Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Rubyonrails Rails | 30/11/2018 | 17/6/2026 | A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and have them executed inline. Additionally, if combined with other techniques such as cookie bombing and… | |
| Modificada | Alta (7.5) | 2.9% | — | Rubyonrails RailsRedhat Cloudforms | 30/11/2018 | 17/6/2026 | A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. | |
| Modificada | Crítica (9.8) | 1.8% | — | Nedap Mysql-binuuid-rails | 24/10/2018 | 17/6/2026 | mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns. | |
| Modificada | Alta (8.8) | 0.98% | — | Rails Admin Project Rails Admin | 5/7/2018 | 17/6/2026 | rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem. | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Grails Fields | 26/6/2018 | 17/6/2026 | Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8. | |
| Modificada | Media (6.1) | 1.3% | — | Rubyonrails Html Sanitizer | 30/3/2018 | 17/6/2026 | There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar… | |
| Modificada | Alta (7.5) | 1.7% | — | Grails Resources | 19/3/2018 | 17/6/2026 | The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized the URI, checked the normalized URI did not step outside the… | |
| Modificada | Media (6.1) | 1.3% | — | Rails Admin Project Rails Admin | 19/1/2018 | 17/6/2026 | An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated… | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Ruby ON Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Ruby ON Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Alta (8.1) | 2.3% | 💥 PoC | Rubyonrails Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Media (5.9) | 1.2% | — | Grails PDF Plugin | 27/2/2017 | 17/6/2026 | XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document. | |
| Modificada | Alta (8.8) | 0.82% | — | Gopivotal Grails | 23/1/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.9% | 💥 PoC | Rubyonrails Rails | 7/9/2016 | 17/6/2026 | Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a… | |
| Modificada | Media (6.1) | 3.4% | — | Rubyonrails RailsRubyonrails Ruby ON RailsDebian Linux | 7/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers. | |
| Modificada | Alta (7.3) | 81% | 💥 Exploit | Debian LinuxRubyonrails RailsRubyonrails Ruby ON Rails | 7/4/2016 | 17/6/2026 | Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method. | |
| Modificada | Media (5.3) | 4.4% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/4/2016 | 17/6/2026 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an… | |
| Modificada | Media (5.3) | 7.2% | — | Rubyonrails RailsDebian LinuxFedoraproject FedoraOpensuse Leap | 16/2/2016 | 17/6/2026 | Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters. | |
| Analizada | Alta (7.5) | 96% | ⚠ Explotación activa💥 Exploit | Rubyonrails RailsOpensuse LeapOpensuseSuse Linux Enterprise Module FOR Containers+2 | 16/2/2016 | 17/6/2026 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a… | |
| Modificada | Alta (7.5) | 9.7% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption)… | |
| Modificada | Alta (7.5) | 6.7% | — | Rubyonrails Rails | 16/2/2016 | 17/6/2026 | actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route. | |
| Modificada | Media (6.1) | 2.2% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node. | |
| Modificada | Media (6.1) | 2.6% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class. | |
| Modificada | Media (6.1) | 2.5% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes. |