Known vulnerabilities in PostgreSQL - page 5

Software: PostgreSQL
Software CPE: cpe:2.3:a:postgresql_global_development_group:postgresql:*:*:*:*:*:*:*:*
Total vulnerabilities: 198
Public exploits: 9
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PostgreSQL PostgreSQL is affected by 198 known vulnerabilities: 2 critical, 22 high, 90 medium, 84 low Critical High Medium Low

Vulnerabilities (198)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU53233 - Missing release of memory after effective lifetime
CVE-2021-32029
CWE-401 Medium
No
No
11.12, 12.7, 13.3 13.05.2021 SB2021051316
SB2021051605
SB2021052507
and 18 more
#VU50656 - Permissions, Privileges, and Access Controls
CVE-2021-20229
CWE-264 Low
No
No
13.2 11.02.2021 SB2021021136
SB2021022002
SB2021022620
and 3 more
#VU50655 - Exposure of sensitive information to an unauthorized actor
CVE-2021-3393
CWE-200 Low
No
No
11.11, 12.6, 13.2 11.02.2021 SB2021021136
SB2021022002
SB2021022618
and 9 more
#VU48436 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-25695
CWE-89 Medium
No
No
9.5.24, 9.6.20, 10.15, 11.10, 12.5, 13.1 16.11.2020 SB2020111609
SB2020111711
SB2020111816
and 33 more
#VU48437 - Improper Access Control
CVE-2020-25694
CWE-284 Medium
No
No
9.5.24, 9.6.20, 10.15, 11.10, 12.5, 13.1 16.11.2020 SB2020111609
SB2020111711
SB2020111815
and 35 more
#VU48438 - Improper input validation
CVE-2020-25696
CWE-20 Medium
No
No
9.5.24, 9.6.20, 10.15, 11.10, 12.5, 13.1 16.11.2020 SB2020111609
SB2020111711
SB2020111817
and 32 more
#VU45749 - Untrusted Search Path
CVE-2020-14350
CWE-426 Medium
No
No
9.5.23, 9.6.19, 10.14, 11.9, 12.4 18.08.2020 SB2020081801
SB2020081802
SB2020081803
and 31 more
#VU45748 - Untrusted Search Path
CVE-2020-14349
CWE-426 Medium
No
No
10.14, 11.9, 12.4 18.08.2020 SB2020081801
SB2020081803
SB2020082205
and 23 more
#VU27923 - Untrusted Search Path
CVE-2020-10733
CWE-426 Low
No
No
9.5.22, 9.6.18, 10.13, 11.8, 12.3 14.05.2020 SB2020051418
SB2020062508
SB2021052507
and 1 more
#VU25333 - Improper Authorization
CVE-2020-1720
CWE-285 Low
No
No
9.6.17, 10.12, 11.7, 12.2 13.02.2020 SB2020021329
SB2020021411
SB2020021412
and 21 more
#VU30418 - Information Exposure Through an Error Message
CVE-2014-8161
CWE-209 Low
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 2 more
#VU30420 - Improper Control of Generation of Code ('Code Injection')
CVE-2015-0241
CWE-94 High
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 2 more
#VU30421 - Improper Control of Generation of Code ('Code Injection')
CVE-2015-0243
CWE-94 High
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 3 more
#VU30422 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2015-0244
CWE-89 High
No
No
9.4.1 27.01.2020 SB2020012730
SB2015041613
SB2015031303
and 3 more
#VU30589 - Memory corruption
CVE-2015-3166
CWE-119 High
No
No
9.4.2 20.11.2019 SB2019112024
SB2015052703
SB2015070725
and 1 more
#VU30590 - Exposure of sensitive information to an unauthorized actor
CVE-2015-3167
CWE-200 Medium
No
No
9.4.2 20.11.2019 SB2019112024
SB2015052704
SB2015070725
and 1 more
#VU22785 - Permissions, Privileges, and Access Controls
CVE-2019-3466
CWE-264 Low
No
No
9.4.25, 9.5.20, 9.6.16, 10.11, 11.6, 12.1 15.11.2019 SB2019111437
SB2019111501
SB2019111514
and 2 more
#VU20005 - Unprotected Storage of Credentials
CVE-2019-10210
CWE-256 Low
No
No
9.4.24, 9.5.19, 9.6.15, 10.10, 11.5 08.08.2019 SB2019080820
SB2020072802
SB2022102056
#VU20004 - Exposure of sensitive information to an unauthorized actor
CVE-2019-10209
CWE-200 Low
No
No
11.5 08.08.2019 SB2019080820
SB2019080904
SB2019080905
and 6 more
#VU20003 - Permissions, Privileges, and Access Controls
CVE-2019-10208
CWE-264 Low
No
No
9.4.24, 9.5.19, 9.6.15, 10.10, 11.5 08.08.2019 SB2019080820
SB2019080904
SB2019080905
and 27 more


Showing elements 81 - 100 out of 198