Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.7% | — | Rubyonrails Rails | 18/10/2021 | 17/6/2026 | A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website. | |
| Modificada | Alta (7.5) | 4.9% | — | Rubyonrails Rails | 11/6/2021 | 17/6/2026 | The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for… | |
| Modificada | Media (6.1) | 1.2% | — | Rubyonrails Rails | 11/6/2021 | 17/6/2026 | The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings… | |
| Modificada | Alta (7.5) | 2.8% | — | Rubyonrails Rails | 11/6/2021 | 17/6/2026 | The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic… | |
| Modificada | Alta (7.5) | 4.1% | — | Rubyonrails RailsRubyonrails Actionpack Page-cachingDebian Linux | 27/5/2021 | 17/6/2026 | A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input. | |
| Modificada | Media (5.3) | 1.8% | — | Rubyonrails Active Record Session Store | 5/3/2021 | 17/6/2026 | The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is valid. Consequently, remote attackers can leverage timing discrepancies to achieve a correct guess in a… | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | Rubyonrails RailsFedoraproject Fedora | 11/2/2021 | 17/6/2026 | The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted… | |
| Modificada | Alta (7.5) | 4.4% | 💥 PoC | Rubyonrails RailsFedoraproject Fedora | 11/2/2021 | 17/6/2026 | The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression,… | |
| Modificada | Media (6.1) | 1.3% | — | Rails Admin Project Rails Admin | 12/1/2021 | 17/6/2026 | RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. | |
| Modificada | Media (6.1) | 67% | — | Rubyonrails Rails | 6/1/2021 | 17/6/2026 | In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the… | |
| Modificada | Media (6.5) | 2.2% | — | Rubyonrails RailsFedoraproject Fedora | 2/7/2020 | 17/6/2026 | A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production. | |
| Modificada | Media (4.3) | 1.7% | — | Rubyonrails RailsDebian Linux | 2/7/2020 | 17/6/2026 | A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token. | |
| Modificada | Alta (8.8) | 82% | 💥 Exploit | Rubyonrails RailsDebian Linux | 2/7/2020 | 17/6/2026 | The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. | |
| Modificada | Media (6.5) | 1.5% | — | Rubyonrails RailsDebian Linux | 19/6/2020 | 17/6/2026 | A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. | |
| Modificada | Crítica (9.8) | 46% | 💥 PoC | Rubyonrails RailsDebian LinuxOpensuse Leap | 19/6/2020 | 17/6/2026 | A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE. | |
| Modificada | Alta (7.5) | 4.9% | — | Rubyonrails RailsDebian LinuxOpensuse Backports SLEOpensuse Leap | 19/6/2020 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. | |
| Modificada | Alta (7.5) | 3.0% | 💥 PoC | Rubyonrails RailsDebian Linux | 19/6/2020 | 17/6/2026 | A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits. | |
| Modificada | Crítica (9.8) | 5.4% | — | Rubyonrails Actionpack Page-cachingDebian Linux | 12/5/2020 | 17/6/2026 | There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view. | |
| Modificada | Alta (7.5) | 2.2% | — | Rubyonrails Active ResourceFedoraproject Fedora | 12/5/2020 | 17/6/2026 | There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information. | |
| Modificada | Media (4.8) | 1.5% | 💥 PoC | Rubyonrails ActionviewDebian LinuxFedoraproject FedoraOpensuse Leap | 19/3/2020 | 17/6/2026 | In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2. | |
| Modificada | Media (6.5) | 1.1% | — | Rubyonrails RailsDebian Linux | 12/11/2019 | 16/6/2026 | The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. | |
| Modificada | Alta (8.1) | 0.83% | — | Grails | 4/6/2019 | 17/6/2026 | Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP. | |
| Modificada | Crítica (9.8) | 89% | 💥 Exploit | Rubyonrails RailsDebian LinuxFedoraproject Fedora | 27/3/2019 | 17/6/2026 | A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit. | |
| Modificada | Alta (7.5) | 8.8% | — | Rubyonrails RailsDebian LinuxRedhat CloudformsRedhat Software Collections+2 | 27/3/2019 | 17/6/2026 | There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive. | |
| Analizada | Alta (7.5) | 99% | ⚠ Explotación activa💥 Exploit | Rubyonrails RailsDebian LinuxRedhat CloudformsOpensuse Leap+2 | 27/3/2019 | 17/6/2026 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed. |