Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 154 CRITICAL 7 HIGH 63 MEDIUM 77 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • オープンソース
  • PostgreSQL Licence
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
31 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 2 2 0
32 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 6 4 1
33 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 8 5 1
34 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 12 10 1
35 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 15 11 1
36 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 19 12 1
37 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 21 9 0
38 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 39 37 0
39 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 31 48 3
40 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 31 38 4
41 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 21 20 2
42 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 21 22 1
43 PostgreSQL - - 4 17 14 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
31 6.5
3.5
MEDIUM
Network
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to … CWE-862
 Missing Authorization
CVE-2020-1720 cpe:2.3:a:postgresql:postgresql:*:* 12.0
11.0
10.0
9.6






12.2
11.7
10.12
9.6.17
2024-11-21 14:11
2020-03-18
Show GitHub Exploit DB Packet Storm
32 9.8
7.5
CRITICAL
Network
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote at… CWE-89
SQL Injection
CVE-2015-0244 cpe:2.3:a:postgresql:postgresql:*:*
9.1.0
9.2.0
9.3.0
9.4.0








9.0.19
9.1.15
9.2.10
9.3.6
9.4.1
2024-11-21 11:22
2020-01-28
Show GitHub Exploit DB Packet Storm
33 8.8
6.5
HIGH
Network
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cau… CWE-120
Classic Buffer Overflow
CVE-2015-0243 cpe:2.3:a:postgresql:postgresql:*:*
9.1.0
9.2.0
9.3.0
9.4.0








9.0.19
9.1.15
9.2.10
9.3.6
9.4.1
2024-11-21 11:22
2020-01-28
Show GitHub Exploit DB Packet Storm
34 8.8
6.5
HIGH
Network
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on … CWE-787
 Out-of-bounds Write
CVE-2015-0242 cpe:2.3:a:postgresql:postgresql:*:*
9.1.0
9.2.0
9.3.0
9.4.0








9.0.19
9.1.15
9.2.10
9.3.6
9.4.1
2024-11-21 11:22
2020-01-28
Show GitHub Exploit DB Packet Storm
35 8.8
6.5
HIGH
Network
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (… CWE-120
Classic Buffer Overflow
CVE-2015-0241 cpe:2.3:a:postgresql:postgresql:*:*
9.1.0
9.2.0
9.3.0
9.4.0








9.0.19
9.1.15
9.2.10
9.3.6
9.4.1
2024-11-21 11:22
2020-01-28
Show GitHub Exploit DB Packet Storm
36 4.3
4.0
MEDIUM
Network
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constr… CWE-209
Information Exposure Through an Error Message
CVE-2014-8161 cpe:2.3:a:postgresql:postgresql:*:*
9.1.0
9.2.0
9.3.0
9.4.0








9.0.19
9.1.15
9.2.10
9.3.6
9.4.1
2024-11-21 11:18
2020-01-28
Show GitHub Exploit DB Packet Storm
37 7.5
5.0
HIGH
Network
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which … CWE-200
Information Exposure
CVE-2015-3167 cpe:2.3:a:postgresql:postgresql:*:* 9.4
9.3
9.2
9.1








9.4.2
9.3.7
9.2.11
9.1.16
9.0.20
2024-11-21 11:28
2019-11-21
Show GitHub Exploit DB Packet Storm
38 9.8
7.5
CRITICAL
Network
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2015-3166 cpe:2.3:a:postgresql:postgresql:*:* 9.4
9.3
9.2
9.1








9.4.2
9.3.7
9.2.11
9.1.16
9.0.20
2024-11-21 11:28
2019-11-21
Show GitHub Exploit DB Packet Storm
39 9.8
7.5
CRITICAL
Network
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. NVD-CWE-noinfo
CVE-2019-10211 cpe:2.3:a:postgresql:postgresql:*:*
9.5.0
9.6.0
10.0
11.0








9.4.24
9.5.19
9.6.15
10.10
11.5
2024-11-21 13:18
2019-10-30
Show GitHub Exploit DB Packet Storm
40 7.0
1.9
HIGH
Local
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file. CWE-522
 Insufficiently Protected Credentials
CVE-2019-10210 cpe:2.3:a:postgresql:postgresql:*:*
9.5.0
9.6.0
10.0
11.0








9.4.24
9.5.19
9.6.15
10.10
11.5
2024-11-21 13:18
2019-10-30
Show GitHub Exploit DB Packet Storm