Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2770▲ 14 respecto a la semana anterior
Críticas / altas1475▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.58% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was… | |
| Analizada | Crítica (9.3) | 0.58% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back… | |
| Analizada | Alta (7.1) | 0.35% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the… | |
| Analizada | Media (6) | 0.32% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously hardened the separate file upload path by opening its target… | |
| Analizada | Crítica (9.4) | 0.67% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>,… | |
| Analizada | Crítica (9.4) | 0.48% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with… | |
| Analizada | Media (5.3) | 0.38% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator (permissions_required) was applied only to a… | |
| Analizada | Crítica (9.3) | 0.40% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password,… | |
| Analizada | Media (6.9) | 0.42% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the… | |
| Analizada | Alta (7.7) | 0.72% | — | Pgadmin 4 | 31/7/2026 | 7/8/2026 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and… | |
| Analizada | Alta (8.7) | 0.61% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names… | |
| Analizada | Media (5.3) | 0.43% | — | Pgadmin 4 | 19/6/2026 | 29/6/2026 | SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a bound parameter, allowing an authenticated pgAdmin user with a connected PostgreSQL… | |
| Analizada | Media (5.3) | 0.38% | — | Pgadmin 4 | 19/6/2026 | 29/6/2026 | Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated victim who clicked /mfa/validate?next=<external> -- a link typically delivered by… | |
| Analizada | Crítica (9.3) | 0.27% | — | Pgadmin 4 | 19/6/2026 | 29/6/2026 | Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through… | |
| Analizada | Media (4.8) | 0.22% | — | Pgadmin 4 | 19/6/2026 | 29/6/2026 | HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception text — and the related file-resolution and database-commit exception text — into… | |
| Analizada | Crítica (9.5) | 1.0% | — | Pgadmin 4 | 19/6/2026 | 1/7/2026 | Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module missing the @pga_login_required decorator. Both reach a pickle.loads sink on… | |
| Analizada | Crítica (9.4) | 0.66% | — | Pgadmin 4 | 19/6/2026 | 1/7/2026 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ… | |
| Analizada | Alta (8.7) | 0.71% | — | Pgadmin 4 | 19/6/2026 | 1/7/2026 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description… | |
| Analizada | Media (6.9) | 0.33% | — | Pgadmin 4 | 11/5/2026 | 17/6/2026 | Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, never consulted the… | |
| Analizada | Alta (7.2) | 0.48% | — | Pgadmin 4 | 11/5/2026 | 17/6/2026 | Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory… | |
| Analizada | Alta (7.3) | 0.35% | — | Pgadmin 4 | 11/5/2026 | 17/6/2026 | Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any HMAC integrity check. Any file dropped into the sessions directory was… | |
| Analizada | Alta (7.1) | 0.35% | — | Pgadmin 4 | 11/5/2026 | 17/6/2026 | Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read arbitrary server-side files by pointing… | |
| Modificada | Alta (8.7) | 2.2% | — | Pgadmin 4 | 11/5/2026 | 17/6/2026 | OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy metacommand template without sanitization. An authenticated user could inject ") TO PROGRAM 'cmd'" to break out of the \copy (...) context and achieve arbitrary command… | |
| Analizada | Alta (8.7) | 0.64% | — | Pgadmin 4 | 11/5/2026 | 17/6/2026 | SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespace) were concatenated directly into the rendered VACUUM/ANALYZE/REINDEX command and passed to psql --command. An authenticated user with the… | |
| Analizada | Media (4.8) | 0.25% | — | Pgadmin 4 | 11/5/2026 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML markup to execute attacker-supplied… |