EnterpriseDB records
16 published records for vendor enterprisedb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 37.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-269 Improper Privilege Management1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-416 Use After Free1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-41117No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-427 | Critical9.8 | — | 0.8% | Dec 12, 2023 |
36Monitor | CVE-2026-50736No exploit | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes messageenterprisedb · pglogical · CWE-89 | Critical9.0 | — | 0.4% | Jul 28, 2026 |
36Monitor | CVE-2026-50737No exploit | When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressionsenterprisedb · pglogical · CWE-250 | Critical9.0 | — | 0.4% | Jul 28, 2026 |
35Monitor | CVE-2023-41118No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | High8.8 | — | 0.8% | Dec 12, 2023 |
35Monitor | CVE-2023-41119No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-269 | High8.8 | — | 0.6% | Dec 12, 2023 |
30Monitor | CVE-2026-50738No exploit | A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slenterprisedb · pglogical · CWE-416 | High7.7 | — | 0.5% | Jul 28, 2026 |
30Monitor | CVE-2023-31043No exploit | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used wienterprisedb · postgres advanced server · CWE-312 | High7.5 | — | 0.4% | Apr 23, 2023 |
28Monitor | CVE-2007-4639Proof of concept | EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listenerenterprisedb · postgres advanced server · CWE-824 | Medium6.5 | — | 5.1% | Aug 31, 2007 |
28Monitor | CVE-2025-14038No exploit | EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints.enterprisedb · hybrid manager · CWE-306 | High7.0 | — | 0.2% | Dec 15, 2025 |
26Monitor | CVE-2023-41115No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Medium6.5 | — | 0.6% | Dec 12, 2023 |
26Monitor | CVE-2023-41114No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Medium6.5 | — | 0.6% | Dec 12, 2023 |
26Monitor | CVE-2023-41120No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-668 | Medium6.5 | — | 0.5% | Dec 12, 2023 |
24Monitor | CVE-2026-50735No exploit | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copyinenterprisedb · pglogical · CWE-125 | Medium6.1 | — | 0.4% | Jul 28, 2026 |
19Monitor | CVE-2026-0949No exploit | PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Chenterprisedb · postgres enterprise manager · CWE-79 | Medium4.8 | — | 0.2% | Jan 16, 2026 |
17Monitor | CVE-2023-41113No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Medium4.3 | — | 0.5% | Dec 12, 2023 |
17Monitor | CVE-2023-41116No exploit | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Medium4.3 | — | 0.4% | Dec 12, 2023 |
- CVE-2023-4111739Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
CriticalCVSS 9.8No exploitEPSS 1%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2026-5073636Monitor
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message
CriticalCVSS 9.0No exploitEPSS 0%enterprisedb · pglogicalJul 28, 2026
- CVE-2026-5073736Monitor
When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions
CriticalCVSS 9.0No exploitEPSS 0%enterprisedb · pglogicalJul 28, 2026
- CVE-2023-4111835Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
HighCVSS 8.8No exploitEPSS 1%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2023-4111935Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
HighCVSS 8.8No exploitEPSS 1%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2026-5073830Monitor
A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying sl
HighCVSS 7.7No exploitEPSS 1%enterprisedb · pglogicalJul 28, 2026
- CVE-2023-3104330Monitor
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used wi
HighCVSS 7.5No exploitEPSS 0%enterprisedb · postgres advanced serverApr 23, 2023
- CVE-2007-463928Monitor
EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener
MediumCVSS 6.5Proof of conceptEPSS 5%enterprisedb · postgres advanced serverAug 31, 2007
- CVE-2025-1403828Monitor
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints.
HighCVSS 7.0No exploitEPSS 0%enterprisedb · hybrid managerDec 15, 2025
- CVE-2023-4111526Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
MediumCVSS 6.5No exploitEPSS 1%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2023-4111426Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
MediumCVSS 6.5No exploitEPSS 1%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2023-4112026Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
MediumCVSS 6.5No exploitEPSS 1%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2026-5073524Monitor
pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copyin
MediumCVSS 6.1No exploitEPSS 0%enterprisedb · pglogicalJul 28, 2026
- CVE-2026-094919Monitor
PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Ch
MediumCVSS 4.8No exploitEPSS 0%enterprisedb · postgres enterprise managerJan 16, 2026
- CVE-2023-4111317Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
MediumCVSS 4.3No exploitEPSS 0%enterprisedb · postgres advanced serverDec 12, 2023
- CVE-2023-4111617Monitor
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
MediumCVSS 4.3No exploitEPSS 0%enterprisedb · postgres advanced serverDec 12, 2023