Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.3)0.49%—Jackc PGX8/5/202617/6/2026
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and…
ModificadaCrítica (9.8)0.86%—Jackc PGX7/4/202610/9/2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
ModificadaCrítica (9.8)0.86%—Jackc PGX7/4/202610/9/2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
ModificadaAlta (7.5)0.65%—Jackc Pgproto326/3/202610/9/2026
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
AnalizadaCrítica (9.8)1.1%—Jackc Pgproto3Jackc PGX6/3/202417/6/2026
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved…
AnalizadaAlta (8.1)0.85%—Jackc PGX6/3/202417/6/2026
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a second placeholder for a string value after…