Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.56% | — | Wpruby Ruby Help Desk | 2/5/2023 | 17/6/2026 | The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own. | |
| Modificada | Media (5.3) | 2.5% | — | Ruby-lang RubyRuby-lang TimeDebian LinuxFedoraproject Fedora | 31/3/2023 | 17/6/2026 | A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2. | |
| Modificada | Media (5.3) | 2.6% | — | Ruby-lang URIDebian LinuxFedoraproject Fedora | 31/3/2023 | 17/6/2026 | A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1. | |
| Modificada | Alta (7.5) | 0.78% | — | Mruby | 14/2/2023 | 17/6/2026 | An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash. | |
| Modificada | Alta (7.5) | 1.0% | — | Rubyonrails Globalid | 9/2/2023 | 17/6/2026 | A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately. | |
| Modificada | Media (6.1) | 0.60% | — | Actionpack Project ActionpackRubyonrails Rails | 9/2/2023 | 17/6/2026 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a… | |
| Modificada | Alta (7.5) | 2.3% | — | Rubyonrails RailsDebian Linux | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the… | |
| Modificada | Alta (7.5) | 1.7% | — | Rubyonrails Rails | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a specially crafted X_FORWARDED_HOST header can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large… | |
| Modificada | Alta (8) | 1.4% | — | Ruby-git Project Ruby-gitDebian LinuxFedoraproject Fedora | 17/1/2023 | 17/6/2026 | ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648. | |
| Modificada | Alta (8) | 1.4% | — | Ruby-git Project Ruby-gitDebian Linux | 17/1/2023 | 17/6/2026 | ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318. | |
| Modificada | Media (6.1) | 1.1% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the… | |
| Modificada | Media (6.1) | 1.0% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either… | |
| Modificada | Media (6.1) | 0.89% | — | Rubyonrails Rails Html SanitizersDebian LinuxLoofah Project Loofah | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4. | |
| Modificada | Alta (7.5) | 1.5% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service… | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Ruby | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder. | |
| Modificada | Alta (8.8) | 2.4% | — | Ruby-lang CGIFedoraproject FedoraRuby-lang Ruby | 18/11/2022 | 17/6/2026 | The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object. | |
| Modificada | Media (5.4) | 0.75% | — | Rubyonrails Rails | 26/10/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The real existence of this… | |
| Modificada | Crítica (9.8) | 4.7% | — | Ruby-lang RubyDebian Linux | 29/9/2022 | 17/6/2026 | An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned… | |
| Modificada | Alta (7.8) | 1.5% | — | Ruby-arr-pm Project Ruby-arr-pm | 21/9/2022 | 17/6/2026 | Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection resulting in shell execution if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the `extract` and `files` methods of the `RPM::File` class of this library. Version… | |
| Modificada | Alta (8.8) | 1.0% | — | Rubygems | 7/9/2022 | 17/6/2026 | RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address. Having access to an account whose email has been changed could enable an attacker to save API keys for that account, and when a… | |
| Modificada | Alta (8.8) | 1.2% | — | Rubyinstaller2 | 30/8/2022 | 17/6/2026 | Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. | |
| Modificada | Alta (8.8) | 1.2% | — | Rubyinstaller2 | 30/8/2022 | 17/6/2026 | Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. | |
| Modificada | Media (6.5) | 1.2% | — | Ruby-mysql Project Ruby-mysql | 28/6/2022 | 17/6/2026 | A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without explicit authorization from the user. This issue was resolved in version 2.10.0 and later. | |
| Modificada | Media (6.1) | 30% | — | Rubyonrails Rails Html SanitizersFedoraproject FedoraDebian Linux | 24/6/2022 | 17/6/2026 | # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability… | |
| Modificada | Alta (7.8) | 0.40% | — | Mruby | 31/5/2022 | 17/6/2026 | Use After Free in GitHub repository mruby/mruby prior to 3.2. |