Known vulnerabilities in postgresql (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:postgresql_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 30
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting postgresql (Red Hat package) postgresql (Red Hat package) is affected by 30 known vulnerabilities: 1 critical, 3 high, 17 medium, 9 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131455 - Integer overflow
CVE-2026-6473
CWE-190 Low
No
No
9.2.24-9.el7_9.6 14.05.2026 SB20260514106
SB20260514108
SB20260514109
and 55 more
#VU131459 - Stack-based buffer overflow
CVE-2026-6477
CWE-121 High
No
No
9.2.24-9.el7_9.6 14.05.2026 SB20260514106
SB20260514108
SB20260514109
and 51 more
#VU131460 - Information Exposure Through Timing Discrepancy
CVE-2026-6478
CWE-208 Medium
No
No
9.2.24-9.el7_9.6 14.05.2026 SB20260514106
SB20260514108
SB20260514109
and 50 more
#VU131463 - Stack-based buffer overflow
CVE-2026-6637
CWE-121 Medium
No
No
9.2.24-9.el7_9.6, 13.23-1.el9_2.3, 13.23-1.el9_6.3 14.05.2026 SB20260514106
SB20260514108
SB20260514109
and 29 more
#VU122779 - Memory corruption
CVE-2026-2006
CWE-119 Medium
No
No
13.23-1.el9_0.1, 13.23-1.el9_2.1, 13.23-1.el9_4.1, 13.23-1.el9_6.1, 13.23-2.el9_7 12.02.2026 SB2026021258
SB2026021302
SB2026021303
and 69 more
#VU122778 - Heap-based Buffer Overflow
CVE-2026-2005
CWE-122 Medium
No
No
13.23-1.el9_0.1, 13.23-1.el9_2.1, 13.23-1.el9_4.1, 13.23-1.el9_6.1, 13.23-2.el9_7 12.02.2026 SB2026021258
SB2026021302
SB2026021303
and 60 more
#VU122777 - Type confusion
CVE-2026-2004
CWE-843 Medium
No
No
13.23-1.el9_0.1, 13.23-1.el9_2.1, 13.23-1.el9_4.1, 13.23-1.el9_6.1, 13.23-2.el9_7 12.02.2026 SB2026021258
SB2026021302
SB2026021303
and 60 more
#VU118520 - Integer overflow
CVE-2025-12818
CWE-190 Medium
No
No
13.23-1.el9_0, 13.23-1.el9_2, 13.23-1.el9_4, 13.23-1.el9_7 13.11.2025 SB2025111368
SB2025112204
SB2025112205
and 64 more
#VU118519 - Missing Authorization
CVE-2025-12817
CWE-862 Low
No
No
13.23-1.el9_0, 13.23-1.el9_2, 13.23-1.el9_4, 13.23-1.el9_7 13.11.2025 SB2025111368
SB2025112204
SB2025112205
and 49 more
#VU114096 - Improper input validation
CVE-2025-8715
CWE-20 Medium
No
No
13.22-1.el9_0, 13.22-1.el9_2, 13.22-1.el9_4, 13.22-1.el9_6 14.08.2025 SB2025081496
SB2025081898
SB2025082551
and 52 more
#VU114095 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-8714
CWE-94 Low
Available
No
9.2.24-9.el7_9.4, 13.22-1.el9_0, 13.22-1.el9_2, 13.22-1.el9_4, 13.22-1.el9_6 14.08.2025 SB2025081496
SB2025081898
SB2025082551
and 60 more
#VU103970 - Improper input validation
CVE-2025-1094
CWE-20 Critical
Available
Exploited
9.2.24-9.el7_9.3, 13.20-1.el9_0, 13.20-1.el9_2, 13.20-1.el9_4, 13.20-1.el9_5 14.02.2025 SB2025021408
SB2025022038
SB2025022039
and 78 more
#VU100514 - Improper Authorization
CVE-2024-10979
CWE-285 High
No
No
9.2.24-9.el7_9.2, 13.18-1.el9_0, 13.18-1.el9_2, 13.18-1.el9_4, 13.18-1.el9_5 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 65 more
#VU100513 - Incorrect Privilege Assignment
CVE-2024-10978
CWE-266 Medium
No
No
13.18-1.el9_5 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 46 more
#VU100511 - Improper Privilege Management
CVE-2024-10976
CWE-269 Medium
No
No
13.18-1.el9_5 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 47 more
#VU95605 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-7348
CWE-367 Low
No
No
9.2.24-9.el7_9.1, 13.16-1.el9_0, 13.16-1.el9_2, 13.16-1.el9_4 08.08.2024 SB2024080866
SB2024080954
SB2024080955
and 63 more
#VU86275 - Improper Privilege Management
CVE-2024-0985
CWE-269 Medium
No
No
13.14-1.el9_0, 13.14-1.el9_2, 13.14-1.el9_3 08.02.2024 SB2024020869
SB2024021617
SB2024021637
and 62 more
#VU82943 - Permissions, Privileges, and Access Controls
CVE-2023-5870
CWE-264 Low
No
No
13.13-1.el9_0, 13.13-1.el9_2, 13.13-1.el9_3 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 54 more
#VU82941 - Exposure of sensitive information to an unauthorized actor
CVE-2023-5868
CWE-200 Low
No
No
13.13-1.el9_0, 13.13-1.el9_2, 13.13-1.el9_3 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 53 more
#VU79454 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39417
CWE-89 Medium
No
No
13.13-1.el9_0, 13.13-1.el9_2, 13.13-1.el9_3 11.08.2023 SB2023081132
SB2023081715
SB2023081716
and 60 more


Showing elements 1 - 20 out of 30