Exposición de PostgreSQL

Databases
41
score de exposición
9760
sitios usan
0
en explotación
0
críticos
Análisis Vexday

O PostgreSQL acumula 83 CVEs catalogadas, sem registros de exploração ativa no catálogo KEV da CISA e sem vulnerabilidades de severidade crítica no conjunto atual — taxa abaixo da média geral do catálogo, o que sugere um perfil de risco relativamente controlado em relação ao universo de vendors monitorados. O tipo de falha mais frequente é CWE-200, relacionada à exposição indevida de informações, padrão que merece atenção em configurações de acesso e controle de privilégios. O ponto de maior atenção imediata é CVE-2025-1094, que apresenta EPSS de 0,89, indicando alta probabilidade de exploração na prática — essa CVE deve ser tratada como prioridade mesmo na ausência de confirmação formal no KEV. Adicionalmente, 11 vulnerabilidades surgiram nos últimos 90 dias, sinalizando atividade recente na superfície de ataque que requer monitoramento contínuo.

CVEs

83 resultados
CVE-2026-6478MEDIUMPostgreSQL discloses MD5-hashed passwords via covert timing channelEPSS 0.6%CVE-2020-14350It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privilEPSS 0.5%CVE-2020-10733The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in theEPSS 0.5%CVE-2018-1053In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates filEPSS 0.5%CVE-2026-2007HIGHPostgreSQL pg_trgm heap buffer overflow writes pattern onto server memoryEPSS 0.5%CVE-2026-6479HIGHPostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionEPSS 0.5%CVE-2026-6477HIGHPostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryEPSS 0.5%CVE-2019-10128A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not locEPSS 0.4%CVE-2025-8715HIGHPostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target serverEPSS 0.4%CVE-2019-10210MEDIUMPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotectedEPSS 0.4%CVE-2024-10977LOWPostgreSQL libpq retains an error message from man-in-the-middleEPSS 0.4%CVE-2026-6637HIGHPostgreSQL refint allows stack buffer overflow and SQL injectionEPSS 0.4%CVE-2025-12818MEDIUMPostgreSQL libpq undersizes allocations, via integer wraparoundEPSS 0.3%CVE-2019-10127A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock downEPSS 0.3%CVE-2026-6475HIGHPostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choiceEPSS 0.3%CVE-2026-6476HIGHPostgreSQL pg_createsubscriber allows SQL injection via subscription nameEPSS 0.3%CVE-2026-2003MEDIUMPostgreSQL oidvector discloses a few bytes of memoryEPSS 0.3%CVE-2025-12817LOWPostgreSQL CREATE STATISTICS does not check for schema CREATE privilegeEPSS 0.2%CVE-2025-8713LOWPostgreSQL optimizer statistics can expose sampled data within a view, partition, or child tableEPSS 0.2%CVE-2026-6474MEDIUMPostgreSQL timeofday() can disclose portions of server memoryEPSS 0.2%