← Back to feed Search feed

PostgreSQL vulnerabilities

47 entries matching postgresql — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-85878Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a netwoCRITICAL9.945%ileNVD2026-09-18
CVE-2026-54354MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tranHIGH8.235%ileNVD2026-09-17
CVE-2026-53557SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated useHIGH7.719%ileNVD2026-09-17
CVE-2026-63460Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticaHIGH7.535%ileNVD2026-09-17
CVE-2026-53556SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datMEDIUM6.032%ileNVD2026-09-17
CVE-2026-75513Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several MarteCRITICAL9.129%ileNVD2026-09-16
CVE-2026-84993MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 aMEDIUM6.541%ileNVD2026-09-16
CVE-2026-55650Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2MEDIUM4.43%ileNVD2026-09-15
CVE-2026-12944IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) CRITICAL9.616%ileNVD2026-09-14
CVE-2026-82028Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API servHIGH8.736%ileNVD2026-09-14
CVE-2026-90775PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables befoHIGH7.128%ileNVD2026-09-13
CVE-2026-14662PostgreSQL tsvector and tsquery undersize allocations, via integer wraparoundHIGH8.839%ileMicrosoft2026-08-11
CVE-2026-14664PostgreSQL regexp heap buffer overflow executes arbitrary codeHIGH8.837%ileMicrosoft2026-08-11
CVE-2026-14670PostgreSQL plperl tied object heap buffer overflow executes arbitrary codeHIGH8.837%ileMicrosoft2026-08-11
CVE-2026-14671PostgreSQL refint plan cache type confusion executes arbitrary codeHIGH8.836%ileMicrosoft2026-08-11
CVE-2026-14677PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparoundHIGH8.836%ileMicrosoft2026-08-11
CVE-2026-14680PostgreSQL type confusion via "internal" argumentsHIGH8.836%ileMicrosoft2026-08-11
CVE-2026-15741PostgreSQL expression deparse allows SQL injection via EXTRACT argumentHIGH8.829%ileMicrosoft2026-08-11
CVE-2026-15742PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparoundHIGH8.837%ileMicrosoft2026-08-11
CVE-2026-16238PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary codeHIGH8.835%ileMicrosoft2026-08-11
CVE-2026-16239PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary codeHIGH8.844%ileMicrosoft2026-08-11
CVE-2026-18408PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql clientHIGH8.830%ileMicrosoft2026-08-11
CVE-2026-19385PostgreSQL pg_dump heap buffer overflow executes arbitrary codeHIGH8.836%ileMicrosoft2026-08-11
CVE-2026-14668PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary readHIGH8.127%ileMicrosoft2026-08-11
CVE-2026-6464PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commandsHIGH8.130%ileMicrosoft2026-08-11
CVE-2026-6471PostgreSQL logical decoding can dlopen arbitrary fileHIGH7.221%ileMicrosoft2026-08-11
CVE-2026-14663PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartextMEDIUM6.51%ileMicrosoft2026-08-11
CVE-2026-53572KEDA: PostgreSQL connection string parameter injection via incomplete whitespace escapingMEDIUM5.925%ileMicrosoft2026-08-11
CVE-2026-14672PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracleMEDIUM5.317%ileMicrosoft2026-08-11
CVE-2026-14678PostgreSQL pg_trgm picksplit reads past end of bufferMEDIUM4.310%ileMicrosoft2026-08-11
CVE-2026-18024PostgreSQL ascii() function reads past end of bufferMEDIUM4.310%ileMicrosoft2026-08-11
CVE-2026-6470PostgreSQL fails to check type USAGE privilegeMEDIUM4.310%ileMicrosoft2026-08-11
CVE-2026-14666PostgreSQL row security caching disregards role modificationsMEDIUM4.27%ileMicrosoft2026-08-11
CVE-2026-14673PostgreSQL amcheck does not clear untrusted search pathLOW3.87%ileMicrosoft2026-08-11
CVE-2026-6469PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownershipLOW3.89%ileMicrosoft2026-08-11
CVE-2026-6473PostgreSQL server undersizes allocations, via integer wraparoundHIGH8.862%ileMicrosoft2026-05-12
CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choiceHIGH8.826%ileMicrosoft2026-05-12
CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryHIGH8.839%ileMicrosoft2026-05-12
CVE-2026-6637PostgreSQL refint allows stack buffer overflow and SQL injectionHIGH8.831%ileMicrosoft2026-05-12
CVE-2026-6479PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionHIGH7.540%ileMicrosoft2026-05-12
CVE-2026-6478PostgreSQL discloses MD5-hashed passwords via covert timing channelMEDIUM6.545%ileMicrosoft2026-05-12
CVE-2026-6472PostgreSQL CREATE TYPE does not check multirange schema CREATE privilegeMEDIUM5.46%ileMicrosoft2026-05-12
CVE-2026-6474PostgreSQL timeofday() can disclose portions of server memoryMEDIUM4.312%ileMicrosoft2026-05-12
CVE-2026-6638PostgreSQL REFRESH PUBLICATION allows SQL injection via table nameLOW3.78%ileMicrosoft2026-05-12
CVE-2025-8714PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientHIGH8.853%ileMicrosoft2025-08-12
CVE-2025-8715PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target serverHIGH8.835%ileMicrosoft2025-08-12
CVE-2025-8713PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child tableLOW3.113%ileMicrosoft2025-08-12