EnterpriseDB Corporation

First CVE: May 14, 2024Active for: 2 years
4
CVEs Published
More CVEs Published than 12% of tracked CNAs
1.3
Avg CVEs / Year
More Avg CVEs / Year than 7% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by EnterpriseDB Corporation as a CNA, 50.0% affect products that EnterpriseDB Corporation develops as a vendor.

50.0%
50.0%
Self-reported: 2Third-party: 2

Of all the CVEs published that affect products developed by EnterpriseDB Corporation, 16.7% are self-published by EnterpriseDB Corporation as a CNA.

16.7%
83.3%
Self-published: 2Published by other CNAs: 10

Trends Over Time

The number and severity of CVEs published by EnterpriseDB Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2024
2 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Top CVEs

All CVEs published by EnterpriseDB Corporation as a CNA, regardless of affected vendor or product.

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive dat
Dec 15, 20257.023NONO
All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from p
May 14, 20247.721NONO
When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication
May 22, 20255.319NONO
PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript
Jan 16, 20264.818NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA4 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High2 (50.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low2 (50.0%)
High1 (25.0%)
None1 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by EnterpriseDB Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by EnterpriseDB Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs