28,678 Entries 2,229 Sources 5 Verticals Last sync 2 minutes Live
Dashboard/ OS & platform/ PostgreSQL
OS & platform

PostgreSQL

PostgreSQL Global Dev Group
CVE-2026-46446 latest release
05.06.2026
Specsattributes
eol_productpostgresql
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
OS & platform High

A SQL injection vulnerability in SOGo software allows attackers to inject malicious database commands when PostgreSQL or MariaDB is used and passwords are stored in cleartext.

CVE-2026-46446
05.06.2026
CVE
OS & platform High

A vulnerability in SOGo (not PostgreSQL itself) allows SQL injection attacks when PostgreSQL is used as the database, potentially enabling attackers to unauthorized access or manipulate data.

CVE-2026-46445
05.06.2026
CVE
OS & platform Critical

A vulnerability in CKAN (a data management system) allows attackers to bypass authorization controls and access private data as well as PostgreSQL system information.

CVE-2026-42032
05.06.2026
CVE
OS & platform Critical

A vulnerability in CKAN (a data management system) allows attackers to inject malicious SQL code, enabling access to confidential data and PostgreSQL system information.

CVE-2026-42031
05.06.2026
CVE
OS & platform High

A SQL injection vulnerability in the postgrex PostgreSQL driver for Elixir allows attackers to execute arbitrary SQL commands when they can influence channel names in notification functions, potentially leading to data loss or unauthorized database access.

CVE-2026-32687
05.06.2026
CVE
OS & platform Critical

A vulnerability in Google Cloud AlloyDB for PostgreSQL caused database clusters created via Terraform or REST API to receive insecure default passwords, allowing attackers with network access to gain full administrative database access.

CVE-2026-7428
05.06.2026
CVE
OS & platform High

A security vulnerability in pgAdmin 4 allows authenticated users to inject malicious SQL code and thereby execute arbitrary commands on the database server.

CVE-2026-7815
05.06.2026
CVE
OS & platform Medium

A security vulnerability in pgAdmin 4 allows attackers to execute malicious JavaScript code in web browsers by using specially crafted names for PostgreSQL objects.

CVE-2026-7814
05.06.2026
CVE
OS & platform Critical

A security vulnerability in the pgx PostgreSQL driver for Go allows SQL injection attacks under specific conditions involving special string literals, enabling attackers to inject malicious database commands.

CVE-2026-41889
05.06.2026
CVE
OS & platform High

A vulnerability in PraisonAI allows SQL injection attacks through unvalidated parameters in multiple database connections, enabling attackers to manipulate databases or access sensitive data.

CVE-2026-41496
05.06.2026
CVE
OS & platform High

A SQL injection vulnerability in Rucio allows authenticated users to execute arbitrary SQL commands against the PostgreSQL database. This can lead to exposure of sensitive data, data manipulation, or even code execution.

CVE-2026-29090
05.06.2026
CVE
OS & platform High

A SQL injection vulnerability in Rucio allows authenticated users to execute arbitrary SQL commands against the Oracle database, potentially stealing or manipulating all managed data, authentication tokens, and password hashes.

CVE-2026-29080
05.06.2026
CVE
OS & platform High

SQLBot, a text-to-SQL system, passes user input unfiltered to an AI model and executes the generated SQL commands without validation. Attackers can exploit this to execute arbitrary SQL commands and, when connected to PostgreSQL, even run code on the server.

CVE-2026-33324
05.06.2026
CVE
OS & platform High

A vulnerability in the PostgreSQL JDBC driver allows malicious servers to freeze client computers through extremely CPU-intensive authentication, blocking CPU cores and exhausting connection pools.

affects: ≥42.2.0 <42.7.11

CVE-2026-42198
05.06.2026
CVE
OS & platform Critical

A critical security flaw in H2O-3 software allows attackers to execute arbitrary code on the server without authentication by exploiting PostgreSQL-specific parameters in the REST API.

CVE-2026-3960
05.06.2026
CVE
OS & platform Critical

A security vulnerability in Jellystat software allows authenticated users to inject malicious SQL code, enabling them to steal sensitive data from the database or even execute arbitrary commands on the PostgreSQL server.

CVE-2026-41167
05.06.2026
CVE
OS & platform Critical

A vulnerability in ElectricSQL allows authenticated users to read, modify, or destroy the entire PostgreSQL database through manipulated sorting parameters in the API.

CVE-2026-40906
05.06.2026
CVE
OS & platform Medium

OpenBao, a secrets management system, fails to properly quote database schema names when revoking PostgreSQL privileges, which can cause revocation failures or rarely enable SQL injection attacks.

CVE-2026-39946
05.06.2026
CVE
OS & platform Critical

A vulnerability in Aperi'Solve allows attackers to gain root access to the server through manipulated JPEG passwords without authentication, potentially compromising the PostgreSQL database and other system components.

CVE-2026-34977
05.06.2026
CVE
OS & platform Critical

A vulnerability in the Kestra orchestration platform allows authenticated users to execute arbitrary commands on the server by visiting a crafted link, as SQL injection attacks are possible through PostgreSQL.

CVE-2026-34612
05.06.2026
CVE
OS & platform High

Hi.Events, an open-source event management platform, contains a SQL injection vulnerability in multiple repository classes that pass user input directly to the database without validation, allowing attackers to execute malicious SQL commands.

CVE-2026-34455
05.06.2026
CVE
OS & platform High

A vulnerability in PostgreSQL allows malicious servers to crash client applications by sending manipulated data messages with invalid field lengths.

CVE-2026-32286
05.06.2026
CVE
OS & platform High

A vulnerability in the n8n workflow automation platform allows authenticated users to manipulate or delete data in PostgreSQL databases through SQL injection attacks.

CVE-2026-33713
05.06.2026
CVE
OS & platform High

Parse Server, a Node.js backend application, contains a SQL injection vulnerability in PostgreSQL connections. Attackers with master key access can execute arbitrary SQL commands and escalate their privileges from application level to database level access.

CVE-2026-33539
05.06.2026
CVE
OS & platform High

A security vulnerability in SQLBot allows authenticated users to inject malicious SQL commands through manipulated Excel files, enabling them to gain complete control over the server.

CVE-2026-32950
05.06.2026
CVE
OS & platform High

A security flaw in SQLBot allows authenticated users to inject malicious content through Excel uploads and manipulate the AI system to execute dangerous PostgreSQL commands, ultimately gaining remote access to the server.

CVE-2026-32622
05.06.2026
CVE
OS & platform High

A SQL injection vulnerability in AnythingLLM allows users to execute arbitrary SQL commands on connected databases because table names are unsafely inserted into queries without proper sanitization.

CVE-2026-32628
05.06.2026
CVE
OS & platform Critical

Parse Server, a backend software for Node.js, contains a critical security vulnerability that allows attackers to take over any user account without authentication by sending specially crafted login requests.

CVE-2026-32248
05.06.2026
CVE
OS & platform Medium

Parse Server, a Node.js backend software, contains a SQL injection vulnerability when using PostgreSQL databases. Attackers with master key access can inject malicious SQL commands through crafted field names in queries, bypassing Parse Server to directly attack the database.

CVE-2026-32234
05.06.2026
CVE
OS & platform High

A security vulnerability in Parse Server allows attackers to bypass protected database field restrictions using dot-notation queries, potentially exposing sensitive data that should be protected.

CVE-2026-31872
05.06.2026
CVE
OS & platform Critical

A critical SQL injection vulnerability in Parse Server allows attackers to execute arbitrary SQL commands in PostgreSQL databases through crafted field names, bypassing security controls.

CVE-2026-31871
05.06.2026
CVE
OS & platform Critical

A SQL injection vulnerability in Parse Server allows attackers to execute arbitrary SQL commands through the REST API and thereby read all data from PostgreSQL databases.

CVE-2026-31856
05.06.2026
CVE
OS & platform Critical

A vulnerability in Parse Server allows SQL injection attacks against PostgreSQL databases through improper handling of dot-notation field names in sort and other query parameters, enabling attackers to inject malicious SQL commands.

CVE-2026-31840
05.06.2026
CVE
OS & platform High

PostgreSQL contains hard-coded credentials that could allow attackers with administrator access and known database passwords to steal information or execute malicious code when SOCKS proxy functionality is enabled.

CVE-2025-13957
05.06.2026
CVE
OS & platform High

A vulnerability in the Budibase low-code platform allows attackers to execute malicious commands through unsafe PostgreSQL database connection parameters, as user inputs are not properly sanitized before shell execution.

CVE-2026-25041
05.06.2026
CVE
OS & platform Critical

A security vulnerability in WeKnora, a document understanding framework, allows attackers to execute malicious code on the PostgreSQL database server by bypassing SQL injection protections.

CVE-2026-30860
05.06.2026
CVE
OS & platform High

A security vulnerability in the TimescaleDB extension for PostgreSQL allows malicious users to create custom functions that override built-in PostgreSQL functions, potentially enabling arbitrary code execution during extension upgrades.

CVE-2026-29089
05.06.2026
CVE
OS & platform Critical

Chartbrew, a web application for data visualization, contains an SQL injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL commands into connected databases, potentially reading, modifying, or deleting data.

CVE-2026-27005
05.06.2026
CVE
OS & platform Medium

A vulnerability in Packetbeat's PostgreSQL protocol parser allows attackers to crash the Packetbeat process by sending specially crafted network packets when PostgreSQL monitoring is enabled.

CVE-2026-26932
05.06.2026
CVE
OS & platform Medium

A vulnerability in Apache Superset allows authenticated users with SQLLab access to bypass read-only restrictions on PostgreSQL connections and perform unauthorized data modifications or deletions.

CVE-2026-23984
05.06.2026
CVE
OS & platform Medium

Apache Superset had an incomplete list of blocked SQL functions for ClickHouse database, potentially allowing attackers to execute sensitive database operations that should have been restricted.

CVE-2026-23969
05.06.2026
CVE
OS & platform Critical

RUCKUS Network Director appliances use identical SSH keys across all installations, allowing attackers to log in without passwords and gain complete control over the PostgreSQL database and administrative user accounts.

CVE-2025-67305
05.06.2026
CVE
OS & platform Critical

A vulnerability in Ruckus Network Director allows attackers to remotely access the PostgreSQL database using hardcoded credentials, enabling them to gain administrator privileges and execute arbitrary system commands.

CVE-2025-67304
05.06.2026
CVE
OS & platform High

A vulnerability in PostgreSQL allows database users to cause a buffer overflow through crafted input strings, potentially leading to privilege escalation within the database system.

affects: ≥18.0 <18.2

CVE-2026-2007
05.06.2026
CVE
OS & platform High

PostgreSQL databases have a vulnerability in multibyte character processing that allows database users to execute arbitrary code on the server through specially crafted queries.

affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2

CVE-2026-2006
05.06.2026
CVE
OS & platform High

A memory corruption flaw in PostgreSQL's encryption module allows attackers to execute arbitrary code on the database server. Older versions before the mentioned security updates are affected.

affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2

CVE-2026-2005
05.06.2026
CVE
OS & platform High

A vulnerability in PostgreSQL's intarray extension allows attackers to execute arbitrary code with database user privileges by exploiting unchecked inputs in a selectivity estimator function.

affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2

CVE-2026-2004
05.06.2026
CVE
OS & platform Medium

A vulnerability in PostgreSQL allows database users to read small amounts of server memory, potentially exposing confidential information stored in that memory.

affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2

CVE-2026-2003
05.06.2026
CVE
OS & platform High

A vulnerability in PostgreSQL Anonymizer allows users to gain superuser privileges by creating a temporary view with malicious code, enabling them to execute arbitrary code with the highest privileges.

CVE-2026-2361
05.06.2026
CVE
OS & platform High

A vulnerability in the PostgreSQL Anonymizer extension allows regular users to gain superuser privileges by creating malicious operators, which is particularly problematic in PostgreSQL 14 and older versions.

CVE-2026-2360
05.06.2026
EOL
OS & platform

EOL 2030-11-14

18
25.09.2025
EOL
OS & platform

EOL 2029-11-08

17
26.09.2024
EOL
OS & platform

EOL 2028-11-09

16
14.09.2023
EOL
OS & platform

EOL 2027-11-11

15
13.10.2022
EOL
OS & platform

EOL 2026-11-12

14
30.09.2021
EOL
OS & platform

EOL 2025-11-13

13
24.09.2020
EOL
OS & platform

EOL 2024-11-21

12
03.10.2019
EOL
OS & platform

EOL 2023-11-09

11
18.10.2018
EOL
OS & platform

EOL 2022-11-10

10
05.10.2017
EOL
OS & platform

EOL 2021-11-11

9.6
29.09.2016
EOL
OS & platform

EOL 2021-02-11

9.5
07.01.2016
EOL
OS & platform

EOL 2020-02-13

9.4
18.12.2014
EOL
OS & platform

EOL 2018-11-08

9.3
09.09.2013
EOL
OS & platform

EOL 2017-11-09

9.2
10.09.2012
EOL
OS & platform

EOL 2016-10-27

9.1
12.09.2011
EOL
OS & platform

EOL 2015-10-08

9.0
20.09.2010
EOL
OS & platform

EOL 2014-07-24

8.4
01.07.2009
EOL
OS & platform

EOL 2013-02-07

8.3
04.02.2008
EOL
OS & platform

EOL 2011-12-05

8.2
05.12.2006
EOL
OS & platform

EOL 2010-11-08

8.1
08.11.2005
EOL
OS & platform

EOL 2010-10-01

8.0
19.01.2005
EOL
OS & platform

EOL 2010-10-01

7.4
17.11.2003
EOL
OS & platform

EOL 2007-11-27

7.3
27.11.2002
EOL
OS & platform

EOL 2007-02-04

7.2
04.02.2002
EOL
OS & platform

EOL 2006-04-13

7.1
13.04.2001
EOL
OS & platform

EOL 2005-05-08

7.0
08.05.2000
EOL
OS & platform

EOL 2004-06-09

6.5
09.06.1999
EOL
OS & platform

EOL 2003-10-30

6.4
30.10.1998
EOL
OS & platform

EOL 2003-03-01

6.3
01.03.1998