Записи pgadmin
48 опубликованных записей вендора pgadmin.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 6,3 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 87,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-306 Missing Authentication for Critical Function2
- CWE-284 Improper Access Control2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
48 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2024-2044Готовый эксплойт | Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4pgadmin · pgadmin 4 · CWE-31 | Критическая9,9 | — | 79,5 % | 7 мар. 2024 г. |
59В плане | CVE-2022-4223Proof of concept | The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities sucpgadmin · pgadmin 4 · CWE-94 | Высокая8,8 | — | 80,1 % | 13 дек. 2022 г. |
59В плане | CVE-2024-3116Готовый эксплойт | Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4pgadmin · pgadmin 4 · CWE-77 | Критическая9,8 | — | 65,6 % | 4 апр. 2024 г. |
52В плане | CVE-2025-2945Готовый эксплойт | pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deploymentpgadmin · pgadmin 4 · CWE-94 | Высокая8,8 | — | 56,3 % | 3 апр. 2025 г. |
43В плане | CVE-2025-12762Proof of concept | Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)pgadmin · pgadmin 4 · CWE-94 | Критическая9,8 | — | 12,7 % | 13 нояб. 2025 г. |
38Наблюдать | CVE-2026-12046Эксплойта нет | pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code executionpgadmin · pgadmin 4 · CWE-306 | Критическая9,5 | — | 1,0 % | 18 июн. 2026 г. |
37Наблюдать | CVE-2026-17566Proof of concept | pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)pgadmin · pgadmin 4 · CWE-78 | Критическая9,4 | — | 0,7 % | 31 июл. 2026 г. |
37Наблюдать | CVE-2026-12045Эксплойта нет | pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code executionpgadmin · pgadmin 4 · CWE-77 | Критическая9,4 | — | 0,7 % | 18 июн. 2026 г. |
37Наблюдать | CVE-2026-7813Эксплойта нет | pgAdmin 4: Cross-user data access and shared-server privilege escalation in server modepgadmin · pgadmin 4 · CWE-284 | Критическая9,4 | — | 0,7 % | 11 мая 2026 г. |
37Наблюдать | CVE-2026-86863Эксплойта нет | pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication modepgadmin · pgadmin 4 · CWE-290 | Критическая9,3 | — | 0,6 % | 17 сент. 2026 г. |
37Наблюдать | CVE-2026-17351Proof of concept | pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)pgadmin · pgadmin 4 · CWE-89 | Критическая9,4 | — | 0,5 % | 31 июл. 2026 г. |
37Наблюдать | CVE-2026-17349Эксплойта нет | pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-ownerpgadmin · pgadmin 4 · CWE-522 | Критическая9,3 | — | 0,4 % | 31 июл. 2026 г. |
37Наблюдать | CVE-2026-12048Эксплойта нет | pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parserpgadmin · pgadmin 4 · CWE-79 | Критическая9,3 | — | 0,3 % | 18 июн. 2026 г. |
36Наблюдать | CVE-2023-5002Эксплойта нет | Pgadmin4: remote code execution by an authenticated userpgadmin · pgadmin 4 · CWE-78 | Высокая8,8 | — | 1,8 % | 22 сент. 2023 г. |
35Наблюдать | CVE-2026-7816Эксплойта нет | pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakoutpgadmin · pgadmin 4 · CWE-78 | Высокая8,7 | — | 2,2 % | 11 мая 2026 г. |
35Наблюдать | CVE-2025-13780Proof of concept | Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)pgadmin · pgadmin 4 · CWE-94 | Высокая8,8 | — | 0,9 % | 11 дек. 2025 г. |
35Наблюдать | CVE-2025-12763Эксплойта нет | Command injection vulnerability allowing arbitrary command execution on Windowspgadmin · pgadmin 4 · CWE-78 | Высокая8,8 | — | 0,9 % | 13 нояб. 2025 г. |
35Наблюдать | CVE-2024-4215Эксплойта нет | The Multi Factor Authentication bypass vulnerability in pgAdmin 4pgadmin · pgadmin 4 · CWE-89 | Высокая8,8 | — | 0,6 % | 2 мая 2024 г. |
34Наблюдать | CVE-2026-12044Эксплойта нет | pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templatespgadmin · pgadmin 4 · CWE-89 | Высокая8,7 | — | 0,7 % | 18 июн. 2026 г. |
34Наблюдать | CVE-2026-7815Эксплойта нет | pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code executionpgadmin · pgadmin 4 · CWE-89 | Высокая8,7 | — | 0,6 % | 11 мая 2026 г. |
34Наблюдать | CVE-2026-17346Эксплойта нет | pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)pgadmin · pgadmin 4 · CWE-89 | Высокая8,7 | — | 0,6 % | 31 июл. 2026 г. |
34Наблюдать | CVE-2026-86864Эксплойта нет | pgAdmin 4: Argument and connection-string injection via the database field in the Backup toolpgadmin · pgadmin 4 · CWE-22 | Высокая8,7 | — | 0,6 % | 17 сент. 2026 г. |
31Наблюдать | CVE-2025-9636Эксплойта нет | Cross-Origin Opener Policy Vulnerability in pgAdmin 4pgadmin · pgadmin 4 · CWE-346 | Высокая7,9 | — | 0,2 % | 4 сент. 2025 г. |
30Наблюдать | CVE-2026-17347Эксплойта нет | pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutionpgadmin · pgadmin 4 · CWE-78 | Высокая7,7 | — | 0,7 % | 31 июл. 2026 г. |
30Наблюдать | CVE-2025-12764Эксплойта нет | pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.pgadmin · pgadmin 4 · CWE-90 | Высокая7,5 | — | 0,4 % | 13 нояб. 2025 г. |
- CVE-2024-204463На этой неделе
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
КритическаяCVSS 9,9Готовый эксплойтEPSS 79 %pgadmin · pgadmin 47 мар. 2024 г.
- CVE-2022-422359В плане
The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities suc
ВысокаяCVSS 8,8Proof of conceptEPSS 80 %pgadmin · pgadmin 413 дек. 2022 г.
- CVE-2024-311659В плане
Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
КритическаяCVSS 9,8Готовый эксплойтEPSS 66 %pgadmin · pgadmin 44 апр. 2024 г.
- CVE-2025-294552В плане
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
ВысокаяCVSS 8,8Готовый эксплойтEPSS 56 %pgadmin · pgadmin 43 апр. 2025 г.
- CVE-2025-1276243В плане
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
КритическаяCVSS 9,8Proof of conceptEPSS 13 %pgadmin · pgadmin 413 нояб. 2025 г.
- CVE-2026-1204638Наблюдать
pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
КритическаяCVSS 9,5Эксплойта нетEPSS 1 %pgadmin · pgadmin 418 июн. 2026 г.
- CVE-2026-1756637Наблюдать
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
КритическаяCVSS 9,4Proof of conceptEPSS 1 %pgadmin · pgadmin 431 июл. 2026 г.
- CVE-2026-1204537Наблюдать
pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %pgadmin · pgadmin 418 июн. 2026 г.
- CVE-2026-781337Наблюдать
pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %pgadmin · pgadmin 411 мая 2026 г.
- CVE-2026-8686337Наблюдать
pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %pgadmin · pgadmin 417 сент. 2026 г.
- CVE-2026-1735137Наблюдать
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
КритическаяCVSS 9,4Proof of conceptEPSS 0 %pgadmin · pgadmin 431 июл. 2026 г.
- CVE-2026-1734937Наблюдать
pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %pgadmin · pgadmin 431 июл. 2026 г.
- CVE-2026-1204837Наблюдать
pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %pgadmin · pgadmin 418 июн. 2026 г.
- CVE-2023-500236Наблюдать
Pgadmin4: remote code execution by an authenticated user
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %pgadmin · pgadmin 422 сент. 2023 г.
- CVE-2026-781635Наблюдать
pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout
ВысокаяCVSS 8,7Эксплойта нетEPSS 2 %pgadmin · pgadmin 411 мая 2026 г.
- CVE-2025-1378035Наблюдать
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %pgadmin · pgadmin 411 дек. 2025 г.
- CVE-2025-1276335Наблюдать
Command injection vulnerability allowing arbitrary command execution on Windows
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pgadmin · pgadmin 413 нояб. 2025 г.
- CVE-2024-421535Наблюдать
The Multi Factor Authentication bypass vulnerability in pgAdmin 4
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pgadmin · pgadmin 42 мая 2024 г.
- CVE-2026-1204434Наблюдать
pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %pgadmin · pgadmin 418 июн. 2026 г.
- CVE-2026-781534Наблюдать
pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %pgadmin · pgadmin 411 мая 2026 г.
- CVE-2026-1734634Наблюдать
pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %pgadmin · pgadmin 431 июл. 2026 г.
- CVE-2026-8686434Наблюдать
pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %pgadmin · pgadmin 417 сент. 2026 г.
- CVE-2025-963631Наблюдать
Cross-Origin Opener Policy Vulnerability in pgAdmin 4
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %pgadmin · pgadmin 44 сент. 2025 г.
- CVE-2026-1734730Наблюдать
pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %pgadmin · pgadmin 431 июл. 2026 г.
- CVE-2025-1276430Наблюдать
pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %pgadmin · pgadmin 413 нояб. 2025 г.