31 Total CVEs
24 AI Analyzed
0 CISA KEV
4 Critical
All Vendors
Showing 1-31 of 31 CVEs
CVE-2026-6637
Analyzed
8.8
PostgreSQL module

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user runnin...

2026-05-15
CVE-2026-6477
Analyzed
8.8
PostgreSQL libpq lo

Use of inherently dangerous function PQfn(

2026-05-15
CVE-2026-6475
Analyzed
8.8
PostgreSQL pg

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e

2026-05-15
CVE-2026-6473
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and writ...

2026-05-15
CVE-2026-4427
7.5
PostgreSQL server can

A flaw was found in pgproto3

2026-03-20
CVE-2026-42198
7.5
PostgreSQL JDBC Driver

pgjdbc is an open source postgresql JDBC Driver

2026-04-30
CVE-2026-41167
Analyzed
9.1
PostgreSQL host via

Jellystat is vulnerable to SQL injection and subsequent remote code execution due to improper sanitization of user-supplied data in API endpoints.

2026-04-23
CVE-2026-40906
Analyzed
9.9
PostgreSQL database through

ElectricSQL is vulnerable to error-based SQL injection via the /v1/shape API, allowing authenticated users to read, modify, or destroy database conten...

2026-04-22
CVE-2026-40887
Analyzed
9.1
PostgreSQL Vendure

An unauthenticated SQL injection vulnerability in the Vendure Shop API allows remote attackers to execute arbitrary SQL commands against the backend d...

2026-04-22
CVE-2026-32628
Analyzed
8.8
PostgreSQL Multiple Products

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting

2026-03-17
CVE-2026-30860
Analyzed
9.9
PostgreSQL array expressions

A remote code execution vulnerability in WeKnora's database query functionality allows unauthenticated attackers to bypass SQL injection protections v...

2026-03-08
CVE-2026-2361
8
PostgreSQL Anonymizer contains

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function contai...

2026-02-12
CVE-2026-2007
8.2
PostgreSQL pg

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string

2026-02-13
CVE-2026-2006
8.8
PostgreSQL text manipulation

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer...

2026-02-13
CVE-2026-2005
8.8
PostgreSQL pgcrypto allows

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database

2026-02-13
CVE-2026-2004
8.8
PostgreSQL intarray extension

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code...

2026-02-13
CVE-2026-19385
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system...

2026-08-14
CVE-2026-18408
Analyzed
8.8
PostgreSQL PostgreSQL

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time executio...

2026-08-14
CVE-2026-16239
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via...

2026-08-14
CVE-2026-16238
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the...

2026-08-14
CVE-2026-15742
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating...

2026-08-14
CVE-2026-15741
Analyzed
8.8
PostgreSQL PostgreSQL

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition

2026-08-14
CVE-2026-14680
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the datab...

2026-08-14
CVE-2026-14677
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write o...

2026-08-14
CVE-2026-14676
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the datab...

2026-08-14
CVE-2026-14671
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database

2026-08-14
CVE-2026-14670
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user runni...

2026-08-14
CVE-2026-14669
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user...

2026-08-14
CVE-2026-14664
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via tex...

2026-08-14
CVE-2026-14662
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an all...

2026-08-14
CVE-2026-12044
Analyzed
8.8
PostgreSQL pgAdmin 4

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON

2026-06-19