📦 Postgresql

by Postgresql

🔍 What is Postgresql?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-2004

HIGH CVSS 8.8 Feb 12, 2026

This vulnerability in PostgreSQL's intarray extension allows attackers to execute arbitrary code with the privileges of the database operating system user. It affects PostgreSQL installations with the...

CVE-2026-2006

HIGH CVSS 8.8 Feb 12, 2026

A buffer overflow vulnerability in PostgreSQL's text manipulation functions allows authenticated database users to execute arbitrary code with the privileges of the database server process. This affec...

CVE-2024-10979

HIGH CVSS 8.8 Nov 14, 2024

This vulnerability allows unprivileged database users in PostgreSQL to manipulate environment variables through PL/Perl, potentially leading to arbitrary code execution on the database server. It affe...

CVE-2024-0985

HIGH CVSS 8.0 Feb 8, 2024

This PostgreSQL vulnerability allows an attacker who creates a materialized view to execute arbitrary SQL functions with the privileges of the user who runs REFRESH MATERIALIZED VIEW CONCURRENTLY. The...

CVE-2023-5869

HIGH CVSS 8.8 Dec 10, 2023

This CVE-2023-5869 vulnerability in PostgreSQL allows authenticated database users to execute arbitrary code on the server through an integer overflow when modifying SQL arrays. Attackers can write ar...

CVE-2023-39417

HIGH CVSS 7.5 Aug 11, 2023

This SQL injection vulnerability in PostgreSQL allows attackers with database-level CREATE privilege to execute arbitrary code as the bootstrap superuser when exploiting improperly quoted extension sc...

CVE-2023-2454

HIGH CVSS 7.2 Jun 9, 2023

CVE-2023-2454 is a PostgreSQL vulnerability where the schema_element function can bypass protective search_path changes, allowing authenticated attackers with elevated database privileges to execute a...

CVE-2021-23214

HIGH CVSS 8.1 Mar 4, 2022

CVE-2021-23214 is a SQL injection vulnerability in PostgreSQL that allows man-in-the-middle attackers to inject arbitrary SQL queries during initial connection establishment, even when SSL certificate...

CVE-2024-10978

MEDIUM CVSS 4.2 Nov 14, 2024

This PostgreSQL vulnerability allows a less-privileged application user to view or modify unintended database rows when the application uses SET ROLE or SET SESSION AUTHORIZATION features. The issue o...