Postgresql Jdbc Driver

Vendor:

First CVE: Oct 6, 2012 · Active for 13 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Postgresql Jdbc Driver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2012
13 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

CVE Severity & Scoring

Postgresql Jdbc Driver11 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network9 (81.8%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High4 (36.4%)
Unknown1 (9.1%)
User Interaction
None9 (81.8%)
Unknown1 (9.1%)
Required1 (9.1%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None8 (72.7%)
Unknown1 (9.1%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authent
Apr 29, 20267.536NONO
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerL
Mar 10, 20229.832NONO
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql li
Feb 2, 20229.832NONO
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with chan
Jul 6, 20265.931NONO
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A pl
Feb 19, 20249.829NONO
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the
Aug 30, 20188.128NONO
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the
Aug 3, 20228.026NONO
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configurat
Oct 6, 20127.523NONO
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(
Nov 23, 20225.521NONO
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
Jun 4, 20207.721NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Postgresql Jdbc Driver

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.117.52.9%00
42.5.015.50.5%00
42.4.118.01.7%00
42.4.018.01.7%00
42.3.219.83.0%00