Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.60% | — | Actionpack Project ActionpackRubyonrails Rails | 9/2/2023 | 17/6/2026 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a… | |
| Modificada | Media (6.1) | 1.6% | — | Rubyonrails ActionpackDebian Linux | 26/5/2022 | 17/6/2026 | A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes. | |
| Modificada | Media (6.1) | 1.8% | — | Rubyonrails ActionpackDebian Linux | 26/5/2022 | 17/6/2026 | An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses. | |
| Modificada | Alta (7.5) | 4.1% | — | Rubyonrails RailsRubyonrails Actionpack Page-cachingDebian Linux | 27/5/2021 | 17/6/2026 | A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input. | |
| Modificada | Crítica (9.8) | 5.4% | — | Rubyonrails Actionpack Page-cachingDebian Linux | 12/5/2020 | 17/6/2026 | There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view. |