Exposição de PostgreSQL

Databases
77
score de exposição
10.313
sites usam
0
em exploração
0
críticos
Análise Vexday

O PostgreSQL acumula 83 CVEs catalogadas, sem registros de exploração ativa no catálogo KEV da CISA e sem vulnerabilidades de severidade crítica no conjunto atual — taxa abaixo da média geral do catálogo, o que sugere um perfil de risco relativamente controlado em relação ao universo de vendors monitorados. O tipo de falha mais frequente é CWE-200, relacionada à exposição indevida de informações, padrão que merece atenção em configurações de acesso e controle de privilégios. O ponto de maior atenção imediata é CVE-2025-1094, que apresenta EPSS de 0,89, indicando alta probabilidade de exploração na prática — essa CVE deve ser tratada como prioridade mesmo na ausência de confirmação formal no KEV. Adicionalmente, 11 vulnerabilidades surgiram nos últimos 90 dias, sinalizando atividade recente na superfície de ataque que requer monitoramento contínuo.

CVEs

111 resultados
CVE-2025-1094HIGHPostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validationEPSS 90.0%CVE-2017-7546PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackersEPSS 56.7%CVE-2020-25695A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker hEPSS 46.4%CVE-2022-1552A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another usEPSS 16.0%CVE-2018-1058A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account couEPSS 13.1%CVE-2017-15099INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contentEPSS 5.8%CVE-2017-7486PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any usEPSS 5.6%CVE-2015-0241The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allowEPSS 5.5%CVE-2017-7547PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackEPSS 5.5%CVE-2018-10915HIGHA vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between coEPSS 5.2%CVE-2018-16850HIGHpostgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. UsinEPSS 5.1%CVE-2015-0242Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9EPSS 5.1%CVE-2015-0243Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, andEPSS 5.1%CVE-2015-3166The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.EPSS 4.6%CVE-2024-10979HIGHPostgreSQL PL/Perl environment variable changes execute arbitrary codeEPSS 4.4%CVE-2015-0244PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erroEPSS 4.4%CVE-2015-3167contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses diffEPSS 4.1%CVE-2018-1115MEDIUMpostgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow EPSS 3.9%CVE-2019-10164HIGHPostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user cEPSS 3.7%CVE-2017-7548PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privEPSS 3.5%