Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

201 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.3)1.0%—Rubyonrails Action PackAI10/12/202417/6/2026
Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper starting in version 5.2.0 of Action Pack and prior to versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1. Applications which set…
AnalizadaBaja (2.3)0.45%—Rubyonrails Rails Html Sanitizers2/12/202417/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an…
AnalizadaBaja (2.3)0.45%—Rubyonrails Rails Html Sanitizers2/12/202417/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an…
AnalizadaBaja (2.3)0.47%—Rubyonrails Rails Html Sanitizers2/12/202417/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an…
AnalizadaBaja (2.3)0.60%—Rubyonrails Rails Html Sanitizers2/12/202417/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of…
AnalizadaBaja (2.3)0.47%—Rubyonrails Rails Html Sanitizers2/12/202417/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an…
AplazadaMedia (6.6)0.94%—Rubyonrails Action MailerAI16/10/202417/6/2026
Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action Mailer. Carefully crafted text can cause the block_format helper to take an unexpected…
AplazadaMedia (6.6)0.98%—Rails Action TextAI16/10/202417/6/2026
Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node helper` in Action Text. Carefully crafted text can cause the `plain_text_for_blockquote_node`…
AplazadaMedia (6.6)1.0%—Rubyonrails Action PackAI16/10/202417/6/2026
Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in Action Controller's HTTP Token authentication. For applications using HTTP Token authentication via…
AplazadaMedia (6.6)1.1%—Rubyonrails Action PackAIRubyonrails Action DispatchAI16/10/202417/6/2026
Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dispatch. Carefully crafted query parameters can cause query…
AplazadaAlta (7.8)0.38%—Guardrailsai GuardrailsAI18/9/202417/6/2026
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the…
AplazadaCrítica (9.6)0.62%—ElektraAIRubyonrails RailsAI1/8/202417/6/2026
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an…
AplazadaMedia (5.9)0.41%—Guardrailsai GuardrailsAI21/7/202417/6/2026
RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL documents from external sources are vulnerable to XXE, which may cause leakage of internal file data via the SYSTEM entity.
AplazadaAlta (8.3)1.0%—Rubyonrails Ruby ON RailsAIHavenweb HavenAI19/7/202417/6/2026
A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functionality requires authentication, but an attacker can craft a link that they can pass to a logged in administrator of the blog software. This leads to the immediate…
ModificadaMedia (5.4)0.58%—Rails Admin Project Rails Admin8/7/202417/6/2026
RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. Upgrade to 3.1.3 or 2.2.2 (to be released).
ModificadaMedia (6.1)0.43%—Rubyonrails Rails4/6/202417/6/2026
Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability is fixed in 7.1.3.4 and 7.2.0.beta2.
ModificadaCrítica (9.8)0.66%—Rubyonrails Rails4/6/202417/6/2026
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.
AnalizadaMedia (5.3)1.1%💥 PoCRubyonrails Rails27/2/202417/6/2026
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the…
AnalizadaMedia (6.1)1.0%—Rubyonrails Rails27/2/202417/6/2026
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is…
AnalizadaAlta (7.5)1.5%—Rubyonrails Rails27/2/202417/6/2026
Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.
ModificadaAlta (7.5)0.72%—Grails21/12/202317/6/2026
Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.
ModificadaMedia (5.5)0.37%—Xaviershay-dm-rails Porject Xaviershay-dm-rails12/12/202317/6/2026
The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and its arguments.
ModificadaCrítica (9.8)3.2%—Geokit-rails6/10/202317/6/2026
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.
ModificadaBaja (3.5)0.14%—BD Guardrails CQI Reporter13/7/202317/6/2026
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
ModificadaMedia (6.7)0.18%—BD Alaris Guardrails Editor13/7/202317/6/2026
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.