📦

postgresql

Vendor: postgresql

Actively Exploited 0 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 20 Remote Access
Total CVEs 1897 Total Indexed
Avg. EPSS 4.24% Exploit Prob.
Latest CVE CVE-2026-6638 May 14

Security Vulnerability Index

Page 18 / 190
4.6 CVSS

Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.

EPSS: 0.48%
6.5 CVSS

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.

EPSS: 2.19%
7.5 CVSS

Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.

EPSS: 3.94%
10.0 CVSS

Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2).

EPSS: 1.79%
4.6 CVSS

Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input."

EPSS: 0.54%
7.5 CVSS

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.

EPSS: 2.75%
7.5 CVSS

PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

EPSS: 1.27%
7.2 CVSS

PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.

EPSS: 0.44%
4.6 CVSS

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

EPSS: 0.49%
7.5 CVSS

The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.

EPSS: 1.09%