Перейти к содержимому
Noroxi

Записи pgadmin

48 опубликованных записей вендора pgadmin.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 6,3 %
Pre-auth RCE
5
С записью об исправлении
87,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

48 записей
  • CVE-2024-2044
    63На этой неделе

    Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4

    КритическаяCVSS 9,9Готовый эксплойтEPSS 79 %

    pgadmin · pgadmin 47 мар. 2024 г.

  • CVE-2022-4223
    59В плане

    The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities suc

    ВысокаяCVSS 8,8Proof of conceptEPSS 80 %

    pgadmin · pgadmin 413 дек. 2022 г.

  • CVE-2024-3116
    59В плане

    Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4

    КритическаяCVSS 9,8Готовый эксплойтEPSS 66 %

    pgadmin · pgadmin 44 апр. 2024 г.

  • CVE-2025-2945
    52В плане

    pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 56 %

    pgadmin · pgadmin 43 апр. 2025 г.

  • CVE-2025-12762
    43В плане

    Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

    КритическаяCVSS 9,8Proof of conceptEPSS 13 %

    pgadmin · pgadmin 413 нояб. 2025 г.

  • CVE-2026-12046
    38Наблюдать

    pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution

    КритическаяCVSS 9,5Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 418 июн. 2026 г.

  • CVE-2026-17566
    37Наблюдать

    pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)

    КритическаяCVSS 9,4Proof of conceptEPSS 1 %

    pgadmin · pgadmin 431 июл. 2026 г.

  • CVE-2026-12045
    37Наблюдать

    pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 418 июн. 2026 г.

  • CVE-2026-7813
    37Наблюдать

    pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 411 мая 2026 г.

  • CVE-2026-86863
    37Наблюдать

    pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 417 сент. 2026 г.

  • CVE-2026-17351
    37Наблюдать

    pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)

    КритическаяCVSS 9,4Proof of conceptEPSS 0 %

    pgadmin · pgadmin 431 июл. 2026 г.

  • CVE-2026-17349
    37Наблюдать

    pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    pgadmin · pgadmin 431 июл. 2026 г.

  • CVE-2026-12048
    37Наблюдать

    pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    pgadmin · pgadmin 418 июн. 2026 г.

  • CVE-2023-5002
    36Наблюдать

    Pgadmin4: remote code execution by an authenticated user

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    pgadmin · pgadmin 422 сент. 2023 г.

  • CVE-2026-7816
    35Наблюдать

    pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout

    ВысокаяCVSS 8,7Эксплойта нетEPSS 2 %

    pgadmin · pgadmin 411 мая 2026 г.

  • CVE-2025-13780
    35Наблюдать

    Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    pgadmin · pgadmin 411 дек. 2025 г.

  • CVE-2025-12763
    35Наблюдать

    Command injection vulnerability allowing arbitrary command execution on Windows

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 413 нояб. 2025 г.

  • CVE-2024-4215
    35Наблюдать

    The Multi Factor Authentication bypass vulnerability in pgAdmin 4

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 42 мая 2024 г.

  • CVE-2026-12044
    34Наблюдать

    pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 418 июн. 2026 г.

  • CVE-2026-7815
    34Наблюдать

    pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 411 мая 2026 г.

  • CVE-2026-17346
    34Наблюдать

    pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 431 июл. 2026 г.

  • CVE-2026-86864
    34Наблюдать

    pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 417 сент. 2026 г.

  • CVE-2025-9636
    31Наблюдать

    Cross-Origin Opener Policy Vulnerability in pgAdmin 4

    ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %

    pgadmin · pgadmin 44 сент. 2025 г.

  • CVE-2026-17347
    30Наблюдать

    pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution

    ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %

    pgadmin · pgadmin 431 июл. 2026 г.

  • CVE-2025-12764
    30Наблюдать

    pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    pgadmin · pgadmin 413 нояб. 2025 г.