Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.31% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process. | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination. | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination. | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication. | |
| Pendiente de análisis | Alta (8.7) | 0.34% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution. | |
| Aplazada | Crítica (9.3) | 0.91% | — | Pgpool-iiAI | 19/5/2025 | 17/6/2026 | Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database. | |
| Aplazada | Alta (7.5) | 0.53% | — | Pgpool-iiAI | 12/9/2024 | 17/6/2026 | Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved. | |
| Modificada | Media (6.5) | 0.70% | — | Pgpool-ii | 30/1/2023 | 17/6/2026 | Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of 3.5 series, All versions of 3.4 series,… |