Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 154 CRITICAL 7 HIGH 63 MEDIUM 77 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • オープンソース
  • PostgreSQL Licence
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
11 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 2 2 0
12 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 6 4 1
13 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 8 5 1
14 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 12 10 1
15 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 15 11 1
16 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 19 12 1
17 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 21 9 0
18 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 39 37 0
19 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 31 48 3
20 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 31 38 4
21 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 21 20 2
22 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 21 22 1
23 PostgreSQL - - 4 17 14 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
11 3.7
-
LOW
Network
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to… NVD-CWE-noinfo
CVE-2022-41862 cpe:2.3:a:postgresql:postgresql:*:* 15.0
14.0
13.0
12.0






15.2
14.7
13.10
12.14
2025-03-8 01:15
2023-03-4
Show GitHub Exploit DB Packet Storm
12 8.8
-
HIGH
Network
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRES… - CVE-2022-1552 cpe:2.3:a:postgresql:postgresql:*:* 14.0
13.0
12.0
11.0
10.0








14.3
13.7
12.11
11.16
10.21
2024-11-21 15:40
2022-09-1
Show GitHub Exploit DB Packet Storm
13 5.9
-
MEDIUM
Network
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to us… CWE-295
Improper Certificate Validation 
CVE-2021-43767 cpe:2.3:a:postgresql:postgresql:14.0:*
cpe:2.3:a:postgresql:postgresql:*:*
10.0
11.0
12.0
13.0
9.6.0








10.19
11.14
12.9
13.5
9.6.24
2024-11-21 15:29
2022-08-26
Show GitHub Exploit DB Packet Storm
14 8.0
-
HIGH
Network
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update a… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2022-2625 cpe:2.3:a:postgresql:postgresql:15:beta2
cpe:2.3:a:postgresql:postgresql:15:beta1
cpe:2.3:a:postgresql:postgresql…
10.0
11.0
12.0
13.0
14.0








10.22
11.17
12.12
13.8
14.5
2024-11-21 16:01
2022-08-19
Show GitHub Exploit DB Packet Storm
15 8.1
5.1
HIGH
Network
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection … - CVE-2021-23214 cpe:2.3:a:postgresql:postgresql:14.0:*
cpe:2.3:a:postgresql:postgresql:*:*
10.0
11.0
12.0
13.0








10.19
11.14
12.9
13.5
9.6.24
2024-11-21 14:51
2022-03-5
Show GitHub Exploit DB Packet Storm
16 5.9
4.3
MEDIUM
Network
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. - CVE-2021-23222 cpe:2.3:a:postgresql:postgresql:14.0:*
cpe:2.3:a:postgresql:postgresql:*:*
9.6
10.0
11.0
12.0
13.0








9.6.24
10.19
11.14
12.9
13.5
2024-11-21 14:51
2022-03-3
Show GitHub Exploit DB Packet Storm
17 6.5
4.0
MEDIUM
Network
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The … - CVE-2021-3677 cpe:2.3:a:postgresql:postgresql:*:* 13.0
12.0
11.0




13.4
12.8
11.13
2024-11-21 15:22
2022-03-3
Show GitHub Exploit DB Packet Storm
18 6.5
4.0
MEDIUM
Network
A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highe… NVD-CWE-noinfo
CVE-2021-32028 cpe:2.3:a:postgresql:postgresql:*:* 13.0
12.0
10.0
11.0
9.6.0








13.3
12.7
10.17
11.12
9.6.22
2024-11-21 15:06
2021-10-12
Show GitHub Exploit DB Packet Storm
19 6.5
4.0
MEDIUM
Network
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from t… CWE-125
Out-of-bounds Read
CVE-2021-32029 cpe:2.3:a:postgresql:postgresql:*:* 13.0
12.0
11.0




13.3
12.7
11.12
2024-11-21 15:06
2021-10-9
Show GitHub Exploit DB Packet Storm
20 8.8
6.5
HIGH
Network
A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated da… - CVE-2021-32027 cpe:2.3:a:postgresql:postgresql:*:* 13.0
12.0
10.0
11.0
9.6.0








13.3
12.7
10.17
11.12
9.6.22
2024-11-21 15:06
2021-06-1
Show GitHub Exploit DB Packet Storm