PostgreSQL records
220 published records for vendor postgresql.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 1.4%
- Pre-auth RCE
- 11
- With a fix record
- 86.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls20
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-189 Numeric Errors8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-20 Improper Input Validation7
The weakness classes this vendor ships most often: where to look.
CWEAll records
220 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2017-7546No exploit | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackerspostgresql · postgresql · CWE-287 | Critical9.8 | — | 61.6% | Aug 16, 2017 |
55Plan | CVE-2019-9193Weaponized | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to postgresql · postgresql · CWE-78 | High7.2 | — | 91.7% | Apr 1, 2019 |
49Plan | CVE-2020-25695No exploit | A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.postgresql · postgresql · CWE-89 | High8.8 | — | 46.4% | Nov 15, 2020 |
44Plan | CVE-2007-3280Weaponized | The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on thepostgresql · postgresql | Critical9.0 | — | 25.5% | Jun 19, 2007 |
42Plan | CVE-2013-1899Weaponized | Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to capostgresql · postgresql · CWE-94 | Medium6.5 | — | 54.3% | Apr 4, 2013 |
41Plan | CVE-2018-16850No exploit | postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ...postgresql · postgresql · CWE-89 | Critical9.8 | — | 5.2% | Nov 13, 2018 |
41Plan | CVE-2007-3279No exploit | PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the postgresql · postgresql | Critical10.0 | — | 2.6% | Jun 19, 2007 |
41Plan | CVE-2013-1903No exploit | PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly ppostgresql · postgresql · CWE-264 | Critical10.0 | — | 2.2% | Apr 4, 2013 |
41Plan | CVE-2013-1902No exploit | PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure tempostgresql · postgresql | Critical10.0 | — | 2.2% | Apr 4, 2013 |
41Plan | CVE-2002-1399No exploit | Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, wipostgresql · postgresql | Critical10.0 | — | 1.8% | Jan 17, 2003 |
40Plan | CVE-2022-1552No exploit | A flaw was found in PostgreSQL.postgresql · postgresql · CWE-459 | High8.8 | — | 16.0% | Aug 31, 2022 |
40Plan | CVE-2024-1597No exploit | pgjdbc SQL Injection via line comment generationpostgresql · postgresql jdbc driver · CWE-89 | Critical9.8 | — | 4.8% | Feb 19, 2024 |
40Plan | CVE-2015-3166No exploit | The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.postgresql · postgresql · CWE-119 | Critical9.8 | — | 4.6% | Nov 20, 2019 |
40Plan | CVE-2015-0244No exploit | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erropostgresql · postgresql · CWE-89 | Critical9.8 | — | 4.4% | Jan 27, 2020 |
40Plan | CVE-2022-21724No exploit | Unchecked Class Instantiation when providing Plugin Classespostgresql · postgresql jdbc driver · CWE-665 | Critical9.8 | — | 3.1% | Feb 2, 2022 |
40Plan | CVE-2022-26520No exploit | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary postgresql · postgresql jdbc driver | Critical9.8 | — | 3.0% | Mar 10, 2022 |
40Plan | CVE-2019-10211No exploit | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unpropostgresql · postgresql · CWE-94 | Critical9.8 | — | 1.8% | Oct 29, 2019 |
39Monitor | CVE-2018-1058Proof of concept | A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.postgresql · postgresql · CWE-20 | High8.8 | — | 13.1% | Mar 2, 2018 |
37Monitor | CVE-2017-7547No exploit | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackpostgresql · postgresql · CWE-522 | High8.8 | — | 5.6% | Aug 16, 2017 |
37Monitor | CVE-2015-0241No exploit | The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allowpostgresql · postgresql · CWE-120 | High8.8 | — | 5.5% | Jan 27, 2020 |
37Monitor | CVE-2015-0242No exploit | Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9postgresql · postgresql · CWE-787 | High8.8 | — | 5.1% | Jan 27, 2020 |
37Monitor | CVE-2015-0243No exploit | Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, andpostgresql · postgresql · CWE-120 | High8.8 | — | 5.1% | Jan 27, 2020 |
37Monitor | CVE-2016-3065No exploit | The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attapostgresql · postgresql · CWE-264 | Critical9.1 | — | 4.1% | Apr 11, 2016 |
37Monitor | CVE-2018-1115No exploit | postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow postgresql · postgresql · CWE-732 | Critical9.1 | — | 3.9% | May 10, 2018 |
36Monitor | CVE-2024-10979No exploit | PostgreSQL PL/Perl environment variable changes execute arbitrary codepostgresql · postgresql · CWE-15 | High8.8 | — | 4.4% | Nov 14, 2024 |
- CVE-2017-754657Plan
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers
CriticalCVSS 9.8No exploitEPSS 62%postgresql · postgresqlAug 16, 2017
- CVE-2019-919355Plan
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to
HighCVSS 7.2WeaponizedEPSS 92%postgresql · postgresqlApr 1, 2019
- CVE-2020-2569549Plan
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.
HighCVSS 8.8No exploitEPSS 46%postgresql · postgresqlNov 15, 2020
- CVE-2007-328044Plan
The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the
CriticalCVSS 9.0WeaponizedEPSS 25%postgresql · postgresqlJun 19, 2007
- CVE-2013-189942Plan
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to ca
MediumCVSS 6.5WeaponizedEPSS 54%postgresql · postgresqlApr 4, 2013
- CVE-2018-1685041Plan
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ...
CriticalCVSS 9.8No exploitEPSS 5%postgresql · postgresqlNov 13, 2018
- CVE-2007-327941Plan
PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the
CriticalCVSS 10.0No exploitEPSS 3%postgresql · postgresqlJun 19, 2007
- CVE-2013-190341Plan
PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly p
CriticalCVSS 10.0No exploitEPSS 2%postgresql · postgresqlApr 4, 2013
- CVE-2013-190241Plan
PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure tem
CriticalCVSS 10.0No exploitEPSS 2%postgresql · postgresqlApr 4, 2013
- CVE-2002-139941Plan
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, wi
CriticalCVSS 10.0No exploitEPSS 2%postgresql · postgresqlJan 17, 2003
- CVE-2022-155240Plan
A flaw was found in PostgreSQL.
HighCVSS 8.8No exploitEPSS 16%postgresql · postgresqlAug 31, 2022
- CVE-2024-159740Plan
pgjdbc SQL Injection via line comment generation
CriticalCVSS 9.8No exploitEPSS 5%postgresql · postgresql jdbc driverFeb 19, 2024
- CVE-2015-316640Plan
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.
CriticalCVSS 9.8No exploitEPSS 5%postgresql · postgresqlNov 20, 2019
- CVE-2015-024440Plan
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erro
CriticalCVSS 9.8No exploitEPSS 4%postgresql · postgresqlJan 27, 2020
- CVE-2022-2172440Plan
Unchecked Class Instantiation when providing Plugin Classes
CriticalCVSS 9.8No exploitEPSS 3%postgresql · postgresql jdbc driverFeb 2, 2022
- CVE-2022-2652040Plan
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary
CriticalCVSS 9.8No exploitEPSS 3%postgresql · postgresql jdbc driverMar 10, 2022
- CVE-2019-1021140Plan
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unpro
CriticalCVSS 9.8No exploitEPSS 2%postgresql · postgresqlOct 29, 2019
- CVE-2018-105839Monitor
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.
HighCVSS 8.8Proof of conceptEPSS 13%postgresql · postgresqlMar 2, 2018
- CVE-2017-754737Monitor
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attack
HighCVSS 8.8No exploitEPSS 6%postgresql · postgresqlAug 16, 2017
- CVE-2015-024137Monitor
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow
HighCVSS 8.8No exploitEPSS 6%postgresql · postgresqlJan 27, 2020
- CVE-2015-024237Monitor
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9
HighCVSS 8.8No exploitEPSS 5%postgresql · postgresqlJan 27, 2020
- CVE-2015-024337Monitor
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and
HighCVSS 8.8No exploitEPSS 5%postgresql · postgresqlJan 27, 2020
- CVE-2016-306537Monitor
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows atta
CriticalCVSS 9.1No exploitEPSS 4%postgresql · postgresqlApr 11, 2016
- CVE-2018-111537Monitor
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow
CriticalCVSS 9.1No exploitEPSS 4%postgresql · postgresqlMay 10, 2018
- CVE-2024-1097936Monitor
PostgreSQL PL/Perl environment variable changes execute arbitrary code
HighCVSS 8.8No exploitEPSS 4%postgresql · postgresqlNov 14, 2024