Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 562 respecto a la semana anterior
Críticas / altas1454▲ 281 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.12% | — | Dalibo Postgresql AnonymizerAI | 25/9/2026 | 29/9/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the… | |
| Pendiente de análisis | Media (6.4) | 0.19% | — | Dalibo Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions | |
| Pendiente de análisis | Media (6.4) | 0.18% | — | Dalibo Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Postgresql AnonymizerAI | 6/9/2026 | 9/9/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with… | |
| Analizada | Media (4.3) | 0.19% | — | Dalibo Postgresql Anonymizer | 30/6/2026 | 6/7/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions | |
| Analizada | Alta (7.5) | 0.25% | — | Dalibo Postgresql Anonymizer | 11/6/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser… | |
| Analizada | Alta (8.8) | 0.43% | — | Dalibo Anonymizer | 27/5/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-anonymity function, the malicious code is executed with superuser privileges. The risk is higher with PostgreSQL 14 or… | |
| Aplazada | Alta (8) | 0.29% | — | PostgresqlAIDalibo Postgresql AnonymizerAI | 11/2/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then called, the malicious code is executed with superuser privileges. This privilege elevation can… | |
| Aplazada | Alta (8) | 0.44% | — | Postgresql AnonymizerAIPostgresqlAI | 11/2/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This operator will later be executed with superuser privileges when the extension is created. The risk is higher with PostgreSQL… | |
| Aplazada | Media (6.5) | 0.34% | — | Dalibo Postgresql AnonymizerAI | 4/6/2025 | 17/6/2026 | PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The… | |
| Analizada | Alta (8.8) | 0.55% | — | Dalibo Anonymizer | 8/3/2024 | 17/6/2026 | PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the… | |
| Analizada | Alta (7.5) | 0.46% | — | Dalibo Anonymizer | 8/3/2024 | 17/6/2026 | PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. PostgreSQL Anonymizer enables users to set security labels on tables to mask specified columns. There is a flaw that allows complex expressions to be provided… |