Exposição de PostgreSQL

Databases
77
score de exposição
10.313
sites usam
0
em exploração
0
críticos
Análise Vexday

O PostgreSQL acumula 83 CVEs catalogadas, sem registros de exploração ativa no catálogo KEV da CISA e sem vulnerabilidades de severidade crítica no conjunto atual — taxa abaixo da média geral do catálogo, o que sugere um perfil de risco relativamente controlado em relação ao universo de vendors monitorados. O tipo de falha mais frequente é CWE-200, relacionada à exposição indevida de informações, padrão que merece atenção em configurações de acesso e controle de privilégios. O ponto de maior atenção imediata é CVE-2025-1094, que apresenta EPSS de 0,89, indicando alta probabilidade de exploração na prática — essa CVE deve ser tratada como prioridade mesmo na ausência de confirmação formal no KEV. Adicionalmente, 11 vulnerabilidades surgiram nos últimos 90 dias, sinalizando atividade recente na superfície de ataque que requer monitoramento contínuo.

CVEs

111 resultados
CVE-2026-16238HIGHPostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary codeEPSS 0.4%CVE-2019-10210MEDIUMPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotectedEPSS 0.4%CVE-2024-10977LOWPostgreSQL libpq retains an error message from man-in-the-middleEPSS 0.4%CVE-2026-6637HIGHPostgreSQL refint allows stack buffer overflow and SQL injectionEPSS 0.4%CVE-2026-18408HIGHPostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql clientEPSS 0.4%CVE-2026-6464HIGHPostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commandsEPSS 0.4%CVE-2026-15741HIGHPostgreSQL expression deparse allows SQL injection via EXTRACT argumentEPSS 0.3%CVE-2025-12818MEDIUMPostgreSQL libpq undersizes allocations, via integer wraparoundEPSS 0.3%CVE-2026-14668HIGHPostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary readEPSS 0.3%CVE-2019-10127A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock downEPSS 0.3%CVE-2026-6475HIGHPostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choiceEPSS 0.3%CVE-2026-14679HIGHPostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memoryEPSS 0.3%CVE-2026-2003MEDIUMPostgreSQL oidvector discloses a few bytes of memoryEPSS 0.3%CVE-2026-6476HIGHPostgreSQL pg_createsubscriber allows SQL injection via subscription nameEPSS 0.3%CVE-2026-6471HIGHPostgreSQL logical decoding can dlopen arbitrary fileEPSS 0.3%CVE-2026-14672MEDIUMPostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracleEPSS 0.3%CVE-2025-12817LOWPostgreSQL CREATE STATISTICS does not check for schema CREATE privilegeEPSS 0.2%CVE-2025-8713LOWPostgreSQL optimizer statistics can expose sampled data within a view, partition, or child tableEPSS 0.2%CVE-2026-6474MEDIUMPostgreSQL timeofday() can disclose portions of server memoryEPSS 0.2%CVE-2026-6575MEDIUMPostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats arrayEPSS 0.2%