Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3042▲ 562 respecto a la semana anterior
Críticas / altas1454▲ 281 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.12%—Dalibo Postgresql AnonymizerAI25/9/202629/9/2026
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the…
Pendiente de análisisMedia (6.4)0.19%—Dalibo Postgresql AnonymizerAI6/9/20269/9/2026
PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions
Pendiente de análisisMedia (6.4)0.18%—Dalibo Postgresql AnonymizerAI6/9/20269/9/2026
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser…
Pendiente de análisisAlta (8.8)0.42%—Postgresql AnonymizerAI6/9/20269/9/2026
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with…
AnalizadaMedia (4.3)0.19%—Dalibo Postgresql Anonymizer30/6/20266/7/2026
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions
AnalizadaAlta (7.5)0.25%—Dalibo Postgresql Anonymizer11/6/202617/6/2026
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser…
AnalizadaAlta (8.8)0.43%—Dalibo Anonymizer27/5/202617/6/2026
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-anonymity function, the malicious code is executed with superuser privileges. The risk is higher with PostgreSQL 14 or…
AplazadaAlta (8)0.29%—PostgresqlAIDalibo Postgresql AnonymizerAI11/2/202617/6/2026
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then called, the malicious code is executed with superuser privileges. This privilege elevation can…
AplazadaAlta (8)0.44%—Postgresql AnonymizerAIPostgresqlAI11/2/202617/6/2026
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This operator will later be executed with superuser privileges when the extension is created. The risk is higher with PostgreSQL…
AplazadaMedia (6.5)0.34%—Dalibo Postgresql AnonymizerAI4/6/202517/6/2026
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The…
AnalizadaAlta (8.8)0.55%—Dalibo Anonymizer8/3/202417/6/2026
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the…
AnalizadaAlta (7.5)0.46%—Dalibo Anonymizer8/3/202417/6/2026
PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. PostgreSQL Anonymizer enables users to set security labels on tables to mask specified columns. There is a flaw that allows complex expressions to be provided…