Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.54%—Postgresql17/1/200316/6/2026
Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input."
ModificadaAlta (7.5)3.9%—Postgresql17/1/200316/6/2026
Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.
ModificadaMedia (4.6)0.48%—Postgresql17/1/200316/6/2026
Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.5)2.8%—Postgresql17/1/200316/6/2026
Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.
ModificadaAlta (7.5)1.3%—Postgresql31/12/200216/6/2026
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
ModificadaAlta (7.2)0.43%—Postgresql3/10/200216/6/2026
PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.
ModificadaMedia (4.6)0.49%—Postgresql24/9/200216/6/2026
Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.
ModificadaAlta (7.5)1.1%—Postgresql12/8/200216/6/2026
The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.
ModificadaAlta (7.5)1.6%—Alessandro Gardich NSS PostgresqlJoerg Wendland Libnss-pgsql10/9/200116/6/2026
libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
ModificadaAlta (7.5)1.6%—Alessandro Gardich NSS Postgresql10/9/200116/6/2026
nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
ModificadaMedia (4.6)0.91%💥 ExploitPostgresql31/8/200116/6/2026
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.
ModificadaBaja (2.1)0.39%—Postgresql2/12/199916/6/2026
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.
Orbitaley — Vulnerabilidades