Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 149

Количество 149

redos логотип

ROS-20260708-73-0006

2 месяца назад

Уязвимость postgresql17

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0005

2 месяца назад

Уязвимость postgresql15-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0004

2 месяца назад

Уязвимость postgresql15

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0003

2 месяца назад

Уязвимость postgresql-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0002

2 месяца назад

Уязвимость postgresql14

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-6475

4 месяца назад

PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-6475

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-7h2q-899j-9636

4 месяца назад

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-07100

4 месяца назад

Уязвимость утилит pg_basebackup и pg_rewind системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписывать произвольные файлы

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260707-73-0058

2 месяца назад

Уязвимость postgresql16

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0035

2 месяца назад

Уязвимость postgresql14

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0034

2 месяца назад

Уязвимость postgresql18-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0033

2 месяца назад

Уязвимость postgresql18

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0032

2 месяца назад

Уязвимость postgresql17-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0031

2 месяца назад

Уязвимость postgresql17

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0030

2 месяца назад

Уязвимость postgresql16

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0029

2 месяца назад

Уязвимость postgresql15-1c

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redos логотип
ROS-20260708-73-0006

Уязвимость postgresql17

CVSS3: 8.8
1%
Низкий
2 месяца назад
redos логотип
ROS-20260708-73-0005

Уязвимость postgresql15-1c

CVSS3: 8.8
1%
Низкий
2 месяца назад
redos логотип
ROS-20260708-73-0004

Уязвимость postgresql15

CVSS3: 8.8
1%
Низкий
2 месяца назад
redos логотип
ROS-20260708-73-0003

Уязвимость postgresql-1c

CVSS3: 8.8
1%
Низкий
2 месяца назад
redos логотип
ROS-20260708-73-0002

Уязвимость postgresql14

CVSS3: 8.8
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-6475

PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice

CVSS3: 8.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-6475

Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-7h2q-899j-9636

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07100

Уязвимость утилит pg_basebackup и pg_rewind системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписывать произвольные файлы

CVSS3: 8.8
0%
Низкий
4 месяца назад
redos логотип
ROS-20260707-73-0058

Уязвимость postgresql16

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0035

Уязвимость postgresql14

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0034

Уязвимость postgresql18-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0033

Уязвимость postgresql18

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0032

Уязвимость postgresql17-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0031

Уязвимость postgresql17

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0030

Уязвимость postgresql16

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0029

Уязвимость postgresql15-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу