Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2537▼ 356 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (2.3)0.39%—LoofahAI12/8/20269/9/2026
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric character references such as &#58, &#9,…
Pendiente de análisisBaja (2.3)0.39%—LoofahAI12/8/20269/9/2026
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or…
Pendiente de análisisMedia (4.7)0.30%—LoofahAI12/8/20269/9/2026
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute on SVG use and feImage elements, while browsers also accept the plain href…
ModificadaMedia (6.1)0.89%—Rubyonrails Rails Html SanitizersDebian LinuxLoofah Project Loofah14/12/202217/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4.
ModificadaAlta (7.5)1.1%—Loofah Project Loofah14/12/202217/6/2026
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service…
ModificadaMedia (6.1)0.83%—Loofah Project LoofahDebian Linux14/12/202217/6/2026
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.
ModificadaAlta (7.5)1.8%—Loofah Project Loofah14/12/202217/6/2026
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service…
ModificadaMedia (5.4)1.6%—Loofah Project LoofahFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux22/10/201917/6/2026
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
ModificadaMedia (5.4)0.92%—Loofah Project LoofahDebian Linux30/10/201817/6/2026
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
ModificadaMedia (6.1)1.9%—Debian LinuxLoofah Project Loofah27/3/201817/6/2026
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.