Skip to content
Noroxi

pgadmin records

48 published records for vendor pgadmin.

All records

48 records
  • CVE-2024-2044
    63This week

    Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4

    CriticalCVSS 9.9WeaponizedEPSS 79%

    pgadmin · pgadmin 4Mar 7, 2024

  • The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities suc

    HighCVSS 8.8Proof of conceptEPSS 80%

    pgadmin · pgadmin 4Dec 13, 2022

  • Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4

    CriticalCVSS 9.8WeaponizedEPSS 66%

    pgadmin · pgadmin 4Apr 4, 2024

  • pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment

    HighCVSS 8.8WeaponizedEPSS 56%

    pgadmin · pgadmin 4Apr 3, 2025

  • Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    pgadmin · pgadmin 4Nov 13, 2025

  • pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution

    CriticalCVSS 9.5No exploitEPSS 1%

    pgadmin · pgadmin 4Jun 18, 2026

  • pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)

    CriticalCVSS 9.4Proof of conceptEPSS 1%

    pgadmin · pgadmin 4Jul 31, 2026

  • pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution

    CriticalCVSS 9.4No exploitEPSS 1%

    pgadmin · pgadmin 4Jun 18, 2026

  • CVE-2026-7813
    37Monitor

    pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode

    CriticalCVSS 9.4No exploitEPSS 1%

    pgadmin · pgadmin 4May 11, 2026

  • pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode

    CriticalCVSS 9.3No exploitEPSS 1%

    pgadmin · pgadmin 4Sep 17, 2026

  • pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)

    CriticalCVSS 9.4Proof of conceptEPSS 0%

    pgadmin · pgadmin 4Jul 31, 2026

  • pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner

    CriticalCVSS 9.3No exploitEPSS 0%

    pgadmin · pgadmin 4Jul 31, 2026

  • pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser

    CriticalCVSS 9.3No exploitEPSS 0%

    pgadmin · pgadmin 4Jun 18, 2026

  • CVE-2023-5002
    36Monitor

    Pgadmin4: remote code execution by an authenticated user

    HighCVSS 8.8No exploitEPSS 2%

    pgadmin · pgadmin 4Sep 22, 2023

  • CVE-2026-7816
    35Monitor

    pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout

    HighCVSS 8.7No exploitEPSS 2%

    pgadmin · pgadmin 4May 11, 2026

  • Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

    HighCVSS 8.8Proof of conceptEPSS 1%

    pgadmin · pgadmin 4Dec 11, 2025

  • Command injection vulnerability allowing arbitrary command execution on Windows

    HighCVSS 8.8No exploitEPSS 1%

    pgadmin · pgadmin 4Nov 13, 2025

  • CVE-2024-4215
    35Monitor

    The Multi Factor Authentication bypass vulnerability in pgAdmin 4

    HighCVSS 8.8No exploitEPSS 1%

    pgadmin · pgadmin 4May 2, 2024

  • pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates

    HighCVSS 8.7No exploitEPSS 1%

    pgadmin · pgadmin 4Jun 18, 2026

  • CVE-2026-7815
    34Monitor

    pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution

    HighCVSS 8.7No exploitEPSS 1%

    pgadmin · pgadmin 4May 11, 2026

  • pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)

    HighCVSS 8.7No exploitEPSS 1%

    pgadmin · pgadmin 4Jul 31, 2026

  • pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool

    HighCVSS 8.7No exploitEPSS 1%

    pgadmin · pgadmin 4Sep 17, 2026

  • CVE-2025-9636
    31Monitor

    Cross-Origin Opener Policy Vulnerability in pgAdmin 4

    HighCVSS 7.9No exploitEPSS 0%

    pgadmin · pgadmin 4Sep 4, 2025

  • pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution

    HighCVSS 7.7No exploitEPSS 1%

    pgadmin · pgadmin 4Jul 31, 2026

  • pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.

    HighCVSS 7.5No exploitEPSS 0%

    pgadmin · pgadmin 4Nov 13, 2025