EnterpriseDB Corporation develops PostgreSQL-derived database server and management products that serve as critical infrastructure for data-driven enterprises, with vulnerabilities concentrating in its Postgres Advanced Server and enterprise management platforms. The vendor's disclosures skew toward moderate severity and recur through weakness classes spanning memory-safety issues such as uninitialized-pointer access, authentication and data-protection concerns including cleartext storage, and web-tier input-handling flaws such as cross-site scripting. Defenders should prioritize this vendor's releases where database instances are internet-reachable or process sensitive data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by EnterpriseDB Corporation over time
Of all the CVEs published by EnterpriseDB Corporation as a CNA, 50.0% affect products that EnterpriseDB Corporation develops as a vendor.
Of all the CVEs published that affect products developed by EnterpriseDB Corporation, 16.7% are self-published by EnterpriseDB Corporation as a CNA.
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4639MEDIUM EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated user | Aug 31, 2007 | 6.5 | 27 | NO | YES |
CVE-2023-41117CRITICAL An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-31043HIGH EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and red | Apr 23, 2023 | 7.5 | 24 | NO | NO |
CVE-2025-14038HIGH EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive dat | Dec 15, 2025 | 7.0 | 23 | NO | NO |
CVE-2023-41119HIGH An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-41118HIGH An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-41115MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. Whe | Dec 12, 2023 | 6.5 | 19 | NO | NO |
CVE-2026-0949MEDIUM PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript | Jan 16, 2026 | 4.8 | 18 | NO | NO |
CVE-2023-41120MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 6.5 | 17 | NO | NO |
CVE-2023-41114MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by EnterpriseDB Corporation.
Media articles that mention a CVE ID that affects a product developed by EnterpriseDB Corporation — matched by CVE ID, not by vendor name.