Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
295 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.33% | — | Postgresql | 13/8/2026 | 29/8/2026 | Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions… | |
| Modificada | Media (4.2) | 0.18% | — | Postgresql | 13/8/2026 | 29/8/2026 | Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection… | |
| Modificada | Alta (8.8) | 0.44% | — | Postgresql | 13/8/2026 | 29/8/2026 | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar.… | |
| Modificada | Media (6.5) | 0.10% | — | Postgresql | 13/8/2026 | 29/8/2026 | Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong… | |
| Modificada | Alta (8.8) | 0.46% | — | Postgresql | 13/8/2026 | 29/8/2026 | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically… | |
| Aplazada | Media (6.4) | 0.67% | — | DokployAIPostgresqlAIMariadbAIMysqlAI+2 | 10/8/2026 | 8/9/2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database names, usernames, and passwords into nested shell command strings passed to… | |
| Aplazada | Crítica (9.9) | 0.65% | — | DokployAIPostgresqlAIMariadbAIMysqlAI+1 | 10/8/2026 | 8/9/2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the value in nested shell… | |
| Aplazada | Alta (8) | 0.47% | — | Openreception Appointment Booking SoftwareAIPostgresqlAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` of that tenant, including the `databaseUrl` field. This field contains the live… | |
| Aplazada | Alta (7.5) | 0.42% | — | DirectusAIPostgresqlAIPostgisAI | 5/8/2026 | 28/8/2026 | Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the… | |
| Aplazada | Alta (7.1) | 0.32% | — | MagistralaAIPostgresqlAITimescaledbAI | 5/8/2026 | 26/8/2026 | Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf in both the PostgreSQL reader (readers/postgres/messages.go: ) and the TimescaleDB reader… | |
| Aplazada | Media (6.5) | 1.2% | — | PostgresqlAI | 5/8/2026 | 26/8/2026 | The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to… | |
| Pendiente de análisis | Crítica (9.1) | 0.43% | — | SupabaseAIPostgresqlAIDockerAI | 31/7/2026 | 8/9/2026 | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. | |
| Aplazada | Media (4.7) | 0.32% | — | PostgresqlAIMysqlAIClastix KamajiAI | 30/7/2026 | 8/9/2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation,… | |
| Aplazada | Alta (8.7) | 0.71% | — | PostgresqlAIGladinet CentrestackAI | 30/7/2026 | 30/7/2026 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of… | |
| Rechazada | Sin puntuar | — | — | ClickhouseAIPostgresqlAI | 29/7/2026 | 6/8/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the… | |
| Aplazada | Media (5.3) | 0.47% | — | ApifoldAIRedisAIPostgresqlAI | 23/7/2026 | 23/7/2026 | APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverSlug/:eventName` endpoint accepts arbitrary unauthenticated JSON and stores it in Redis and the `webhook_events`… | |
| Aplazada | Media (6.7) | 0.72% | — | Nocobase Plugin BackupsAIPostgresqlAI | 15/7/2026 | 18/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata.json into shell command strings executed with Node.js… | |
| Aplazada | Baja (3.3) | 0.31% | — | Docker ComposeAIRedisAIKeydbAIDragonflyAI+4 | 7/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the… | |
| Aplazada | Alta (8.8) | 0.89% | — | PostgresqlAICoollabs CoolifyAI | 7/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not sufficiently restrict paths, allowing an authenticated… | |
| Aplazada | Alta (8.8) | 0.65% | — | PostgresqlAICoollabs CoolifyAI | 6/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands… | |
| Analizada | Alta (8.2) | 0.24% | — | Postgresql Jdbc Driver | 6/7/2026 | 9/7/2026 | pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who… | |
| Analizada | Media (4.3) | 0.19% | — | Dalibo Postgresql Anonymizer | 30/6/2026 | 6/7/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions | |
| Aplazada | Crítica (9.3) | 0.53% | — | Raytha CMSAIPostgresqlAI | 30/6/2026 | 30/6/2026 | Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL statements against the underlying PostgreSQL database, leading to full database compromise, including credential extraction. Because vendor contact… | |
| Aplazada | Media (6) | 0.38% | — | NocodbAIPostgresqlAI | 23/6/2026 | 25/6/2026 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed base can inject arbitrary SQL into the formula engine via the optional direction argument of ARRAYSORT(...). The value is unrestricted by formula validation and embedded… | |
| Aplazada | Alta (8.7) | 0.49% | — | Capgo BackendAISupabase PostgrestAIPostgresqlAI | 23/6/2026 | 23/6/2026 | Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries… |