Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.31% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process. | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination. | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination. | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication. | |
| Pendiente de análisis | Alta (8.7) | 0.34% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution. | |
| Aplazada | Alta (7.2) | 0.32% | — | PgpointcloudAI | 25/9/2026 | 30/9/2026 | pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for… | |
| Pendiente de análisis | Alta (7.4) | 0.20% | — | Sequoia OpenpgpAI | 16/9/2026 | 23/9/2026 | A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can… | |
| Aplazada | Alta (7.1) | 0.28% | — | Ipgp Visitors OriginAI | 5/9/2026 | 8/9/2026 | The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request. | |
| Analizada | Media (5.5) | 0.11% | — | Redhat Hardened ImagesSequoia-pgp Rpm-sequoiaRedhat Enterprise Linux | 3/4/2026 | 24/7/2026 | A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of… | |
| Modificada | Alta (7.5) | 0.65% | — | Jackc Pgproto3 | 26/3/2026 | 10/9/2026 | The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. | |
| Analizada | Media (4.6) | 0.19% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user. | |
| Analizada | Media (5.6) | 0.30% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed. | |
| Analizada | Media (5.3) | 0.34% | — | Sequoia-pgp Buffered-reader | 28/7/2025 | 17/6/2026 | The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic. | |
| Analizada | Media (5.3) | 0.29% | — | Sequoia-pgp Sequoia-openpgp | 28/7/2025 | 17/6/2026 | The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic. | |
| Analizada | Alta (7.5) | 0.38% | — | Sequoia-pgp Sequoia-openpgp | 27/7/2025 | 17/6/2026 | The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type. | |
| Aplazada | Alta (8.7) | 0.65% | — | Openpgp.jsAI | 19/5/2025 | 17/6/2026 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data… | |
| Aplazada | Crítica (9.3) | 0.91% | — | Pgpool-iiAI | 19/5/2025 | 17/6/2026 | Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database. | |
| Analizada | Crítica (9.4) | 0.50% | — | Broadcom BitnamiBroadcom Bitnami/pgpool | 13/5/2025 | 17/6/2026 | The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes,… | |
| Aplazada | Alta (7.5) | 0.47% | — | RpgpAI | 5/12/2024 | 17/6/2026 | rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys. | |
| Aplazada | Alta (7.5) | 0.47% | — | RpgpAI | 5/12/2024 | 17/6/2026 | rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1. | |
| Aplazada | Alta (7.5) | 0.53% | — | Pgpool-iiAI | 12/9/2024 | 17/6/2026 | Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved. | |
| Analizada | Media (4.6) | 0.25% | — | Arnesonium Openpgp Form Encryption | 13/7/2024 | 17/6/2026 | The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Crítica (9.8) | 1.1% | — | Jackc Pgproto3Jackc PGX | 6/3/2024 | 17/6/2026 | pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved… |