Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
295 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | 0.29% | — | Canonical Postgresql OperatorAI | 2/10/2026 | 3/10/2026 | The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which… | |
| Pendiente de análisis | Media (4.3) | 0.12% | — | Dalibo Postgresql AnonymizerAI | 25/9/2026 | 29/9/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | DjangoAIPostgresqlAI | 23/9/2026 | 26/9/2026 | — | |
| Pendiente de análisis | Media (5.9) | 0.31% | — | PgbouncerAIPostgresqlAI | 23/9/2026 | 23/9/2026 | Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds… | |
| Pendiente de análisis | Media (6.5) | 0.53% | — | PostgresqlAIPgxn PG PartmanAI | 18/9/2026 | 24/9/2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immediately terminates the loop and skips every later set. A role with partman_user… | |
| Pendiente de análisis | Alta (8.5) | 0.38% | — | Postgresql PG PartmanAI | 18/9/2026 | 24/9/2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty schema name. A role with partman_user access can select a target schema… | |
| Pendiente de análisis | Alta (8.5) | 0.73% | — | PostgresqlAIPgxn PG PartmanAI | 18/9/2026 | 23/9/2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim inside a SQL string literal used to call pg_jobmon.add_job(). A partman_user… | |
| Pendiente de análisis | Alta (8.5) | 0.73% | — | PostgresqlAIPgxn PG PartmanAI | 18/9/2026 | 24/9/2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_dncoder text value without identifier quoting into dynamic SQL. A role… | |
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | PostgresqlAIPgxn PG PartmanAI | 18/9/2026 | 23/9/2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT… | |
| Aplazada | Alta (7.7) | 0.34% | — | PostgresqlAIFit2cloud SqlbotAI | 17/9/2026 | 23/9/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, and SQLBot stores that value without safe identifier handling. When… | |
| Aplazada | Media (6) | 0.48% | — | PostgresqlAIFit2cloud SqlbotAI | 17/9/2026 | 23/9/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated… | |
| Pendiente de análisis | Alta (8.2) | 0.68% | — | MapserverAIPostgresqlAIPostgisAI | 17/9/2026 | 24/9/2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does… | |
| Aplazada | Crítica (9.1) | 0.47% | — | MartenAIPostgresqlAINpgsqlAI | 16/9/2026 | 19/9/2026 | Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a… | |
| Aplazada | Media (4.4) | 0.19% | — | Outerbase StudioAIPostgresqlAIMysqlAISqliteAI | 15/9/2026 | 30/9/2026 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to… | |
| Aplazada | Alta (8.7) | 0.60% | — | MagistralaAIPostgresqlAI | 14/9/2026 | 23/9/2026 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or… | |
| Pendiente de análisis | Alta (7.1) | 0.63% | — | PostgisAIPostgresqlAI | 13/9/2026 | 24/9/2026 | PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Eclipse AeriosAIKeycloakAIPostgresqlAIOpenldapAI | 8/9/2026 | 9/9/2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database… | |
| Pendiente de análisis | Media (6.4) | 0.19% | — | Dalibo Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions | |
| Pendiente de análisis | Media (6.4) | 0.18% | — | Dalibo Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with… | |
| Pendiente de análisis | Media (6.5) | 0.40% | — | GrafanaAIMicrosoft SQL ServerAIPostgresqlAIMysqlAI | 2/9/2026 | 3/9/2026 | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana… | |
| Pendiente de análisis | Media (5.9) | 0.39% | — | KedaAIPostgresql LibpqAI | 21/8/2026 | 25/9/2026 | KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values, while escapePostgreConnectionParameter() only quotes values containing a literal… | |
| Aplazada | Crítica (9.4) | 0.77% | — | PostgresqlAILinuxfoundation CloudnativepgAI | 20/8/2026 | 18/9/2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role holding DATABASE OWNER could create… | |
| Aplazada | Alta (8.5) | 0.50% | — | PostgresqlAILinuxfoundation CloudnativepgAI | 20/8/2026 | 18/9/2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in… | |
| Aplazada | Alta (8.6) | 0.50% | — | BasercmsAIPostgresqlAI | 20/8/2026 | 31/8/2026 | baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a… |