Записи EnterpriseDB
16 опубликованных записей вендора enterprisedb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 37,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-269 Improper Privilege Management1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-416 Use After Free1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-41117Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-427 | Критическая9,8 | — | 0,8 % | 12 дек. 2023 г. |
36Наблюдать | CVE-2026-50736Эксплойта нет | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes messageenterprisedb · pglogical · CWE-89 | Критическая9,0 | — | 0,4 % | 28 июл. 2026 г. |
36Наблюдать | CVE-2026-50737Эксплойта нет | When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressionsenterprisedb · pglogical · CWE-250 | Критическая9,0 | — | 0,4 % | 28 июл. 2026 г. |
35Наблюдать | CVE-2023-41118Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Высокая8,8 | — | 0,8 % | 12 дек. 2023 г. |
35Наблюдать | CVE-2023-41119Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-269 | Высокая8,8 | — | 0,6 % | 12 дек. 2023 г. |
30Наблюдать | CVE-2026-50738Эксплойта нет | A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slenterprisedb · pglogical · CWE-416 | Высокая7,7 | — | 0,5 % | 28 июл. 2026 г. |
30Наблюдать | CVE-2023-31043Эксплойта нет | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used wienterprisedb · postgres advanced server · CWE-312 | Высокая7,5 | — | 0,4 % | 23 апр. 2023 г. |
28Наблюдать | CVE-2007-4639Proof of concept | EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listenerenterprisedb · postgres advanced server · CWE-824 | Средняя6,5 | — | 5,1 % | 31 авг. 2007 г. |
28Наблюдать | CVE-2025-14038Эксплойта нет | EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints.enterprisedb · hybrid manager · CWE-306 | Высокая7,0 | — | 0,2 % | 15 дек. 2025 г. |
26Наблюдать | CVE-2023-41115Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Средняя6,5 | — | 0,6 % | 12 дек. 2023 г. |
26Наблюдать | CVE-2023-41114Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Средняя6,5 | — | 0,6 % | 12 дек. 2023 г. |
26Наблюдать | CVE-2023-41120Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server · CWE-668 | Средняя6,5 | — | 0,5 % | 12 дек. 2023 г. |
24Наблюдать | CVE-2026-50735Эксплойта нет | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copyinenterprisedb · pglogical · CWE-125 | Средняя6,1 | — | 0,4 % | 28 июл. 2026 г. |
19Наблюдать | CVE-2026-0949Эксплойта нет | PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Chenterprisedb · postgres enterprise manager · CWE-79 | Средняя4,8 | — | 0,2 % | 16 янв. 2026 г. |
17Наблюдать | CVE-2023-41113Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Средняя4,3 | — | 0,5 % | 12 дек. 2023 г. |
17Наблюдать | CVE-2023-41116Эксплойта нет | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beenterprisedb · postgres advanced server | Средняя4,3 | — | 0,4 % | 12 дек. 2023 г. |
- CVE-2023-4111739Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2026-5073636Наблюдать
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %enterprisedb · pglogical28 июл. 2026 г.
- CVE-2026-5073736Наблюдать
When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %enterprisedb · pglogical28 июл. 2026 г.
- CVE-2023-4111835Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2023-4111935Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2026-5073830Наблюдать
A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying sl
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %enterprisedb · pglogical28 июл. 2026 г.
- CVE-2023-3104330Наблюдать
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used wi
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %enterprisedb · postgres advanced server23 апр. 2023 г.
- CVE-2007-463928Наблюдать
EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener
СредняяCVSS 6,5Proof of conceptEPSS 5 %enterprisedb · postgres advanced server31 авг. 2007 г.
- CVE-2025-1403828Наблюдать
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints.
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %enterprisedb · hybrid manager15 дек. 2025 г.
- CVE-2023-4111526Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
СредняяCVSS 6,5Эксплойта нетEPSS 1 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2023-4111426Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
СредняяCVSS 6,5Эксплойта нетEPSS 1 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2023-4112026Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
СредняяCVSS 6,5Эксплойта нетEPSS 1 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2026-5073524Наблюдать
pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copyin
СредняяCVSS 6,1Эксплойта нетEPSS 0 %enterprisedb · pglogical28 июл. 2026 г.
- CVE-2026-094919Наблюдать
PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Ch
СредняяCVSS 4,8Эксплойта нетEPSS 0 %enterprisedb · postgres enterprise manager16 янв. 2026 г.
- CVE-2023-4111317Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
СредняяCVSS 4,3Эксплойта нетEPSS 0 %enterprisedb · postgres advanced server12 дек. 2023 г.
- CVE-2023-4111617Наблюдать
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x be
СредняяCVSS 4,3Эксплойта нетEPSS 0 %enterprisedb · postgres advanced server12 дек. 2023 г.