Known vulnerabilities in PostgreSQL - page 2
Software:
PostgreSQL
Software CPE:
cpe:2.3:a:postgresql_global_development_group:postgresql:*:*:*:*:*:*:*:*
Website:
https://www.postgresql.org
Total vulnerabilities:
170
Public exploits:
9
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
18.4
17.10
16.14
15.18
14.23
18.3
17.9
16.13
15.17
14.22
18.2
17.8
16.12
15.16
14.21
18.1
17.7
16.11
15.15
14.20
13.23
18.0
17.6
16.10
15.14
14.19
13.22
17.5
16.9
15.13
14.18
13.21
17.4
16.8
15.12
14.17
13.20
17.3
16.7
15.11
14.16
13.19
17.2
16.6
15.10
14.15
13.18
12.22
17.1
16.5
15.9
14.14
13.17
12.21
17.0
16.4
15.8
14.13
13.16
12.20
16.3
15.7
14.12
13.15
12.19
16.2
15.6
14.11
13.14
12.18
16.1
15.5
14.10
13.13
12.17
11.22
16.0
15.4
14.9
13.12
12.16
11.21
15.3
14.8
13.11
12.15
11.20
15.2
14.7
13.10
12.14
11.19
15.1
14.6
13.9
12.13
11.18
10.23
15.0
14.5
13.8
12.12
11.17
10.22
14.4
14.3
13.7
12.11
11.16
10.21
14.2
13.6
12.10
11.15
10.20
14.1
13.5
12.9
11.14
10.19
9.6.24
14.0
13.4
12.8
11.13
10.18
9.6.23
13.3
12.7
11.12
10.17
9.6.22
13.2
12.6
11.11
10.16
9.6.21
9.5.25
13.1
12.5
11.10
10.15
9.6.20
9.5.24
13.0
8.4.22
12.4
11.9
10.14
9.6.19
9.5.23
5.0.3
10.10.4
12.3
11.8
10.13
9.6.18
9.5.22
12.2
11.7
10.12
9.6.17
9.5.21
9.4.26
12.1
11.6
10.11
9.6.16
9.5.20
9.4.25
12.0
11.5
10.10
9.6.15
9.5.19
9.4.24
12
11.4
10.9
9.6.14
9.5.18
9.4.23
11.3
11.2
10.8
10.7
9.6.13
9.6.12
9.6.11
9.5.17
9.5.16
9.5.15
9.5.13
9.5.12
9.4.22
9.4.21
9.4.20
9.4.18
9.4.17
9.3.25
9.3.23
9.3.22
11.1
11.0
10.6
9.3.24
9.4.19
9.5.14
9.6.10
10.5
9.6.8
10.4
9.6.9
10.3
10.2
10.1
10.0
9.6.7
9.5.11
9.5.10
9.5.9
9.4.16
9.4.15
9.4.14
9.3.21
9.3.20
9.3.19
9.3.18
9.3.0
9.2.24
9.2.23
9.2.0
9.1.24
9.1.22
9.1.21
9.1.20
9.1.0
9.0.23
9.0.21
9.0.20
9.0.18
9.0.17
9.0.16
8.4.21
8.4.20
8.4.0
8.3.23
8.3.0
8.2.23
8.2.22
8.2.21
8.2.20
8.2.0
8.1.23
8.1.22
8.0.26
7.4.30
7.3.21
7.3.20
1.08
9.6.6
9.6.5
9.5.8
9.6.4
9.5.0
9.4.13
9.2.22
9.6.3
9.5.7
9.4.12
9.3.17
9.2.21
9.6.2
9.6.1
9.6.0
9.5.6
9.5.5
9.5.3
9.5.2
9.4.11
9.4.10
9.4.8
9.4.7
9.4.6
9.3.13
9.3.12
9.3.11
9.3.10
9.3.16
9.3.15
9.2.20
9.2.19
9.2.17
9.2.16
9.2.15
9.5.1
9.2.14
9.5
9.4.5
9.4
9.1.19
9.0.22
9.2.13
9.2.12
9.3.8
9.2.11
9.3.9
9.3.7
9.1.18
9.1.17
9.1.16
9.4.3
9.4.4
9.4.2
9.2.10
9.4.0
9.0.19
9.4.1
9.3.3
9.3.4
9.3.5
9.3.6
9.2.7
9.2.8
9.2.9
9.1.12
9.1.15
9.1.14
9.1.13
9.3.2
9.3.1
9.1.9
9.0.13
9.0.14
9.0.15
8.4.19
8.4.18
8.4.17
9.2.4
9.2.5
9.2.6
9.3
9.1.11
9.1.10
8.4.16
9.2.3
9.2.1
9.2.2
9.1.8
9.0.12
9.2
9.1.5
9.1.6
9.1.7
9.0.10
9.0.11
8.4.14
8.4.13
8.4.15
9.0.9
8.3.20
8.3.21
8.3.22
8.3.19
8.4.12
9.1.4
9.0.8
8.4.11
9.1.3
8.3.18
9.0.7
9.1.1
8.4.7
8.4.10
8.4.8
8.4.9
9.0.4
8.3.15
9.0.5
8.3.16
9.1.2
9.0.3
8.3.17
9.0.6
8.3.14
8.2.19
8.2.18
9.0.1
9.0.2
8.4.6
8.4.5
8.3.13
8.3.12
9.0
7.4.29
8.2.17
8.4.4
8.0.25
8.3.11
8.1.21
7.4.28
7.4.27
9.0.0
8.4.2
8.4.3
8.0.24
8.1.19
8.3.9
8.1.20
8.3.10
8.2.15
8.2.16
8.5
8.0.23
8.1.18
8.3.8
7.4.26
8.1.17
8.2.14
8.4.1
8.0.22
8.0.19
8.0.17
8.0.18
8.0.15
8.0.16
7.4.19
7.4.23
7.4.22
7.4.21
7.4.25
7.4.20
8.1.14
8.1.15
8.1.12
8.1.13
8.1.11
8.0.21
8.3.3
8.3.4
8.3.1
8.3.2
8.2.8
8.3.7
8.2.9
8.2.6
8.3.5
8.2.7
8.3
8.4
8.2.13
8.2.11
8.2.10
7.4.24
8.1.16
8.3.6
8.0.20
8.2.12
8.0.12
8.2.5
7.4.18
8.0.14
8.1.10
8.1.8
8.1.7
8.1.9
8.0.11
8.0.13
8.2.2
8.2.4
8.0.317
7.4.17
8.2.3
8.1.6
8.1.5
1.09
6.4
6.2
6.5
6.0
6.3
6.1.1
6.3.1
7.3.18
7.2.8
8.0.10
6.5.2
7.0.1
6.5.1
6.1
8.0.9
7.4.15
7.4.16
1.0
6.4.1
6.2.1
7.3.16
7.3.17
6.4.2
7.0
1.02
1.01
8.2.1
8.2
7.4.14
8.1.4
7.4.13
8.0.8
7.0.2
7.3.15
8.1.3
8.0.7
7.3.14
7.4.12
8.0.6
7.4.9
7.4.8
7.3.10
7.3.11
7.3.12
7.3.13
8.1
7.4.10
7.4.11
8.1.2
8.0.4
8.0.5
8.1.0
8.1.1
8.0.3
8.0.2
8.0.1
8.0
7.4
7.3.4
7.3.7
7.3.5
7.3.8
7.3.6
7.3.9
8.0.0
7.4.2
7.2.5
7.4.6
7.4.1
7.4.4
7.2.6
7.4.7
7.2.7
7.4.3
7.4.5
7.3.3
7.2.4
7.3.1
7.3.2
7.3
7.3.19
7.2.2
7.2.3
7.0.3
7.1.3
7.1.1
7.2.1
7.1.2
7.1
7.2
6.5.0
6.3.2
6.5.3.1
6.5.3
9.1
9.5.4
9.4.9
9.3.14
9.2.18
9.1.23
Vulnerabilities (170)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU114096 - Improper input validation CVE-2025-8715 |
CWE-20 | Medium | 13.22, 14.19, 15.14, 16.10, 17.6 | 14.08.2025 |
SB2025081496 SB2025081898 SB2025082551 and 51 more |
||
| #VU108834 - Buffer over-read CVE-2025-4207 |
CWE-126 | Medium | 13.21, 14.18, 15.13, 16.9, 17.5 | 09.05.2025 |
SB2025050920 SB2025051669 SB20250521157 and 37 more |
||
| #VU103970 - Improper input validation CVE-2025-1094 |
CWE-20 | Critical | 13.19, 14.16, 15.11, 16.7, 17.3 | 14.02.2025 |
SB2025021408 SB2025022038 SB2025022039 and 77 more |
||
| #VU111802 - Use of Password Hash With Insufficient Computational Effort CVE-2002-1657 |
CWE-916 | Medium | - | 16.01.2025 |
SB2025011674 |
||
| #VU100514 - Improper Authorization CVE-2024-10979 |
CWE-285 | High | 12.21, 13.17, 14.14, 15.9, 16.5, 17.1 | 15.11.2024 |
SB2024111502 SB2024111601 SB2024112245 and 65 more |
||
| #VU100513 - Incorrect Privilege Assignment CVE-2024-10978 |
CWE-266 | Medium | 12.21, 13.17, 14.14, 15.9, 16.5, 17.1 | 15.11.2024 |
SB2024111502 SB2024111601 SB2024112245 and 46 more |
||
| #VU100512 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2024-10977 |
CWE-300 | Low | 12.21, 13.17, 14.14, 15.9, 16.5, 17.1 | 15.11.2024 |
SB2024111502 SB2024111601 SB2024112245 and 34 more |
||
| #VU100511 - Improper Privilege Management CVE-2024-10976 |
CWE-269 | Medium | 12.21, 13.17, 14.14, 15.9, 16.5, 17.1 | 15.11.2024 |
SB2024111502 SB2024111601 SB2024112245 and 47 more |
||
| #VU95605 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2024-7348 |
CWE-367 | Low | 12.20, 13.16, 14.13, 15.8, 16.4 | 08.08.2024 |
SB2024080866 SB2024080954 SB2024080955 and 63 more |
||
| #VU89297 - Missing Authorization CVE-2024-4317 |
CWE-862 | Low | 14.12, 15.7, 16.3 | 09.05.2024 |
SB2024050940 SB2024051519 SB2024051525 and 28 more |
||
| #VU111775 - Improper Authentication CVE-2009-3231 |
CWE-287 | Medium | 8.2.14, 8.3.8 | 13.02.2024 |
SB2024021385 SB2011102510 |
||
| #VU86275 - Improper Privilege Management CVE-2024-0985 |
CWE-269 | Medium | 12.18, 13.14, 14.11, 15.6, 16.2 | 08.02.2024 |
SB2024020869 SB2024021617 SB2024021637 and 62 more |
||
| #VU111793 - Improper input validation CVE-2004-0977 |
CWE-20 | Low | 7.4.6 | 02.02.2024 |
SB2024020259 SB2004101801 |
||
| #VU82943 - Permissions, Privileges, and Access Controls CVE-2023-5870 |
CWE-264 | Low | 11.22, 12.17, 13.13, 14.10, 15.5, 16.1 | 09.11.2023 |
SB2023110930 SB2023111320 SB2023111324 and 54 more |
||
| #VU82942 - Integer overflow CVE-2023-5869 |
CWE-190 | High | 11.22, 12.17, 13.13, 14.10, 15.5, 16.1 | 09.11.2023 |
SB2023110930 SB2023111320 SB2023111324 and 70 more |
||
| #VU82941 - Exposure of sensitive information to an unauthorized actor CVE-2023-5868 |
CWE-200 | Low | 11.22, 12.17, 13.13, 14.10, 15.5, 16.1 | 09.11.2023 |
SB2023110930 SB2023111320 SB2023111324 and 53 more |
||
| #VU111785 - Improper input validation CVE-2006-5541 |
CWE-20 | Low | 8.0.9, 8.1.5 | 12.10.2023 |
SB2023101297 |
||
| #VU79455 - Permissions, Privileges, and Access Controls CVE-2023-39418 |
CWE-264 | Low | 15.4 | 11.08.2023 |
SB2023081132 SB2023081716 SB2023081720 and 22 more |
||
| #VU79454 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2023-39417 |
CWE-89 | Medium | 11.21, 12.16, 13.12, 14.9, 15.4 | 11.08.2023 |
SB2023081132 SB2023081715 SB2023081716 and 60 more |
||
| #VU76041 - Permissions, Privileges, and Access Controls CVE-2023-2454 |
CWE-264 | Medium | 11.20, 12.15, 13.11, 14.8, 15.3 | 11.05.2023 |
SB2023051138 SB2023051301 SB2023051528 and 55 more |
Showing elements 21 - 40 out of 170