<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:44:25.082671+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-113497</id>
    <title>EUVD-2026-113497</title>
    <updated>2026-10-03T03:44:25.184737+00:00</updated>
    <content>EUVD-2026-113497</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-113497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2012-6496</id>
    <title>fkie_cve-2012-6496</title>
    <updated>2026-10-03T03:44:25.184773+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2012-6496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gh2w-j7cx-2664</id>
    <title>GHSA-gh2w-j7cx-2664 — Active Record contains SQL Injection</title>
    <updated>2026-10-03T03:44:25.184806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: activerecord</p>
<p>SQL injection vulnerability in the Active Record component in Ruby on Rails before 2.3.15, 3.0.x before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gh2w-j7cx-2664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2012-6496</id>
    <title>gsd-2012-6496</title>
    <updated>2026-10-03T03:44:25.184835+00:00</updated>
    <content>gsd-2012-6496</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2012-6496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:0154</id>
    <title>RHSA-2013:0154 — Red Hat Security Advisory: Ruby on Rails security update</title>
    <updated>2026-10-03T03:44:25.184848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-actionpack: Unsafe query generation rubygem-activerecord: SQL injection when processing nested query paramaters rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660) rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest rubygem-actionpack: potential XSS vulnerability in select_tag prompt rubygem-actionpack: potential XSS vulnerability rubygem-actionpack: XSS Vulnerability in strip_tags rubygem-activerecord: find_by_* SQL Injection rubygem-activerecord: Unsafe Query Generation Risk in Ruby on Rails rubygem-activesupport: Multiple vulnerabilities in parameter parsing in ActionPack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:0154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-6496</id>
    <title>Withdrawn: UBUNTU-CVE-2012-6496</title>
    <updated>2026-10-03T03:44:25.184882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby-activerecord-3.2</p>
<p>SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-6496"/>
  </entry>
</feed>
