Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)96%💥 ExploitRubyonrails RailsRubyonrails Ruby ON Rails30/1/201316/6/2026
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that…
ModificadaAlta (7.5)99%💥 ExploitRubyonrails RailsRubyonrails Ruby ON RailsDebian Linux13/1/201316/6/2026
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service…
ModificadaMedia (6.4)8.2%—Rubyonrails RailsRubyonrails Ruby ON RailsDebian Linux13/1/201316/6/2026
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger…
ModificadaAlta (7.5)4.6%—Rubyonrails RailsRubyonrails Ruby ON Rails4/1/201316/6/2026
SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types…
ModificadaMedia (4.3)2.0%—Rubyonrails RailsRubyonrails Ruby ON Rails10/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
ModificadaMedia (4.3)2.6%—Rubyonrails RailsRubyonrails Ruby ON Rails10/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.
ModificadaMedia (4.3)1.3%—Rubyonrails RailsRubyonrails Ruby ON Rails10/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper.
ModificadaMedia (5)1.9%—Rubyonrails RailsRubyonrails Ruby ON Rails8/8/201216/6/2026
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an…
ModificadaAlta (7.5)3.0%—Rubyonrails RailsRubyonrails Ruby ON Rails22/6/201216/6/2026
The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage…
ModificadaMedia (4.3)3.9%—Rubyonrails RailsRubyonrails Ruby ON Rails22/6/201216/6/2026
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions…
ModificadaMedia (5)4.1%💥 PoCRubyonrails RailsRubyonrails Ruby ON Rails22/6/201216/6/2026
The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that…
ModificadaMedia (6.4)4.6%—Rubyonrails RailsRubyonrails Ruby ON Rails22/6/201216/6/2026
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions…
ModificadaMedia (4.3)2.5%—Rubyonrails RailsRubyonrails Ruby ON Rails13/3/201216/6/2026
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION…
ModificadaMedia (4.3)2.7%—Rubyonrails RailsRubyonrails Ruby ON Rails13/3/201216/6/2026
Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.
ModificadaMedia (4.3)1.6%—Rubyonrails RailsRubyonrails Ruby ON Rails28/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with…
ModificadaMedia (4.3)2.5%—Rubyonrails RailsRubyonrails Ruby ON Rails29/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a malformed Unicode string, related to a "UTF-8 escaping…
ModificadaMedia (4.3)2.5%—Rubyonrails RailsRubyonrails Ruby ON Rails29/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name.
ModificadaAlta (7.5)2.3%—Rubyonrails RailsRubyonrails Ruby ON Rails29/8/201116/6/2026
Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.
ModificadaMedia (5)1.8%—Rubyonrails RailsRubyonrails Ruby ON Rails29/8/201116/6/2026
The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via a crafted URL, related to a "filter skipping vulnerability."
ModificadaMedia (4.3)2.0%—Rubyonrails RailsRubyonrails Ruby ON Rails30/6/201116/6/2026
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string…
ModificadaMedia (4.3)3.0%—Rubyonrails RailsRubyonrails Ruby ON Rails7/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and…
ModificadaCrítica (9.8)3.4%—Rubyonrails Ruby ON RailsApple MAC OS XApple MAC OS X Server10/7/200916/6/2026
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for…
ModificadaMedia (5)1.5%—Rubyonrails RailsRubyonrails Ruby ON Rails21/11/200816/6/2026
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.
ModificadaAlta (7.5)3.0%—Rubyonrails RailsRubyonrails Ruby ON Rails30/9/200816/6/2026
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
ModificadaMedia (6.8)3.6%—David Hansson Ruby ON Rails19/10/200716/6/2026
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."
Orbitaley — Vulnerabilidades