Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 1.0% | — | Rubyonrails Ruby ON RailsAIHavenweb HavenAI | 19/7/2024 | 17/6/2026 | A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functionality requires authentication, but an attacker can craft a link that they can pass to a logged in administrator of the blog software. This leads to the immediate… | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Ruby ON Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Ruby ON Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Media (6.1) | 3.4% | — | Rubyonrails RailsRubyonrails Ruby ON RailsDebian Linux | 7/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers. | |
| Modificada | Alta (7.3) | 81% | — | Debian LinuxRubyonrails RailsRubyonrails Ruby ON Rails | 7/4/2016 | 17/6/2026 | Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method. | |
| Modificada | Media (5.3) | 4.4% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/4/2016 | 17/6/2026 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an… | |
| Modificada | Alta (7.5) | 9.7% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption)… | |
| Modificada | Media (5.3) | 4.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change… | |
| Modificada | Baja (3.7) | 4.9% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 16/2/2016 | 17/6/2026 | The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time… | |
| Modificada | Media (4.3) | 2.8% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 26/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding. | |
| Modificada | Media (5) | 4.2% | — | OpensuseRubyonrails RailsRubyonrails Ruby ON Rails | 18/11/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the… | |
| Modificada | Media (4.3) | 3.5% | — | Rubyonrails RailsRubyonrails Ruby ON RailsOpensuse | 8/11/2014 | 17/6/2026 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the… | |
| Modificada | Alta (7.5) | 4.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/7/2014 | 17/6/2026 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting. | |
| Modificada | Media (5) | 6.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 20/2/2014 | 17/6/2026 | actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers. | |
| Modificada | Media (4.3) | 4.0% | — | Rubyonrails RailsRubyonrails Ruby ON RailsOpensuseOpensuse Project Opensuse+2 | 20/2/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to… | |
| Modificada | Media (6.4) | 2.4% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL… | |
| Modificada | Media (4.3) | 3.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter. | |
| Modificada | Media (5) | 21% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 17/6/2026 | actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching. | |
| Modificada | Media (4.3) | 2.2% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 7/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback… | |
| Modificada | Media (6.4) | 2.0% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 22/4/2013 | 16/6/2026 | The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on… | |
| Modificada | Media (4.3) | 1.9% | — | Redhat Enterprise LinuxRubyonrails RailsRubyonrails Ruby ON Rails | 19/3/2013 | 16/6/2026 | The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct… | |
| Modificada | Media (5.8) | 2.1% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 19/3/2013 | 16/6/2026 | The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files… | |
| Modificada | Media (4.3) | 2.6% | — | Rubyonrails RailsRubyonrails Ruby ON RailsRedhat Enterprise Linux | 19/3/2013 | 16/6/2026 | The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site… | |
| Modificada | Media (5) | 3.5% | — | Rubyonrails RailsRubyonrails Ruby ON RailsRedhat Enterprise Linux | 19/3/2013 | 16/6/2026 | The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method. | |
| Modificada | Alta (10) | 7.5% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 13/2/2013 | 16/6/2026 | ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML. |