Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2537▼ 356 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.3) | 0.39% | — | LoofahAI | 12/8/2026 | 9/9/2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric character references such as :, 	,… | |
| Pendiente de análisis | Baja (2.3) | 0.39% | — | LoofahAI | 12/8/2026 | 9/9/2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or… | |
| Pendiente de análisis | Media (4.7) | 0.30% | — | LoofahAI | 12/8/2026 | 9/9/2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute on SVG use and feImage elements, while browsers also accept the plain href… | |
| Modificada | Media (6.1) | 0.89% | — | Rubyonrails Rails Html SanitizersDebian LinuxLoofah Project Loofah | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4. | |
| Modificada | Alta (7.5) | 1.1% | — | Loofah Project Loofah | 14/12/2022 | 17/6/2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service… | |
| Modificada | Media (6.1) | 0.83% | — | Loofah Project LoofahDebian Linux | 14/12/2022 | 17/6/2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1. | |
| Modificada | Alta (7.5) | 1.8% | — | Loofah Project Loofah | 14/12/2022 | 17/6/2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service… | |
| Modificada | Media (5.4) | 1.6% | — | Loofah Project LoofahFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 22/10/2019 | 17/6/2026 | In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. | |
| Modificada | Media (5.4) | 0.92% | — | Loofah Project LoofahDebian Linux | 30/10/2018 | 17/6/2026 | In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. | |
| Modificada | Media (6.1) | 1.9% | — | Debian LinuxLoofah Project Loofah | 27/3/2018 | 17/6/2026 | In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment. |