Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)2.2%—Rubyonrails RailsDebian Linux11/2/202217/6/2026
Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked…
ModificadaCrítica (9.1)1.2%—Mruby9/2/202217/6/2026
Out-of-bounds Read in Homebrew mruby prior to 3.2.
ModificadaCrítica (9.8)4.8%—Ruby-lang CGIFedoraproject Fedora6/2/202217/6/2026
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.
ModificadaAlta (7.5)0.92%—Mruby4/2/202217/6/2026
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
ModificadaMedia (5.5)0.81%—Mruby21/1/202217/6/2026
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
ModificadaAlta (7.5)0.96%—Mruby17/1/202217/6/2026
mruby is vulnerable to NULL Pointer Dereference
ModificadaAlta (7.5)1.0%—Mruby14/1/202217/6/2026
An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.
ModificadaMedia (6.1)4.2%—Rubyonrails Rails10/1/202217/6/2026
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
ModificadaCrítica (9.8)1.4%—Mruby2/1/202217/6/2026
mruby is vulnerable to Heap-based Buffer Overflow
ModificadaAlta (7.5)2.9%—Ruby-lang CGIRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
ModificadaAlta (7.5)3.2%—Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
ModificadaAlta (7.5)0.86%—Mruby30/12/202117/6/2026
mruby is vulnerable to NULL Pointer Dereference
ModificadaAlta (7.5)1.6%—Mruby15/12/202117/6/2026
mruby is vulnerable to NULL Pointer Dereference
ModificadaMedia (6.1)1.3%—Rubyonrails Rails19/10/202116/6/2026
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.
ModificadaMedia (6.1)1.7%—Rubyonrails Rails18/10/202117/6/2026
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
ModificadaAlta (8.8)1.4%—Jetbrains Rubymine6/8/202117/6/2026
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
ModificadaAlta (7.4)2.9%—Ruby-lang RubyOracle JD Edwards Enterpriseone Tools1/8/202117/6/2026
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the…
ModificadaAlta (7)1.5%—Debian LinuxRuby-lang RdocOracle JD Edwards Enterpriseone Tools30/7/202117/6/2026
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
ModificadaAlta (7.5)57%—Ruby-lang Ruby30/7/202117/6/2026
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
ModificadaAlta (7.5)1.3%—Sciruby NmatrixUblockorigin Ublock OriginUmatrix Project UmatrixDebian Linux18/7/202117/6/2026
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
ModificadaMedia (5.8)3.0%—Ruby-lang RubyDebian LinuxOracle JD Edwards Enterpriseone Tools13/7/202117/6/2026
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed…
ModificadaAlta (7.8)0.99%—Mruby1/7/202117/6/2026
mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
ModificadaAlta (7.5)5.0%—Rubyonrails Rails11/6/202117/6/2026
The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for…
ModificadaMedia (6.1)1.2%—Rubyonrails Rails11/6/202117/6/2026
The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings…
ModificadaAlta (7.5)2.8%—Rubyonrails Rails11/6/202117/6/2026
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic…