Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.6% | — | Rubyonrails ActionpackDebian Linux | 26/5/2022 | 17/6/2026 | A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes. | |
| Modificada | Media (6.1) | 1.8% | — | Rubyonrails ActionpackDebian Linux | 26/5/2022 | 17/6/2026 | An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses. | |
| Modificada | Crítica (9.8) | 3.1% | — | Rubyonrails Active StorageDebian Linux | 26/5/2022 | 17/6/2026 | A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments. | |
| Modificada | Alta (7.5) | 1.3% | — | Rubygems.org | 13/5/2022 | 17/6/2026 | RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a malicious package. The bug has been patched, and… | |
| Modificada | Alta (7.5) | 4.4% | — | Ruby-lang RubyDebian LinuxApple Macos | 9/5/2022 | 17/6/2026 | There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ruby-lang Ruby | 9/5/2022 | 17/6/2026 | A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations. | |
| Modificada | Alta (7.5) | 1.9% | — | Rubygems.org | 5/5/2022 | 17/6/2026 | Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vulnerable, a gem needed: one or more dashes in its name creation… | |
| Modificada | Alta (7.8) | 0.48% | — | Mruby | 23/4/2022 | 17/6/2026 | Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mruby | 10/4/2022 | 17/6/2026 | heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mruby | 10/4/2022 | 17/6/2026 | Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | |
| Modificada | Alta (7.5) | 3.5% | — | Yajl-ruby Project Yajl-ruby | 5/4/2022 | 17/6/2026 | yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer… | |
| Modificada | Crítica (9.8) | 1.8% | — | Mruby | 5/4/2022 | 17/6/2026 | Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | |
| Modificada | Media (6.5) | 0.37% | — | Mruby | 2/4/2022 | 17/6/2026 | NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system. | |
| Modificada | Crítica (9.1) | 0.97% | — | Mruby | 27/3/2022 | 17/6/2026 | use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. | |
| Modificada | Alta (8.2) | 0.92% | — | Mruby | 26/3/2022 | 17/6/2026 | User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. | |
| Modificada | Media (5.5) | 0.83% | — | Mruby | 10/3/2022 | 17/6/2026 | NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2. | |
| Modificada | Crítica (9.8) | 1.1% | — | Jetbrains ClionJetbrains GolandJetbrains Intellij IdeaJetbrains Phpstorm+3 | 25/2/2022 | 17/6/2026 | JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development… | |
| Modificada | Crítica (9.1) | 0.92% | — | Mruby | 23/2/2022 | 17/6/2026 | Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. | |
| Modificada | Media (5.5) | 0.81% | — | Mruby | 19/2/2022 | 17/6/2026 | NULL Pointer Dereference in Homebrew mruby prior to 3.2. | |
| Modificada | Alta (7.1) | 0.99% | — | Mruby | 19/2/2022 | 17/6/2026 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | |
| Modificada | Crítica (9.8) | 0.92% | — | Mruby | 18/2/2022 | 17/6/2026 | Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. | |
| Modificada | Crítica (9.1) | 1.6% | — | Mruby | 17/2/2022 | 17/6/2026 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | |
| Modificada | Media (5.5) | 0.91% | — | Mruby | 16/2/2022 | 17/6/2026 | Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mruby | 14/2/2022 | 17/6/2026 | Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. | |
| Modificada | Media (5.9) | 2.1% | — | PumaRubyonrails RailsDebian LinuxFedoraproject Fedora | 11/2/2022 | 17/6/2026 | Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these… |