Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

PostgreSQL

First CVE: Dec 2, 1999Active for: 27 yearsTotal CVEs: 192
49.3
VTI Score
High

PostgreSQL is a widely embedded open-source relational database that, despite a narrow product line, occupies a critical position in the software supply chain and is deployed across an enormous range of applications, servers, and cloud platforms. Its vulnerabilities matter out of proportion to their volume because a single flaw in the database engine or its drivers can propagate to every downstream application that depends on it, and the recurring exposure centers on SQL injection, information disclosure, and memory-safety issues that reflect the parsing and protocol complexity inherent to a full-featured SQL implementation. A meaningful share of disclosed vulnerabilities reach serious severity, and the exposure spans the core database product and its JDBC driver alongside the postgresql-common packaging that enables widespread deployment across Linux distributions. Defenders should treat PostgreSQL advisories as high-priority wherever databases are internet-reachable or handle sensitive data, and should track upstream patches carefully since remediation typically requires direct database updates rather than dependency rebuilds. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
192
Total CVEs
More Total CVEs than 100% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by PostgreSQL over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 1999
26 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

Self-Reporting Analysis

Of all the CVEs published by PostgreSQL as a CNA, 31.2% affect products that PostgreSQL develops as a vendor.

31.2%
68.8%
Self-reported: 24 (31.2%)
Third-party: 53 (68.8%)

Of all the CVEs published that affect products developed by PostgreSQL, 12.5% are self-published by PostgreSQL as a CNA.

12.5%
87.5%
Self-published: 24 (12.5%)
Other CNAs: 168 (87.5%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (192 CVEs).

192 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9193HIGH
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of
Apr 1, 20197.289NOYES
CVE-2017-7546CRITICAL
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts wit
Aug 16, 20179.865NONO
CVE-2013-1899MEDIUM
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption
Apr 4, 20136.557NOYES
CVE-2020-25695HIGH
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary
Nov 16, 20208.854NONO
CVE-2007-3280HIGH
The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows re
Jun 19, 20079.048NOYES
CVE-2026-6473HIGH
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may exe
May 14, 20268.839NONO
CVE-2026-2005HIGH
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18
Feb 12, 20268.838NONO
CVE-2005-0245HIGH
Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which lea
Feb 1, 20057.538NOYES
CVE-2026-6637HIGH
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct at
May 14, 20268.837NONO
CVE-2026-6477HIGH
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser
May 14, 20268.837NONO
View all 192 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products192 CVEs
47%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (6.3%)
Network96 (50.0%)
Unknown84 (43.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low85 (44.3%)
High23 (12.0%)
Unknown84 (43.8%)
User Interaction
None98 (51.0%)
Unknown84 (43.8%)
Required10 (5.2%)
Privileges Required
Low64 (33.3%)
High7 (3.6%)
None37 (19.3%)
Unknown84 (43.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (192 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
1.6% of CVEs· 97th percentile
Nuclei
1 CVE
0.5% of CVEs· 95th percentile
ExploitDB
7 CVEs
3.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by PostgreSQL.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by PostgreSQL — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For PostgreSQL's Products

View all 8 CNAs →

Top CWEs