Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.59% | — | Rubyonrails Rails | 24/3/2026 | 17/6/2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands delimiters. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, the interaction between the repeated… | |
| Analizada | Baja (1.3) | 0.33% | — | Rubyonrails Rails | 23/3/2026 | 12/8/2026 | Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This… | |
| Modificada | Alta (8.3) | 1.0% | — | Ruby-lang Json | 20/3/2026 | 21/8/2026 | Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This… | |
| Aplazada | Alta (7.5) | 0.34% | — | Themeruby Easy Post SubmissionAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Post Submission: from n/a through <= 2.4.0. | |
| Aplazada | Alta (7.5) | 0.49% | — | Ruby-lang RexmlAI | 27/2/2026 | 26/6/2026 | A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected component. This issue is… | |
| Modificada | Alta (8.8) | 0.78% | — | Redhat SatelliteLogicminds Rubyipmi | 27/2/2026 | 17/6/2026 | A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution… | |
| Analizada | Baja (1.9) | 0.16% | — | Mruby | 6/2/2026 | 17/6/2026 | A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called… | |
| Aplazada | Crítica (9.2) | 5.5% | — | Ruby-vips Image ProcessingAIImagemagick Mini MagickAIRubyonrails Active StorageAI | 30/1/2026 | 15/7/2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command… | |
| Aplazada | Media (6.4) | 0.27% | — | Themeruby Multi AuthorsAI | 24/1/2026 | 17/6/2026 | The ThemeRuby Multi Authors – Assign Multiple Writers to Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' shortcode attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Baja (2.1) | 0.56% | — | Ruby-lang URI | 30/12/2025 | 17/6/2026 | URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the… | |
| Aplazada | Media (6) | 0.21% | — | Amazon SDK FOR RubyAI | 17/12/2025 | 30/9/2026 | Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby… | |
| Aplazada | Media (6.5) | 0.46% | — | AltchaAIAltcha-libAIAltcha RubygemAIAltcha PIPAI+4 | 16/12/2025 | 17/6/2026 | ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce, allowing an attacker to reinterpret a valid… | |
| Analizada | Crítica (9.3) | 0.23% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When… | |
| Analizada | Crítica (9.3) | 0.39% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from… | |
| Analizada | Media (4.8) | 0.14% | — | S-itoc Mruby/c | 19/11/2025 | 17/6/2026 | A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file src/alloc.c. Such manipulation of the argument ptr leads to null pointer dereference. An attack has to be approached locally. The name of the patch is 009111904807b8567262036bf45297c3da8f1c87. It is… | |
| Modificada | Baja (1.9) | 0.15% | — | Mruby | 13/11/2025 | 17/6/2026 | A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is… | |
| Modificada | Baja (1.9) | 0.16% | — | Mruby | 7/11/2025 | 17/6/2026 | A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing a manipulation of the argument start/length can lead to out-of-bounds write. The attack needs to be launched locally. The exploit has been made available to… | |
| Aplazada | Media (5.5) | 0.19% | — | Themeruby Easy Post SubmissionAI | 22/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Retrieve Embedded Sensitive Data.This issue affects Easy Post Submission: from n/a through <= 1.7.0. | |
| Analizada | Baja (1.2) | 0.25% | — | Ruby-lang Rexml | 17/9/2025 | 17/6/2026 | REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities. | |
| Aplazada | Media (4.2) | 0.24% | — | Basecamp Google Sign INAIRubyonrails RailsAI | 27/8/2025 | 17/6/2026 | Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.0, it is possible to craft a malformed URL that passes the "same origin" check, resulting in the user being redirected to another origin. Rails applications configured to store the flash information in a session cookie may be… | |
| Aplazada | Baja (2.7) | 0.59% | — | Rubyonrails Active RecordAI | 13/8/2025 | 17/6/2026 | Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2,… | |
| Aplazada | Crítica (9.1) | 0.16% | — | Ruby-jwtAI | 7/8/2025 | 17/6/2026 | ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also." | |
| Aplazada | Media (6.9) | 0.40% | — | Onelogin Ruby-samlAI | 30/7/2025 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to… | |
| Analizada | Baja (1.9) | 0.24% | — | Mruby | 9/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has… | |
| Analizada | Media (5.9) | 0.50% | — | Ruby-lang Webrick | 25/6/2025 | 17/6/2026 | Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists… |