Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.6% | — | Rubygems Mini Magick | 20/3/2013 | 16/6/2026 | lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Alta (7.5) | 2.3% | — | Rubygems Fastreader | 20/3/2013 | 16/6/2026 | lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Alta (7.5) | 3.6% | — | Rubygems Command Wrap | 20/3/2013 | 16/6/2026 | command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename. | |
| Modificada | Media (4.3) | 1.9% | — | Redhat Enterprise LinuxRubyonrails RailsRubyonrails Ruby ON Rails | 19/3/2013 | 16/6/2026 | The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct… | |
| Modificada | Media (5.8) | 2.1% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 19/3/2013 | 16/6/2026 | The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files… | |
| Modificada | Media (4.3) | 2.6% | — | Rubyonrails RailsRubyonrails Ruby ON RailsRedhat Enterprise Linux | 19/3/2013 | 16/6/2026 | The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site… | |
| Modificada | Media (5) | 3.5% | — | Rubyonrails RailsRubyonrails Ruby ON RailsRedhat Enterprise Linux | 19/3/2013 | 16/6/2026 | The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method. | |
| Modificada | Media (4.3) | 3.0% | — | Ruby-lang RdocRuby-lang RubyCanonical Ubuntu Linux | 1/3/2013 | 16/6/2026 | darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL. | |
| Modificada | Baja (2.1) | 0.34% | — | Ryan Davis Ruby Parser | 1/3/2013 | 16/6/2026 | The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp. | |
| Modificada | Alta (10) | 7.5% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 13/2/2013 | 16/6/2026 | ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML. | |
| Modificada | Media (4.3) | 2.5% | — | Rubyonrails Rails | 13/2/2013 | 16/6/2026 | ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request. | |
| Modificada | Alta (7.5) | 13% | — | Rubygems Json GEM | 13/2/2013 | 16/6/2026 | The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as… | |
| Modificada | Alta (7.5) | 96% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 30/1/2013 | 16/6/2026 | lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that… | |
| Modificada | Alta (7.5) | 99% | — | Rubyonrails RailsRubyonrails Ruby ON RailsDebian Linux | 13/1/2013 | 16/6/2026 | active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service… | |
| Modificada | Media (6.4) | 8.2% | — | Rubyonrails RailsRubyonrails Ruby ON RailsDebian Linux | 13/1/2013 | 16/6/2026 | Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger… | |
| Modificada | Media (5) | 2.7% | — | Rubyonrails Rails | 4/1/2013 | 16/6/2026 | The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a… | |
| Modificada | Alta (7.5) | 4.6% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 4/1/2013 | 16/6/2026 | SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types… | |
| Modificada | Media (5) | 3.3% | — | Ruby-lang Ruby | 28/11/2012 | 16/6/2026 | Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as… | |
| Modificada | Media (5) | 2.2% | — | Jruby | 28/11/2012 | 16/6/2026 | JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack… | |
| Modificada | Media (5) | 2.2% | — | Ruby-lang Ruby | 24/11/2012 | 16/6/2026 | The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path. | |
| Modificada | Media (4.3) | 2.2% | — | Jruby | 23/11/2012 | 16/6/2026 | The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string. | |
| Modificada | Media (6.7) | 0.99% | — | Ruby-lang Ruby | 11/10/2012 | 16/6/2026 | Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\Ruby193\bin directory, which may be added to the PATH system environment variable by an administrator, as… | |
| Modificada | Media (4.3) | 2.0% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 10/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup. | |
| Modificada | Media (4.3) | 2.6% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 10/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character. | |
| Modificada | Media (4.3) | 1.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 10/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper. |