PostgreSQL
First CVE: Feb 8, 2024Active for: 2 years
77
CVEs Published
More CVEs Published than 67% of tracked CNAs
25.7
Avg CVEs / Year
More Avg CVEs / Year than 74% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 61% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by PostgreSQL as a CNA, 31.2% affect products that PostgreSQL develops as a vendor.
31.2%
68.8%
Self-reported: 24Third-party: 53
Of all the CVEs published that affect products developed by PostgreSQL, 12.5% are self-published by PostgreSQL as a CNA.
12.5%
87.5%
Self-published: 24Published by other CNAs: 168
Trends Over Time
The number and severity of CVEs published by PostgreSQL over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2024
2 years ago
Most Recent CVE
Jun 30, 2026
24 days ago
Top CVEs
All CVEs published by PostgreSQL as a CNA, regardless of affected vendor or product.
77 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1094HIGH Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input | Feb 13, 2025 | 8.1 | 85 | NO | YES |
CVE-2024-2044CRITICAL pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticat | Mar 7, 2024 | 9.9 | 82 | NO | YES |
CVE-2024-3116CRITICAL pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on th | Apr 4, 2024 | 9.8 | 78 | NO | YES |
CVE-2025-2945HIGH Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules).
The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_t | Apr 3, 2025 | 8.8 | 67 | NO | YES |
CVE-2025-12762CRITICAL pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. | Nov 13, 2025 | 9.8 | 41 | NO | NO |
CVE-2026-12046CRITICAL Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> | Jun 19, 2026 | 9.0 | 39 | NO | NO |
CVE-2026-6473HIGH Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may exe | May 14, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-12045HIGH Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileg | Jun 19, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-7813CRITICAL Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules.
Multiple endpoints fetched user- | May 11, 2026 | 9.9 | 38 | NO | NO |
CVE-2026-6665CRITICAL The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend th | May 9, 2026 | 9.8 | 38 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA77 CVEs
30%
56%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.6%)
Network75 (97.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low61 (79.2%)
High16 (20.8%)
Unknown0 (0.0%)
User Interaction
None64 (83.1%)
Unknown0 (0.0%)
Required13 (16.9%)
Privileges Required
Low46 (59.7%)
High4 (5.2%)
None27 (35.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (77 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
5.2% of CVEs· 97th percentile
Nuclei
1 CVE
1.3% of CVEs· 82nd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by PostgreSQL as a CNA.
Media Mentions
Media articles that mention a CVE ID published by PostgreSQL as a CNA — matched by CVE ID, not by organization name.