Vulnerabilities in DALIBO
8 resultsVexday analysis
DALIBO apresenta perfil de risco moderado com 8 vulnerabilidades registradas, nenhuma em exploração ativa ou crítica. A fraqueza dominante é injeção SQL (CWE-89), padrão clássico de risco em aplicações de dados. Recentemente, 3 vulnerabilidades foram publicadas nos últimos 90 dias, indicando exposição contínua que requer monitoramento.
CVE-2024-2339HIGHImproper Input Validation in PostgreSQL Anonymizer 1.2 allows table owner to gain superuser privileges via masking ruleEPSS 0.6%CVE-2024-2338HIGHSQL Injection in PostgreSQL Anonymizer 1.2 allows table owner to gain superuser privileges via masking ruleEPSS 0.5%CVE-2026-2360HIGHImproper search_path protection in PostgreSQL Anonymizer 2.5 allows any user to gain superuser privileges in PostgreSQL 14EPSS 0.4%CVE-2025-5690MEDIUMCursor allows PostgreSQL Anonymizer masked user to gain unauthorized access to authentic dataEPSS 0.3%CVE-2026-2361HIGHImproper search_path protection in PostgreSQL Anonymizer 2.5 allows any user with create privilege to gain superuser privilegesEPSS 0.3%CVE-2026-9617MEDIUMPostgreSQL Anonymizer: malicious column name allows SQL injection via anon.k_anonymity() functionEPSS 0.3%CVE-2026-11945MEDIUMPostgreSQL Anonymizer: SQL injection in the rules import functionsEPSS 0.2%CVE-2026-13455MEDIUMPostgreSQL Anonymizer: Unrestricted function can leak the secret saltEPSS 0.1%