Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.7) | 0.19% | — | JrubyJruby-openssl | 7/5/2025 | 17/6/2026 | JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby-OpenSSL does not… | |
| Analizada | Media (6) | 0.49% | — | Ruby-lang Net\ | 28/4/2025 | 17/6/2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any time while the client is connected, a malicious server can send… | |
| Analizada | Media (6.5) | 0.25% | — | Jetbrains Rubymine | 17/4/2025 | 17/6/2026 | In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces | |
| Modificada | Alta (7.7) | 1.5% | — | Omniauth SamlOnelogin Ruby-saml | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to… | |
| Modificada | Crítica (9.3) | 65% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document… | |
| Modificada | Crítica (9.3) | 21% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document… | |
| Aplazada | Crítica (9) | 3.1% | — | Graphql RubyAI | 12/3/2025 | 17/6/2026 | graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any… | |
| Analizada | Alta (7.5) | 0.71% | — | Ruby-lang Javascript Object Notation | 12/3/2025 | 17/6/2026 | JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions prior to 2.10.0 are not vulnerable. Version 2.10.2 fixes the problem. No known workarounds are available. | |
| Modificada | Media (5.3) | 0.51% | — | Ruby-lang URI | 4/3/2025 | 17/6/2026 | In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. | |
| Modificada | Alta (7.5) | 0.76% | — | Ruby-lang CGI | 4/3/2025 | 17/6/2026 | In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method. | |
| Modificada | Alta (7.5) | 0.85% | — | Ruby-lang CGI | 4/3/2025 | 17/6/2026 | In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely… | |
| Aplazada | Alta (8.8) | 0.24% | — | GradleAINet.rubygrapefruit Native-platformAI | 25/2/2025 | 17/6/2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library initialization could be vulnerable to a local… | |
| Aplazada | Media (6.5) | 0.63% | — | Ruby Net-imapAI | 10/2/2025 | 17/6/2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious… | |
| Aplazada | Alta (7.4) | 0.65% | — | RubyAI | 9/1/2025 | 30/6/2026 | A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service. | |
| Aplazada | Media (4) | 0.33% | — | Rubyonrails RailsAI | 9/1/2025 | 17/6/2026 | The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. | |
| Aplazada | Baja (2.3) | 1.0% | — | Rubyonrails Action PackAI | 10/12/2024 | 17/6/2026 | Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper starting in version 5.2.0 of Action Pack and prior to versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1. Applications which set… | |
| Analizada | Baja (2.3) | 0.45% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Analizada | Baja (2.3) | 0.45% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Analizada | Baja (2.3) | 0.47% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Analizada | Baja (2.3) | 0.60% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of… | |
| Analizada | Baja (2.3) | 0.47% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Modificada | Media (6.6) | 1.4% | — | Ruby-lang RexmlNetapp Ontap Tools | 28/10/2024 | 17/6/2026 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later… | |
| Aplazada | Media (6.6) | 0.94% | — | Rubyonrails Action MailerAI | 16/10/2024 | 17/6/2026 | Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action Mailer. Carefully crafted text can cause the block_format helper to take an unexpected… | |
| Aplazada | Media (6.6) | 1.0% | — | Rubyonrails Action PackAI | 16/10/2024 | 17/6/2026 | Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in Action Controller's HTTP Token authentication. For applications using HTTP Token authentication via… | |
| Aplazada | Media (6.6) | 1.1% | — | Rubyonrails Action PackAIRubyonrails Action DispatchAI | 16/10/2024 | 17/6/2026 | Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dispatch. Carefully crafted query parameters can cause query… |