Exposição de PostgreSQL

Databases
41
score de exposição
9.760
sites usam
0
em exploração
0
críticos
Análise Vexday

O PostgreSQL acumula 83 CVEs catalogadas, sem registros de exploração ativa no catálogo KEV da CISA e sem vulnerabilidades de severidade crítica no conjunto atual — taxa abaixo da média geral do catálogo, o que sugere um perfil de risco relativamente controlado em relação ao universo de vendors monitorados. O tipo de falha mais frequente é CWE-200, relacionada à exposição indevida de informações, padrão que merece atenção em configurações de acesso e controle de privilégios. O ponto de maior atenção imediata é CVE-2025-1094, que apresenta EPSS de 0,89, indicando alta probabilidade de exploração na prática — essa CVE deve ser tratada como prioridade mesmo na ausência de confirmação formal no KEV. Adicionalmente, 11 vulnerabilidades surgiram nos últimos 90 dias, sinalizando atividade recente na superfície de ataque que requer monitoramento contínuo.

CVEs

83 resultados
CVE-2025-1094HIGHPostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validationEPSS 90.0%CVE-2017-7546PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackersEPSS 61.6%CVE-2020-25695A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker hEPSS 46.4%CVE-2018-1058A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account couEPSS 13.2%CVE-2022-1552A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another usEPSS 12.5%CVE-2017-7486PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any usEPSS 6.3%CVE-2017-15099INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contentEPSS 6.3%CVE-2017-7547PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackEPSS 5.6%CVE-2015-0241The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allowEPSS 5.5%CVE-2018-10915HIGHA vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between coEPSS 5.2%CVE-2018-16850HIGHpostgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. UsinEPSS 5.1%CVE-2015-0242Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9EPSS 5.1%CVE-2015-0243Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, andEPSS 5.1%CVE-2015-3166The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.EPSS 4.6%CVE-2024-10979HIGHPostgreSQL PL/Perl environment variable changes execute arbitrary codeEPSS 4.4%CVE-2015-0244PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erroEPSS 4.4%CVE-2015-3167contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses diffEPSS 4.1%CVE-2018-1115MEDIUMpostgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow EPSS 4.0%CVE-2017-15098Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before EPSS 3.7%CVE-2019-10164HIGHPostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user cEPSS 3.7%