Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.9)0.31%—Pgpool-iiAI30/9/202630/9/2026
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.
Pendiente de análisisMedia (5.3)0.18%—Pgpool-iiAI30/9/202630/9/2026
Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.
Pendiente de análisisAlta (8.7)0.29%—Pgpool-iiAI30/9/202630/9/2026
A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.
Pendiente de análisisAlta (8.7)0.32%—Pgpool-iiAI30/9/202630/9/2026
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
Pendiente de análisisAlta (7.1)0.25%—Pgpool-iiAI30/9/202630/9/2026
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.
Pendiente de análisisMedia (6.9)0.15%—Pgpool-iiAI30/9/202630/9/2026
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
Pendiente de análisisAlta (8.7)0.34%—Pgpool-iiAI30/9/202630/9/2026
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
AplazadaAlta (7.2)0.32%—PgpointcloudAI25/9/202630/9/2026
pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for…
Pendiente de análisisAlta (7.4)0.20%—Sequoia OpenpgpAI16/9/202623/9/2026
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can…
AplazadaAlta (7.1)0.28%—Ipgp Visitors OriginAI5/9/20268/9/2026
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.
AnalizadaMedia (5.5)0.11%—Redhat Hardened ImagesSequoia-pgp Rpm-sequoiaRedhat Enterprise Linux3/4/202624/7/2026
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of…
ModificadaAlta (7.5)0.65%—Jackc Pgproto326/3/202610/9/2026
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
AnalizadaMedia (4.6)0.19%—Broadcom Symantec PGP Encryption11/8/202517/6/2026
A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.
AnalizadaMedia (5.6)0.30%—Broadcom Symantec PGP Encryption11/8/202517/6/2026
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.
AnalizadaMedia (5.3)0.34%—Sequoia-pgp Buffered-reader28/7/202517/6/2026
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.
AnalizadaMedia (5.3)0.29%—Sequoia-pgp Sequoia-openpgp28/7/202517/6/2026
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
AnalizadaAlta (7.5)0.38%—Sequoia-pgp Sequoia-openpgp27/7/202517/6/2026
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
AplazadaAlta (8.7)0.65%—Openpgp.jsAI19/5/202517/6/2026
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data…
AplazadaCrítica (9.3)0.91%—Pgpool-iiAI19/5/202517/6/2026
Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.
AnalizadaCrítica (9.4)0.50%—Broadcom BitnamiBroadcom Bitnami/pgpool13/5/202517/6/2026
The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes,…
AplazadaAlta (7.5)0.47%—RpgpAI5/12/202417/6/2026
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.
AplazadaAlta (7.5)0.47%—RpgpAI5/12/202417/6/2026
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.
AplazadaAlta (7.5)0.53%—Pgpool-iiAI12/9/202417/6/2026
Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved.
AnalizadaMedia (4.6)0.25%—Arnesonium Openpgp Form Encryption13/7/202417/6/2026
The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AnalizadaCrítica (9.8)1.1%—Jackc Pgproto3Jackc PGX6/3/202417/6/2026
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved…