Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 4.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change… | |
| Modificada | Baja (3.7) | 4.9% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time… | |
| Modificada | Media (5) | 4.3% | — | OpensuseRubyonrails Rails | 26/7/2015 | 17/6/2026 | The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth. | |
| Modificada | Media (4.3) | 2.8% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 26/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding. | |
| Modificada | Media (4.3) | 45% | 💥 Exploit | Rubyonrails WEB Console | 26/7/2015 | 17/6/2026 | request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request. | |
| Modificada | Media (5) | 4.5% | — | Fedoraproject FedoraRubyonrails Jquery-railsRubyonrails Jquery-ujsOpensuse | 26/7/2015 | 17/6/2026 | jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL… | |
| Modificada | Media (5) | 4.2% | — | OpensuseRubyonrails RailsRubyonrails Ruby ON Rails | 18/11/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the… | |
| Modificada | Media (5) | 1.4% | — | Rubyonrails Rails | 16/11/2014 | 17/6/2026 | The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string. | |
| Modificada | Media (4.3) | 3.5% | — | Rubyonrails RailsRubyonrails Ruby ON RailsOpensuse | 8/11/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the… | |
| Modificada | Alta (7.5) | 2.8% | — | Rubyonrails Rails | 20/8/2014 | 17/6/2026 | activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls. | |
| Modificada | Alta (7.5) | 4.2% | — | Rubyonrails Rails | 7/7/2014 | 17/6/2026 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting. | |
| Modificada | Alta (7.5) | 4.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/7/2014 | 17/6/2026 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting. | |
| Analizada | Alta (7.5) | 54% | ⚠ Explotación activa💥 PoC | Redhat Subscription Asset ManagerRedhat Enterprise Linux ServerRubyonrails Rails | 7/5/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request. | |
| Modificada | Media (5) | 3.1% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability… | |
| Modificada | Media (5) | 1.4% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to… | |
| Modificada | Media (5) | 2.0% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different… | |
| Modificada | Media (5) | 6.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 20/2/2014 | 17/6/2026 | actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers. | |
| Modificada | Media (4.3) | 4.0% | — | Rubyonrails RailsRubyonrails Ruby ON RailsOpensuseOpensuse Project Opensuse+2 | 20/2/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to… | |
| Modificada | Media (6.8) | 1.3% | — | Rubyonrails Rails | 20/2/2014 | 17/6/2026 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not… | |
| Modificada | Media (6.4) | 2.4% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL… | |
| Modificada | Media (4.3) | 2.0% | — | Rubyonrails Rails | 7/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute. | |
| Modificada | Media (4.3) | 3.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter. | |
| Modificada | Media (5) | 21% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching. | |
| Modificada | Media (4.3) | 2.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback… | |
| Modificada | Media (4.3) | 3.1% | — | Rubyonrails RailsOpensuseDebian Linux | 17/10/2013 | 16/6/2026 | Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message. |