Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2566▼ 323 respecto a la semana anterior
Críticas / altas1319▲ 64 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.12% | — | Dalibo Postgresql AnonymizerAI | 25/9/2026 | 29/9/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the… | |
| Pendiente de análisis | Media (6.4) | 0.19% | — | Dalibo Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions | |
| Pendiente de análisis | Media (6.4) | 0.18% | — | Dalibo Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser… | |
| Analizada | Media (4.3) | 0.19% | — | Dalibo Postgresql Anonymizer | 30/6/2026 | 6/7/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions | |
| Analizada | Alta (7.5) | 0.25% | — | Dalibo Postgresql Anonymizer | 11/6/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser… | |
| Aplazada | Alta (8) | 0.29% | — | PostgresqlAIDalibo Postgresql AnonymizerAI | 11/2/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then called, the malicious code is executed with superuser privileges. This privilege elevation can… | |
| Aplazada | Media (6.5) | 0.34% | — | Dalibo Postgresql AnonymizerAI | 4/6/2025 | 17/6/2026 | PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The… |