Exposição de PostgreSQL

Databases
41
score de exposição
9.760
sites usam
0
em exploração
0
críticos
Análise Vexday

O PostgreSQL acumula 83 CVEs catalogadas, sem registros de exploração ativa no catálogo KEV da CISA e sem vulnerabilidades de severidade crítica no conjunto atual — taxa abaixo da média geral do catálogo, o que sugere um perfil de risco relativamente controlado em relação ao universo de vendors monitorados. O tipo de falha mais frequente é CWE-200, relacionada à exposição indevida de informações, padrão que merece atenção em configurações de acesso e controle de privilégios. O ponto de maior atenção imediata é CVE-2025-1094, que apresenta EPSS de 0,89, indicando alta probabilidade de exploração na prática — essa CVE deve ser tratada como prioridade mesmo na ausência de confirmação formal no KEV. Adicionalmente, 11 vulnerabilidades surgiram nos últimos 90 dias, sinalizando atividade recente na superfície de ataque que requer monitoramento contínuo.

CVEs

83 resultados
CVE-2021-23222A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification aEPSS 1.5%CVE-2021-20229A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special queryEPSS 1.5%CVE-2021-3677A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authentEPSS 1.4%CVE-2026-2005HIGHPostgreSQL pgcrypto heap buffer overflow executes arbitrary codeEPSS 1.2%CVE-2023-2454HIGHschema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attackeEPSS 1.2%CVE-2021-3393An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but EPSS 1.2%CVE-2020-1720LOWA flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticatedEPSS 1.2%CVE-2019-10130LOWA vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x EPSS 1.1%CVE-2026-2006HIGHPostgreSQL missing validation of multibyte character length executes arbitrary codeEPSS 1.1%CVE-2019-10209LOWPostgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.EPSS 1.1%CVE-2026-6473HIGHPostgreSQL server undersizes allocations, via integer wraparoundEPSS 1.0%CVE-2024-10976MEDIUMPostgreSQL row security below e.g. subqueries disregards user ID changesEPSS 0.8%CVE-2026-2004HIGHPostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary codeEPSS 0.8%CVE-2025-8714HIGHPostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientEPSS 0.7%CVE-2024-4317LOWPostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checksEPSS 0.7%CVE-2024-10978MEDIUMPostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user IDEPSS 0.7%CVE-2023-2455MEDIUMRow security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases whEPSS 0.7%CVE-2025-4207MEDIUMPostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validationEPSS 0.7%CVE-2022-41862LOWIn PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption.EPSS 0.6%CVE-2017-12172PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runsEPSS 0.6%