<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:14:04 +0000</lastBuildDate>
    <item>
      <title>certa-2013-avi-024 — Deux vulnérabilités ont été corrigées dans &lt;span class="textit"&gt;Ruby on
Rails&lt;/span&gt; Elles concernent des exécutions de…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2013-avi-024</link>
      <description>certa-2013-avi-024</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2013-avi-024</guid>
    </item>
    <item>
      <title>EUVD-2026-104531</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-104531</link>
      <description>EUVD-2026-104531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-104531</guid>
    </item>
    <item>
      <title>fkie_cve-2013-0155</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2013-0155</link>
      <description>&lt;p&gt;Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain &amp;#34;[nil]&amp;#34; values, a related issue to CVE-2012-2660 and CVE-2012-2694.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain &amp;#34;[nil]&amp;#34; values, a related issue to CVE-2012-2660 and CVE-2012-2694.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2013-0155</guid>
    </item>
    <item>
      <title>GHSA-gppp-5xc5-wfpx — Active Record allows bypassing of database-query restrictions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gppp-5xc5-wfpx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activerecord&lt;/p&gt;
&lt;p&gt;Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain &amp;#34;[nil]&amp;#34; values, a related issue to CVE-2012-2660 and CVE-2012-2694.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activerecord&lt;/p&gt;
&lt;p&gt;Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain &amp;#34;[nil]&amp;#34; values, a related issue to CVE-2012-2660 and CVE-2012-2694.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gppp-5xc5-wfpx</guid>
    </item>
    <item>
      <title>gsd-2013-0155</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2013-0155</link>
      <description>gsd-2013-0155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2013-0155</guid>
    </item>
    <item>
      <title>RHSA-2013:0154 — Red Hat Security Advisory: Ruby on Rails security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:0154</link>
      <description>&lt;p&gt;rubygem-actionpack: Unsafe query generation rubygem-activerecord: SQL injection when processing nested query paramaters rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660) rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest rubygem-actionpack: potential XSS vulnerability in select_tag prompt rubygem-actionpack: potential XSS vulnerability rubygem-actionpack: XSS Vulnerability in strip_tags rubygem-activerecord: find_by_* SQL Injection rubygem-activerecord: Unsafe Query Generation Risk in Ruby on Rails rubygem-activesupport: Multiple vulnerabilities in parameter parsing in ActionPack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-actionpack: Unsafe query generation rubygem-activerecord: SQL injection when processing nested query paramaters rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660) rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest rubygem-actionpack: potential XSS vulnerability in select_tag prompt rubygem-actionpack: potential XSS vulnerability rubygem-actionpack: XSS Vulnerability in strip_tags rubygem-activerecord: find_by_* SQL Injection rubygem-activerecord: Unsafe Query Generation Risk in Ruby on Rails rubygem-activesupport: Multiple vulnerabilities in parameter parsing in ActionPack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:0154</guid>
    </item>
  </channel>
</rss>
