26 entries matching postgresql — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-48031 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202 | CRITICAL | 9.1 | 27%ile | NVD | 2026-08-03 |
| CVE-2026-17351 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu | CRITICAL | 9.4 | 37%ile | NVD | 2026-07-31 |
| CVE-2026-17566 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query in | CRITICAL | 9.4 | 35%ile | NVD | 2026-07-31 |
| CVE-2026-16503 | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces | CRITICAL | 9.1 | 16%ile | NVD | 2026-07-31 |
| CVE-2026-17346 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatin | HIGH | 8.7 | 36%ile | NVD | 2026-07-31 |
| CVE-2026-45376 | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3 | MEDIUM | 5.5 | 27%ile | NVD | 2026-07-31 |
| CVE-2026-54368 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows | HIGH | 8.7 | 32%ile | NVD | 2026-07-30 |
| CVE-2026-68563 | A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and th | MEDIUM | 5.5 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-62845 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv | MEDIUM | 4.7 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-50736 | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscrib | CRITICAL | 9.0 | 9%ile | NVD | 2026-07-28 |
| CVE-2026-50737 | When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's | CRITICAL | 9.0 | 9%ile | NVD | 2026-07-28 |
| CVE-2026-50738 | A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aft | HIGH | 7.7 | 22%ile | NVD | 2026-07-28 |
| CVE-2026-52888 | NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass | MEDIUM | 6.8 | 19%ile | GitHub | 2026-07-28 |
| CVE-2026-50735 | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me | MEDIUM | 6.1 | 9%ile | NVD | 2026-07-28 |
| CVE-2026-6473 | PostgreSQL server undersizes allocations, via integer wraparound | HIGH | 8.8 | 60%ile | Microsoft | 2026-05-12 |
| CVE-2026-6637 | PostgreSQL refint allows stack buffer overflow and SQL injection | HIGH | 8.8 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-6477 | PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory | HIGH | 8.8 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-6475 | PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice | HIGH | 8.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-6479 | PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-6478 | PostgreSQL discloses MD5-hashed passwords via covert timing channel | MEDIUM | 6.5 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-6472 | PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege | MEDIUM | 5.4 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-6474 | PostgreSQL timeofday() can disclose portions of server memory | MEDIUM | 4.3 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-6638 | PostgreSQL REFRESH PUBLICATION allows SQL injection via table name | LOW | 3.7 | 8%ile | Microsoft | 2026-05-12 |
| FG-IR-26-107 | Hardcoded symmetric encryption key for Postgresql | UNKNOWN | — | — | Fortinet | 2026-04-14 |
| CVE-2025-4207 | PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation | MEDIUM | 5.9 | 49%ile | Microsoft | 2025-05-13 |
| CVE-2024-4317 | PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks | MEDIUM | 4.3 | 50%ile | Microsoft | 2024-05-14 |