Known vulnerabilities in PostgreSQL - page 2

Software: PostgreSQL
Software CPE: cpe:2.3:a:postgresql_global_development_group:postgresql:*:*:*:*:*:*:*:*
Total vulnerabilities: 170
Public exploits: 9
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PostgreSQL PostgreSQL is affected by 170 known vulnerabilities: 2 critical, 18 high, 75 medium, 75 low Critical High Medium Low

Vulnerabilities (170)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114096 - Improper input validation
CVE-2025-8715
CWE-20 Medium
No
No
13.22, 14.19, 15.14, 16.10, 17.6 14.08.2025 SB2025081496
SB2025081898
SB2025082551
and 51 more
#VU108834 - Buffer over-read
CVE-2025-4207
CWE-126 Medium
No
No
13.21, 14.18, 15.13, 16.9, 17.5 09.05.2025 SB2025050920
SB2025051669
SB20250521157
and 37 more
#VU103970 - Improper input validation
CVE-2025-1094
CWE-20 Critical
Available
Exploited
13.19, 14.16, 15.11, 16.7, 17.3 14.02.2025 SB2025021408
SB2025022038
SB2025022039
and 77 more
#VU111802 - Use of Password Hash With Insufficient Computational Effort
CVE-2002-1657
CWE-916 Medium
No
No
- 16.01.2025 SB2025011674
#VU100514 - Improper Authorization
CVE-2024-10979
CWE-285 High
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 65 more
#VU100513 - Incorrect Privilege Assignment
CVE-2024-10978
CWE-266 Medium
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 46 more
#VU100512 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2024-10977
CWE-300 Low
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 34 more
#VU100511 - Improper Privilege Management
CVE-2024-10976
CWE-269 Medium
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 47 more
#VU95605 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-7348
CWE-367 Low
No
No
12.20, 13.16, 14.13, 15.8, 16.4 08.08.2024 SB2024080866
SB2024080954
SB2024080955
and 63 more
#VU89297 - Missing Authorization
CVE-2024-4317
CWE-862 Low
No
No
14.12, 15.7, 16.3 09.05.2024 SB2024050940
SB2024051519
SB2024051525
and 28 more
#VU111775 - Improper Authentication
CVE-2009-3231
CWE-287 Medium
No
No
8.2.14, 8.3.8 13.02.2024 SB2024021385
SB2011102510
#VU86275 - Improper Privilege Management
CVE-2024-0985
CWE-269 Medium
No
No
12.18, 13.14, 14.11, 15.6, 16.2 08.02.2024 SB2024020869
SB2024021617
SB2024021637
and 62 more
#VU111793 - Improper input validation
CVE-2004-0977
CWE-20 Low
No
No
7.4.6 02.02.2024 SB2024020259
SB2004101801
#VU82943 - Permissions, Privileges, and Access Controls
CVE-2023-5870
CWE-264 Low
No
No
11.22, 12.17, 13.13, 14.10, 15.5, 16.1 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 54 more
#VU82942 - Integer overflow
CVE-2023-5869
CWE-190 High
No
No
11.22, 12.17, 13.13, 14.10, 15.5, 16.1 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 70 more
#VU82941 - Exposure of sensitive information to an unauthorized actor
CVE-2023-5868
CWE-200 Low
No
No
11.22, 12.17, 13.13, 14.10, 15.5, 16.1 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 53 more
#VU111785 - Improper input validation
CVE-2006-5541
CWE-20 Low
No
No
8.0.9, 8.1.5 12.10.2023 SB2023101297
#VU79455 - Permissions, Privileges, and Access Controls
CVE-2023-39418
CWE-264 Low
No
No
15.4 11.08.2023 SB2023081132
SB2023081716
SB2023081720
and 22 more
#VU79454 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39417
CWE-89 Medium
No
No
11.21, 12.16, 13.12, 14.9, 15.4 11.08.2023 SB2023081132
SB2023081715
SB2023081716
and 60 more
#VU76041 - Permissions, Privileges, and Access Controls
CVE-2023-2454
CWE-264 Medium
No
No
11.20, 12.15, 13.11, 14.8, 15.3 11.05.2023 SB2023051138
SB2023051301
SB2023051528
and 55 more


Showing elements 21 - 40 out of 170