1.3% | — | Newrelic Ruby Agent | 9/4/2013 | 16/6/2026 | Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data. |