Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 2.2% | — | Rubyonrails RailsDebian Linux | 11/2/2022 | 17/6/2026 | Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked… | |
| Modificada | Crítica (9.1) | 1.2% | — | Mruby | 9/2/2022 | 17/6/2026 | Out-of-bounds Read in Homebrew mruby prior to 3.2. | |
| Modificada | Crítica (9.8) | 4.8% | — | Ruby-lang CGIFedoraproject Fedora | 6/2/2022 | 17/6/2026 | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby. | |
| Modificada | Alta (7.5) | 0.92% | — | Mruby | 4/2/2022 | 17/6/2026 | NULL Pointer Dereference in Homebrew mruby prior to 3.2. | |
| Modificada | Media (5.5) | 0.81% | — | Mruby | 21/1/2022 | 17/6/2026 | NULL Pointer Dereference in Homebrew mruby prior to 3.2. | |
| Modificada | Alta (7.5) | 0.96% | — | Mruby | 17/1/2022 | 17/6/2026 | mruby is vulnerable to NULL Pointer Dereference | |
| Modificada | Alta (7.5) | 1.0% | — | Mruby | 14/1/2022 | 17/6/2026 | An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash. | |
| Modificada | Media (6.1) | 4.2% | — | Rubyonrails Rails | 10/1/2022 | 17/6/2026 | A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. | |
| Modificada | Crítica (9.8) | 1.4% | — | Mruby | 2/1/2022 | 17/6/2026 | mruby is vulnerable to Heap-based Buffer Overflow | |
| Modificada | Alta (7.5) | 2.9% | — | Ruby-lang CGIRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+5 | 1/1/2022 | 17/6/2026 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. | |
| Modificada | Alta (7.5) | 3.2% | — | Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+5 | 1/1/2022 | 17/6/2026 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. | |
| Modificada | Alta (7.5) | 0.86% | — | Mruby | 30/12/2021 | 17/6/2026 | mruby is vulnerable to NULL Pointer Dereference | |
| Modificada | Alta (7.5) | 1.6% | — | Mruby | 15/12/2021 | 17/6/2026 | mruby is vulnerable to NULL Pointer Dereference | |
| Modificada | Media (6.1) | 1.3% | — | Rubyonrails Rails | 19/10/2021 | 16/6/2026 | A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6. | |
| Modificada | Media (6.1) | 1.7% | — | Rubyonrails Rails | 18/10/2021 | 17/6/2026 | A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website. | |
| Modificada | Alta (8.8) | 1.4% | — | Jetbrains Rubymine | 6/8/2021 | 17/6/2026 | In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects. | |
| Modificada | Alta (7.4) | 2.9% | — | Ruby-lang RubyOracle JD Edwards Enterpriseone Tools | 1/8/2021 | 17/6/2026 | An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the… | |
| Modificada | Alta (7) | 1.5% | — | Debian LinuxRuby-lang RdocOracle JD Edwards Enterpriseone Tools | 30/7/2021 | 17/6/2026 | In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename. | |
| Modificada | Alta (7.5) | 57% | — | Ruby-lang Ruby | 30/7/2021 | 17/6/2026 | In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir. | |
| Modificada | Alta (7.5) | 1.3% | — | Sciruby NmatrixUblockorigin Ublock OriginUmatrix Project UmatrixDebian Linux | 18/7/2021 | 17/6/2026 | uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality). | |
| Modificada | Media (5.8) | 3.0% | — | Ruby-lang RubyDebian LinuxOracle JD Edwards Enterpriseone Tools | 13/7/2021 | 17/6/2026 | An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed… | |
| Modificada | Alta (7.8) | 0.99% | — | Mruby | 1/7/2021 | 17/6/2026 | mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free). | |
| Modificada | Alta (7.5) | 5.0% | — | Rubyonrails Rails | 11/6/2021 | 17/6/2026 | The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for… | |
| Modificada | Media (6.1) | 1.2% | — | Rubyonrails Rails | 11/6/2021 | 17/6/2026 | The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings… | |
| Modificada | Alta (7.5) | 2.8% | — | Rubyonrails Rails | 11/6/2021 | 17/6/2026 | The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic… |