Known vulnerabilities in PostgreSQL - page 4

Software: PostgreSQL
Software CPE: cpe:2.3:a:postgresql_global_development_group:postgresql:*:*:*:*:*:*:*:*
Total vulnerabilities: 170
Public exploits: 9
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PostgreSQL PostgreSQL is affected by 170 known vulnerabilities: 2 critical, 18 high, 75 medium, 75 low Critical High Medium Low

Vulnerabilities (170)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU27923 - Untrusted Search Path
CVE-2020-10733
CWE-426 Low
No
No
9.5.22, 9.6.18, 10.13, 11.8, 12.3 14.05.2020 SB2020051418
SB2020062508
SB2021052507
and 1 more
#VU25333 - Improper Authorization
CVE-2020-1720
CWE-285 Low
No
No
9.6.17, 10.12, 11.7, 12.2 13.02.2020 SB2020021329
SB2020021411
SB2020021412
and 21 more
#VU30418 - Information Exposure Through an Error Message
CVE-2014-8161
CWE-209 Low
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 2 more
#VU30420 - Improper Control of Generation of Code ('Code Injection')
CVE-2015-0241
CWE-94 High
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 2 more
#VU30421 - Improper Control of Generation of Code ('Code Injection')
CVE-2015-0243
CWE-94 High
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 3 more
#VU30422 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2015-0244
CWE-89 High
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 3 more
#VU30589 - Memory corruption
CVE-2015-3166
CWE-119 High
No
No
9.4.2 20.11.2019 SB2019112024
SB2015052703
SB2015070725
and 1 more
#VU30590 - Exposure of sensitive information to an unauthorized actor
CVE-2015-3167
CWE-200 Medium
No
No
9.4.2 20.11.2019 SB2019112024
SB2015052704
SB2015070725
and 1 more
#VU22785 - Permissions, Privileges, and Access Controls
CVE-2019-3466
CWE-264 Low
No
No
9.4.25, 9.5.20, 9.6.16, 10.11, 11.6, 12.1 15.11.2019 SB2019111437
SB2019111501
SB2019111514
and 2 more
#VU20006 - Untrusted Search Path
CVE-2019-10211
CWE-426 Low
No
No
9.4.24, 9.5.19, 9.6.15, 10.10, 11.5 08.08.2019 SB2019080820
SB2020072802
SB2022102056
and 2 more
#VU20005 - Unprotected Storage of Credentials
CVE-2019-10210
CWE-256 Low
No
No
9.4.24, 9.5.19, 9.6.15, 10.10, 11.5 08.08.2019 SB2019080820
SB2020072802
SB2022102056
#VU20004 - Exposure of sensitive information to an unauthorized actor
CVE-2019-10209
CWE-200 Low
No
No
11.5 08.08.2019 SB2019080820
SB2019080904
SB2019080905
and 6 more
#VU20003 - Permissions, Privileges, and Access Controls
CVE-2019-10208
CWE-264 Low
No
No
9.4.24, 9.5.19, 9.6.15, 10.10, 11.5 08.08.2019 SB2019080820
SB2019080904
SB2019080905
and 27 more
#VU18862 - Memory corruption
CVE-2019-10164
CWE-119 Medium
No
No
10.9, 11.4, 12 20.06.2019 SB2019062003
#VU18861 - Stack-based buffer overflow
CVE-2019-10164
CWE-121 Medium
No
No
10.9, 11.4, 12 20.06.2019 SB2019062003
SB2019062104
SB2019072103
and 14 more
#VU18424 - Permissions, Privileges, and Access Controls
CVE-2019-10130
CWE-264 Low
No
No
9.4.22, 9.5.17, 9.6.13, 10.8, 11.3 10.05.2019 SB2019051001
SB2019051002
SB2019051513
and 29 more
#VU18423 - Missing release of memory after effective lifetime
CVE-2019-10129
CWE-401 Low
No
No
11.3 10.05.2019 SB2019051001
SB2019051513
SB2020031233
and 4 more
#VU18422 - Permissions, Privileges, and Access Controls
CVE-2019-10128
CWE-264 Low
No
No
9.4.22, 9.5.17, 9.6.13, 10.8, 11.3 10.05.2019 SB2019051001
SB2019051016
SB2022102056
#VU18421 - Permissions, Privileges, and Access Controls
CVE-2019-10127
CWE-264 Low
No
No
9.4.22, 9.5.17, 9.6.13, 10.8, 11.3 10.05.2019 SB2019051001
SB2019051015
SB2022102056
#VU15796 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-16850
CWE-89 Low
No
No
10.6, 11.1 09.11.2018 SB2018111202
SB2018112603
SB2018120302
and 4 more


Showing elements 61 - 80 out of 170