Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

333 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8)0.29%—PostgresqlAIDalibo Postgresql AnonymizerAI11/2/202617/6/2026
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then called, the malicious code is executed with superuser privileges. This privilege elevation can…
AplazadaAlta (8)0.44%—Postgresql AnonymizerAIPostgresqlAI11/2/202617/6/2026
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This operator will later be executed with superuser privileges when the extension is created. The risk is higher with PostgreSQL…
AnalizadaMedia (4.8)0.23%—Enterprisedb Postgres Enterprise Manager16/1/202617/6/2026
PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript when creating a new chart, which is then executed by any user accessing the chart. By default only the superuser and users with pem_admin…
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AplazadaMedia (5.9)0.34%—Postgresql LibpqAI13/11/202517/6/2026
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL…
AplazadaBaja (3.1)0.23%—PostgresqlAI13/11/202517/6/2026
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7,…
AplazadaAlta (8.6)0.73%—Amazon Aurora PostgresqlAIAmazon Jdbc WrapperAIAmazon GO WrapperAIAmazon Nodejs WrapperAI+210/11/202517/6/2026
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the…
AplazadaAlta (8.8)0.43%—PostgresqlAI14/8/202517/6/2026
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL…
AplazadaAlta (8.8)0.76%—PostgresqlAI14/8/202517/6/2026
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to…
AplazadaBaja (3.1)0.24%—PostgresqlAI14/8/202517/6/2026
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted…
AplazadaBaja (2.1)0.33%—Pingidentity PingfederateAIPostgresqlAI15/6/202517/6/2026
PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.
AnalizadaMedia (5.9)0.49%—Postgresql Jdbc Driver11/6/202517/6/2026
pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as…
AplazadaMedia (6.5)0.34%—Dalibo Postgresql AnonymizerAI4/6/202517/6/2026
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The…
AplazadaMedia (5.9)0.76%—PostgresqlAIPostgresql LibpqAI8/5/202517/6/2026
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are…
AplazadaAlta (8.1)90%—PostgresqlAI13/2/202517/6/2026
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function…
ModificadaAlta (8.8)4.4%—Postgresql14/11/202417/6/2026
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL…
ModificadaMedia (4.2)0.69%—PostgresqlDebian Linux14/11/202417/6/2026
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE, SET SESSION AUTHORIZATION, or an equivalent feature. The problem arises when an application query uses parameters from the…
ModificadaBaja (3.7)0.37%—Postgresql14/11/202417/6/2026
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query…
ModificadaMedia (5.4)0.77%—Postgresql14/11/202417/6/2026
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or…
AnalizadaAlta (7.2)1.2%—Microsoft Azure Database FOR Postgresql Flexible Server12/11/202417/6/2026
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
AnalizadaAlta (7.2)1.2%—Microsoft Azure Database FOR Postgresql Flexible Server12/11/202417/6/2026
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
AplazadaMedia (5.3)0.51%—ASH Framework ASH PostgresAIAsh-rs ASHAI23/10/202417/6/2026
AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only on "empty" update actions (no changing fields), and would allow their hooks…
ModificadaAlta (7.5)1.6%—Postgresql8/8/202417/6/2026
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to…
AplazadaCrítica (9.8)20%—PostgresqlAIParseplatform Parse ServerAI1/7/202417/6/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and…