Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

333 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.49%—Postgresql Jdbc DriverDebian Linux23/11/202217/6/2026
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This will create a temporary file which is readable…
ModificadaAlta (8.8)16%—Postgresql31/8/202217/6/2026
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the…
ModificadaMedia (5.9)0.40%—Postgresql25/8/202217/6/2026
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries.…
ModificadaAlta (8)1.9%—PostgresqlFedoraproject FedoraRedhat Enterprise Linux18/8/202217/6/2026
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE…
ModificadaCrítica (10)0.64%—Linuxfoundation Loopback-connector-postgresql12/8/202217/6/2026
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the…
ModificadaAlta (8)2.2%—Postgresql Jdbc DriverDebian LinuxFedoraproject Fedora3/8/202217/6/2026
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement…
ModificadaCrítica (9.8)3.0%—Postgresql Jdbc DriverDebian Linux10/3/202217/6/2026
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the…
ModificadaAlta (8.1)1.9%—PostgresqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+24/3/202217/6/2026
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
ModificadaMedia (6.5)1.4%—PostgresqlRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux FOR IBM Z Systems+32/3/202217/6/2026
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known…
ModificadaMedia (5.9)1.5%—Postgresql2/3/202217/6/2026
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
ModificadaCrítica (9.8)3.1%—Postgresql Jdbc DriverFedoraproject FedoraQuarkusDebian Linux2/2/202217/6/2026
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided…
ModificadaMedia (6.5)1.6%—Postgresql11/10/202117/6/2026
A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
ModificadaMedia (6.5)1.5%—PostgresqlRedhat Jboss Enterprise Application Platform8/10/202117/6/2026
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
ModificadaAlta (8.8)2.0%—PostgresqlRedhat Jboss Enterprise Application PlatformRedhat Software CollectionsRedhat Enterprise Linux1/6/202117/6/2026
A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The highest threat from this vulnerability is to…
ModificadaMedia (4.3)1.2%—PostgresqlRedhat Software CollectionsRedhat Enterprise Linux1/4/202117/6/2026
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use…
ModificadaAlta (7.8)0.45%—Postgresql19/3/202117/6/2026
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to…
ModificadaAlta (8.8)0.33%—Postgresql19/3/202117/6/2026
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged…
ModificadaMedia (4.3)1.5%—PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora23/2/202117/6/2026
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
ModificadaAlta (7.5)2.7%—PostgresqlDebian Linux23/11/202017/6/2026
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account…
ModificadaAlta (8.8)46%—PostgresqlDebian Linux16/11/202017/6/2026
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this…
ModificadaAlta (8.1)1.6%—PostgresqlDebian Linux16/11/202017/6/2026
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a…
ModificadaAlta (7.3)0.53%—Postgresql16/9/202017/6/2026
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those…
ModificadaAlta (7.3)0.53%—PostgresqlDebian LinuxOpensuse LeapCanonical Ubuntu Linux24/8/202017/6/2026
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions…
ModificadaAlta (7.1)2.2%—PostgresqlOpensuse Leap24/8/202017/6/2026
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for…
ModificadaAlta (7.7)4.1%—Postgresql Jdbc DriverQuarkusNetapp Steelstore Cloud Integrated StorageFedoraproject Fedora+14/6/202017/6/2026
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
Orbitaley — Vulnerabilidades