PostgreSQL

First CVE: Feb 8, 2024Active for: 2 years
77
CVEs Published
More CVEs Published than 67% of tracked CNAs
25.7
Avg CVEs / Year
More Avg CVEs / Year than 74% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 61% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by PostgreSQL as a CNA, 31.2% affect products that PostgreSQL develops as a vendor.

31.2%
68.8%
Self-reported: 24Third-party: 53

Of all the CVEs published that affect products developed by PostgreSQL, 12.5% are self-published by PostgreSQL as a CNA.

12.5%
87.5%
Self-published: 24Published by other CNAs: 168

Trends Over Time

The number and severity of CVEs published by PostgreSQL over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2024
2 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Top CVEs

All CVEs published by PostgreSQL as a CNA, regardless of affected vendor or product.

77 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input
Feb 13, 20258.185NOYES
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticat
Mar 7, 20249.982NOYES
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on th
Apr 4, 20249.878NOYES
Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_t
Apr 3, 20258.867NOYES
pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files.
Nov 13, 20259.841NONO
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did>
Jun 19, 20269.039NONO
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may exe
May 14, 20268.839NONO
Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileg
Jun 19, 20268.838NONO
Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-
May 11, 20269.938NONO
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend th
May 9, 20269.838NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA77 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (2.6%)
Network75 (97.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low61 (79.2%)
High16 (20.8%)
Unknown0 (0.0%)
User Interaction
None64 (83.1%)
Unknown0 (0.0%)
Required13 (16.9%)
Privileges Required
Low46 (59.7%)
High4 (5.2%)
None27 (35.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (77 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
5.2% of CVEs· 97th percentile
Nuclei
1 CVE
1.3% of CVEs· 82nd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by PostgreSQL as a CNA.

Media Mentions

Media articles that mention a CVE ID published by PostgreSQL as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs