Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.1%—Rubyonrails RailsRubyonrails Actionpack Page-cachingDebian Linux27/5/202117/6/2026
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
ModificadaCrítica (9.8)2.6%—Pixar Ruby-jss25/5/202117/6/2026
The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.
ModificadaAlta (7.5)5.1%—Ruby-lang RexmlRuby-lang RubyFedoraproject Fedora21/4/202117/6/2026
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
ModificadaCrítica (9.8)9.7%—Wpruby Controlled Admin Access12/4/202117/6/2026
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target…
ModificadaMedia (5.3)1.8%—Rubyonrails Active Record Session Store5/3/202117/6/2026
The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is valid. Consequently, remote attackers can leverage timing discrepancies to achieve a correct guess in a…
ModificadaMedia (6.1)87%—Rubyonrails RailsFedoraproject Fedora11/2/202117/6/2026
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted…
ModificadaAlta (7.5)4.4%—Rubyonrails RailsFedoraproject Fedora11/2/202117/6/2026
The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression,…
ModificadaMedia (6.1)67%—Rubyonrails Rails6/1/202117/6/2026
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the…
ModificadaAlta (7.5)3.8%—Ruby-lang RubyRuby-lang WebrickFedoraproject Fedora6/10/202017/6/2026
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check),…
ModificadaAlta (7.4)0.86%—Oauth-ruby Project Oauth-ruby24/9/202017/6/2026
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
ModificadaCrítica (9.8)2.1%—MrubyDebian Linux21/7/202017/6/2026
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.
ModificadaMedia (6.5)2.2%—Rubyonrails RailsFedoraproject Fedora2/7/202017/6/2026
A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.
ModificadaMedia (4.3)1.7%—Rubyonrails RailsDebian Linux2/7/202017/6/2026
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
ModificadaAlta (8.8)82%—Rubyonrails RailsDebian Linux2/7/202017/6/2026
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
ModificadaMedia (6.5)1.5%—Rubyonrails RailsDebian Linux19/6/202017/6/2026
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
ModificadaCrítica (9.8)46%—Rubyonrails RailsDebian LinuxOpensuse Leap19/6/202017/6/2026
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
ModificadaAlta (7.5)4.8%—Rubyonrails RailsDebian LinuxOpensuse Backports SLEOpensuse Leap19/6/202017/6/2026
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
ModificadaAlta (7.5)3.0%—Rubyonrails RailsDebian Linux19/6/202017/6/2026
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
ModificadaCrítica (9.8)5.4%—Rubyonrails Actionpack Page-cachingDebian Linux12/5/202017/6/2026
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
ModificadaAlta (7.5)2.2%—Rubyonrails Active ResourceFedoraproject Fedora12/5/202017/6/2026
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
ModificadaMedia (5.3)2.5%—Ruby-lang RubyFedoraproject FedoraDebian Linux4/5/202017/6/2026
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap.…
ModificadaMedia (4.8)1.5%—Rubyonrails ActionviewDebian LinuxFedoraproject FedoraOpensuse Leap19/3/202017/6/2026
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.
ModificadaAlta (7.5)2.5%—PumaRuby-lang RubyDebian LinuxFedoraproject Fedora28/2/202017/6/2026
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entirely new response body. This…
ModificadaMedia (6.4)1.4%—Ruby-lang RakeCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+124/2/202017/6/2026
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
ModificadaCrítica (9.8)1.5%—Rubygeocoder Geocoder25/1/202017/6/2026
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.