23 Total CVEs
23 AI Analyzed
0 CISA KEV
0 Critical

Profile

0% ended up actively exploited 0 of 23 added to CISA KEV
0% rated critical (CVSS 9.0+) 0 critical, 23 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

23 CVEs in the last 12 months

Products

  • PostgreSQL22
  • server can1

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-23 of 23 CVEs
CVE-2026-6637
Analyzed
8.8
PostgreSQL PostgreSQL

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user runnin...

2026-05-15
Full analysis →
CVE-2026-6475
Analyzed
8.8
PostgreSQL PostgreSQL

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e

2026-05-15
Full analysis →
CVE-2026-6473
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and writ...

2026-05-15
Full analysis →
CVE-2026-2007
Analyzed
8.2
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string

2026-02-13
Full analysis →
CVE-2026-2006
Analyzed
8.8
PostgreSQL PostgreSQL

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer...

2026-02-13
Full analysis →
CVE-2026-2005
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database

2026-02-13
Full analysis →
CVE-2026-2004
Analyzed
8.8
PostgreSQL PostgreSQL

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code...

2026-02-13
Full analysis →
CVE-2026-19385
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system...

2026-08-14
Full analysis →
CVE-2026-18408
Analyzed
8.8
PostgreSQL PostgreSQL

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time executio...

2026-08-14
Full analysis →
CVE-2026-16239
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via...

2026-08-14
Full analysis →
CVE-2026-16238
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the...

2026-08-14
Full analysis →
CVE-2026-15742
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating...

2026-08-14
Full analysis →
CVE-2026-15741
Analyzed
8.8
PostgreSQL PostgreSQL

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition

2026-08-14
Full analysis →
CVE-2026-14680
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the datab...

2026-08-14
Full analysis →
CVE-2026-14677
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write o...

2026-08-14
Full analysis →
CVE-2026-14676
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the datab...

2026-08-14
Full analysis →
CVE-2026-14671
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database

2026-08-14
Full analysis →
CVE-2026-14670
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user runni...

2026-08-14
Full analysis →
CVE-2026-14669
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user...

2026-08-14
Full analysis →
CVE-2026-14664
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via tex...

2026-08-14
Full analysis →
CVE-2026-14662
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an all...

2026-08-14
Full analysis →