Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)1.0%—Rubyonrails Ruby ON RailsAIHavenweb HavenAI19/7/202417/6/2026
A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functionality requires authentication, but an attacker can craft a link that they can pass to a logged in administrator of the blog software. This leads to the immediate…
ModificadaAlta (8.1)1.5%—Rubyonrails Ruby ON Rails29/12/201717/6/2026
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
ModificadaAlta (8.1)1.5%—Rubyonrails Ruby ON Rails29/12/201717/6/2026
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
ModificadaMedia (6.1)3.4%—Rubyonrails RailsRubyonrails Ruby ON RailsDebian Linux7/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.
ModificadaAlta (7.3)81%—Debian LinuxRubyonrails RailsRubyonrails Ruby ON Rails7/4/201617/6/2026
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
ModificadaMedia (5.3)4.4%—Rubyonrails RailsRubyonrails Ruby ON Rails7/4/201617/6/2026
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an…
ModificadaAlta (7.5)9.7%—Rubyonrails RailsRubyonrails Ruby ON Rails16/2/201617/6/2026
actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption)…
ModificadaMedia (5.3)4.3%—Rubyonrails RailsRubyonrails Ruby ON Rails16/2/201617/6/2026
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change…
ModificadaBaja (3.7)4.9%—Rubyonrails RailsRubyonrails Ruby ON Rails16/2/201617/6/2026
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time…
ModificadaMedia (4.3)2.8%—Rubyonrails RailsRubyonrails Ruby ON Rails26/7/201517/6/2026
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
ModificadaMedia (5)4.2%—OpensuseRubyonrails RailsRubyonrails Ruby ON Rails18/11/201417/6/2026
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the…
ModificadaMedia (4.3)3.5%—Rubyonrails RailsRubyonrails Ruby ON RailsOpensuse8/11/201417/6/2026
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the…
ModificadaAlta (7.5)4.3%—Rubyonrails RailsRubyonrails Ruby ON Rails7/7/201417/6/2026
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
ModificadaMedia (5)6.2%—Rubyonrails RailsRubyonrails Ruby ON Rails20/2/201417/6/2026
actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
ModificadaMedia (4.3)4.0%—Rubyonrails RailsRubyonrails Ruby ON RailsOpensuseOpensuse Project Opensuse+220/2/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to…
ModificadaMedia (6.4)2.4%—Rubyonrails RailsRubyonrails Ruby ON Rails7/12/201317/6/2026
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL…
ModificadaMedia (4.3)3.2%—Rubyonrails RailsRubyonrails Ruby ON Rails7/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
ModificadaMedia (5)21%—Rubyonrails RailsRubyonrails Ruby ON Rails7/12/201317/6/2026
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
ModificadaMedia (4.3)2.2%—Rubyonrails RailsRubyonrails Ruby ON Rails7/12/201316/6/2026
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback…
ModificadaMedia (6.4)2.0%—Rubyonrails RailsRubyonrails Ruby ON Rails22/4/201316/6/2026
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on…
ModificadaMedia (4.3)1.9%—Redhat Enterprise LinuxRubyonrails RailsRubyonrails Ruby ON Rails19/3/201316/6/2026
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct…
ModificadaMedia (5.8)2.1%—Rubyonrails RailsRubyonrails Ruby ON Rails19/3/201316/6/2026
The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files…
ModificadaMedia (4.3)2.6%—Rubyonrails RailsRubyonrails Ruby ON RailsRedhat Enterprise Linux19/3/201316/6/2026
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site…
ModificadaMedia (5)3.5%—Rubyonrails RailsRubyonrails Ruby ON RailsRedhat Enterprise Linux19/3/201316/6/2026
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
ModificadaAlta (10)7.5%—Rubyonrails RailsRubyonrails Ruby ON Rails13/2/201316/6/2026
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.