PostgreSQL is a widely embedded open-source relational database that, despite a narrow product line, occupies a critical position in the software supply chain and is deployed across an enormous range of applications, servers, and cloud platforms. Its vulnerabilities matter out of proportion to their volume because a single flaw in the database engine or its drivers can propagate to every downstream application that depends on it, and the recurring exposure centers on SQL injection, information disclosure, and memory-safety issues that reflect the parsing and protocol complexity inherent to a full-featured SQL implementation. A meaningful share of disclosed vulnerabilities reach serious severity, and the exposure spans the core database product and its JDBC driver alongside the postgresql-common packaging that enables widespread deployment across Linux distributions. Defenders should treat PostgreSQL advisories as high-priority wherever databases are internet-reachable or handle sensitive data, and should track upstream patches carefully since remediation typically requires direct database updates rather than dependency rebuilds. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by PostgreSQL over time
Of all the CVEs published by PostgreSQL as a CNA, 31.2% affect products that PostgreSQL develops as a vendor.
Of all the CVEs published that affect products developed by PostgreSQL, 12.5% are self-published by PostgreSQL as a CNA.
Signals from CVEs in this vendor scope (192 CVEs).
192 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9193HIGH In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of | Apr 1, 2019 | 7.2 | 89 | NO | YES |
CVE-2017-7546CRITICAL PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts wit | Aug 16, 2017 | 9.8 | 65 | NO | NO |
CVE-2013-1899MEDIUM Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption | Apr 4, 2013 | 6.5 | 57 | NO | YES |
CVE-2020-25695HIGH A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary | Nov 16, 2020 | 8.8 | 54 | NO | NO |
CVE-2007-3280HIGH The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows re | Jun 19, 2007 | 9.0 | 48 | NO | YES |
CVE-2026-6473HIGH Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may exe | May 14, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-2005HIGH Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18 | Feb 12, 2026 | 8.8 | 38 | NO | NO |
CVE-2005-0245HIGH Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which lea | Feb 1, 2005 | 7.5 | 38 | NO | YES |
CVE-2026-6637HIGH Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct at | May 14, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-6477HIGH Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser | May 14, 2026 | 8.8 | 37 | NO | NO |
Signals from CVEs in this vendor scope (192 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by PostgreSQL.
Media articles that mention a CVE ID that affects a product developed by PostgreSQL — matched by CVE ID, not by vendor name.