Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

331 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.12%—Dalibo Postgresql AnonymizerAI25/9/202629/9/2026
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the…
Pendiente de análisisMedia (4.3)0.21%—DjangoAIPostgresqlAI23/9/202626/9/2026
—
Pendiente de análisisMedia (5.9)0.31%—PgbouncerAIPostgresqlAI23/9/202623/9/2026
Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds…
Pendiente de análisisMedia (6.5)0.53%—PostgresqlAIPgxn PG PartmanAI18/9/202624/9/2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immediately terminates the loop and skips every later set. A role with partman_user…
Pendiente de análisisAlta (8.5)0.38%—Postgresql PG PartmanAI18/9/202624/9/2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty schema name. A role with partman_user access can select a target schema…
Pendiente de análisisAlta (8.5)0.73%—PostgresqlAIPgxn PG PartmanAI18/9/202623/9/2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim inside a SQL string literal used to call pg_jobmon.add_job(). A partman_user…
Pendiente de análisisAlta (8.5)0.73%—PostgresqlAIPgxn PG PartmanAI18/9/202624/9/2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_dncoder text value without identifier quoting into dynamic SQL. A role…
Pendiente de análisisCrítica (9.9)0.80%—PostgresqlAIPgxn PG PartmanAI18/9/202623/9/2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT…
AplazadaAlta (7.7)0.34%—PostgresqlAIFit2cloud SqlbotAI17/9/202623/9/2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, and SQLBot stores that value without safe identifier handling. When…
AplazadaMedia (6)0.48%—PostgresqlAIFit2cloud SqlbotAI17/9/202623/9/2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated…
Pendiente de análisisAlta (8.2)0.68%—MapserverAIPostgresqlAIPostgisAI17/9/202624/9/2026
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does…
AplazadaCrítica (9.1)0.47%—MartenAIPostgresqlAINpgsqlAI16/9/202619/9/2026
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a…
AplazadaMedia (4.4)0.19%—Outerbase StudioAIPostgresqlAIMysqlAISqliteAI15/9/202630/9/2026
Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to…
AplazadaAlta (8.7)0.60%—MagistralaAIPostgresqlAI14/9/202623/9/2026
Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or…
Pendiente de análisisAlta (7.1)0.63%—PostgisAIPostgresqlAI13/9/202624/9/2026
PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process…
AplazadaCrítica (9.3)0.37%—CapgoAISupabaseAISupabase PostgrestAI10/9/202630/9/2026
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route…
AplazadaCrítica (9)1.7%—Amazon Awslabs Postgres-mcp-serverAI9/9/202610/9/2026
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement…
AplazadaCrítica (9.9)0.55%—Eclipse AeriosAIKeycloakAIPostgresqlAIOpenldapAI8/9/20269/9/2026
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database…
Pendiente de análisisMedia (6.4)0.19%—Dalibo Postgresql AnonymizerAI6/9/20269/9/2026
PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions
Pendiente de análisisMedia (6.4)0.18%—Dalibo Postgresql AnonymizerAI6/9/20269/9/2026
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser…
Pendiente de análisisAlta (8.8)0.42%—Postgresql AnonymizerAI6/9/20269/9/2026
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with…
Pendiente de análisisAlta (7.1)0.34%—Amazon Postgres-mcp-serverAI4/9/20268/9/2026
An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP…
Pendiente de análisisCrítica (9.2)0.51%—Postgres MCP PROAI4/9/202624/9/2026
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.
Pendiente de análisisMedia (6.5)0.40%—GrafanaAIMicrosoft SQL ServerAIPostgresqlAIMysqlAI2/9/20263/9/2026
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana…
AplazadaAlta (7.2)0.16%—Ash-project ASH PostgresAI30/8/20261/9/2026
Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. AshPostgres.MultiTenancy.rename_tenant/3 issues the…