Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Rails-routes-to-json Project Rails-routes-to-json | 24/4/2023 | 17/6/2026 | rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| Modificada | Alta (7.5) | 1.0% | — | Unpoly-rails | 30/3/2023 | 17/6/2026 | Unpoly is a JavaScript framework for server-side web applications. There is a possible Denial of Service (DoS) vulnerability in the `unpoly-rails` gem that implements the Unpoly server protocol for Rails applications. This issues affects Rails applications that operate as an upstream of a load balancer's that uses… | |
| Modificada | Crítica (9.8) | 1.1% | — | Harrys Dynosaur-rails | 21/2/2023 | 17/6/2026 | A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about… | |
| Modificada | Alta (7.5) | 1.0% | — | Rubyonrails Globalid | 9/2/2023 | 17/6/2026 | A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately. | |
| Modificada | Media (6.1) | 0.60% | — | Actionpack Project ActionpackRubyonrails Rails | 9/2/2023 | 17/6/2026 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a… | |
| Modificada | Alta (7.5) | 2.3% | — | Rubyonrails RailsDebian Linux | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the… | |
| Modificada | Alta (7.5) | 1.7% | — | Rubyonrails Rails | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a specially crafted X_FORWARDED_HOST header can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large… | |
| Modificada | Media (4.3) | 0.56% | — | Reddit-on-rails Project Reddit-on-rails | 7/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identified as 7f3c7407d95d532fcc342b00d68d0ea09ca71030. It is… | |
| Modificada | Alta (7.5) | 0.87% | — | Rails-cv-app Project Rails-cv-app | 2/1/2023 | 17/6/2026 | A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/controllers/uploaded_files_controller.rb. The manipulation with the input ../../../etc/passwd leads to path traversal: '../filedir'. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 1.1% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the… | |
| Modificada | Media (6.1) | 1.0% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either… | |
| Modificada | Media (6.1) | 0.89% | — | Rubyonrails Rails Html SanitizersDebian LinuxLoofah Project Loofah | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4. | |
| Modificada | Alta (7.5) | 1.5% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service… | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Grails Spring Security Core | 23/11/2022 | 17/6/2026 | Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework applications, access to the targeted… | |
| Modificada | Media (5.4) | 0.75% | — | Rubyonrails Rails | 26/10/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The real existence of this… | |
| Modificada | Crítica (9.8) | 2.3% | — | Grails | 19/7/2022 | 17/6/2026 | In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader. | |
| Modificada | Media (6.1) | 30% | — | Rubyonrails Rails Html SanitizersFedoraproject FedoraDebian Linux | 24/6/2022 | 17/6/2026 | # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability… | |
| Modificada | Media (6.1) | 1.6% | — | Rubyonrails ActionpackDebian Linux | 26/5/2022 | 17/6/2026 | A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes. | |
| Modificada | Media (6.1) | 1.8% | — | Rubyonrails ActionpackDebian Linux | 26/5/2022 | 17/6/2026 | An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 PoC | Rubyonrails Active StorageDebian Linux | 26/5/2022 | 17/6/2026 | A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments. | |
| Modificada | Media (5.9) | 2.1% | — | PumaRubyonrails RailsDebian LinuxFedoraproject Fedora | 11/2/2022 | 17/6/2026 | Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these… | |
| Modificada | Media (5.9) | 2.2% | — | Rubyonrails RailsDebian Linux | 11/2/2022 | 17/6/2026 | Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked… | |
| Modificada | Media (6.1) | 4.2% | 💥 Exploit | Rubyonrails Rails | 10/1/2022 | 17/6/2026 | A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. | |
| Modificada | Alta (8.8) | 0.63% | — | Discourse Rails Multisite | 15/11/2021 | 17/6/2026 | rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be possible for an attacker to re-use cookies… | |
| Modificada | Media (6.1) | 1.3% | — | Rubyonrails Rails | 19/10/2021 | 16/6/2026 | A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6. |