Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 154 CRITICAL 7 HIGH 63 MEDIUM 77 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • オープンソース
  • PostgreSQL Licence
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
41 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 2 2 0
42 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 6 4 1
43 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 8 5 1
44 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 12 10 1
45 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 15 11 1
46 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 19 12 1
47 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 21 9 0
48 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 39 37 0
49 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 31 48 3
50 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 31 38 4
51 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 21 20 2
52 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 21 22 1
53 PostgreSQL - - 4 17 14 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
41 2.2
3.5
LOW
Network
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan. CWE-125
Out-of-bounds Read
CVE-2019-10209 cpe:2.3:a:postgresql:postgresql:*:* 11.0 11.5 2024-11-21 13:18
2019-10-30
Show GitHub Exploit DB Packet Storm
42 8.8
6.5
HIGH
Network
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given… CWE-89
SQL Injection
CVE-2019-10208 cpe:2.3:a:postgresql:postgresql:*:* 9.5.0
9.6.0
10.0
11.0
9.4.0








9.5.19
9.6.15
10.10
11.5
9.4.24
2024-11-21 13:18
2019-10-30
Show GitHub Exploit DB Packet Storm
43 4.3
4.0
MEDIUM
Network
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statis… CWE-284
Improper Access Control
CVE-2019-10130 cpe:2.3:a:postgresql:postgresql:*:* 11.0
9.5.0
9.6.0
10.0






11.3
9.5.17
9.6.13
10.8
2024-11-21 13:18
2019-07-31
Show GitHub Exploit DB Packet Storm
44 6.5
4.0
MEDIUM
Network
A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default confi… CWE-125
Out-of-bounds Read
CVE-2019-10129 cpe:2.3:a:postgresql:postgresql:*:* 11.0 11.3 2024-11-21 13:18
2019-07-31
Show GitHub Exploit DB Packet Storm
45 8.8
9.0
HIGH
Network
PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own… CWE-787
 Out-of-bounds Write
CVE-2019-10164 cpe:2.3:a:postgresql:postgresql:*:* 10.0
11.0


10.9
11.4
2024-11-21 13:18
2019-06-27
Show GitHub Exploit DB Packet Storm
46 7.2
9.0
HIGH
Network
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's ope… CWE-78
OS Command 
CVE-2019-9193 cpe:2.3:a:postgresql:postgresql:*:* 9.3 11.2 2024-11-21 13:51
2019-04-2
Show GitHub Exploit DB Packet Storm
47 9.8
7.5
CRITICAL
Network
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cau… CWE-89
SQL Injection
CVE-2018-16850 cpe:2.3:a:postgresql:postgresql:*:* 10.0
11.0


10.6
11.1
2024-11-21 12:53
2018-11-14
Show GitHub Exploit DB Packet Storm
48 8.1
9.3
HIGH
Network
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download softwar… CWE-284
Improper Access Control
CVE-2016-7048 cpe:2.3:a:postgresql:postgresql:*:* 9.4.0
9.5.0

9.2
9.3








9.4.10
9.5.5
9.1.24
9.2.19
9.3.15
2024-11-21 11:57
2018-08-21
Show GitHub Exploit DB Packet Storm
49 8.1
5.5
HIGH
Network
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE… CWE-863
 Incorrect Authorization
CVE-2018-10925 cpe:2.3:a:postgresql:postgresql:*:* 9.5.0
9.6.0
10.0




9.5.14
9.6.10
10.5
2024-11-21 12:42
2018-08-10
Show GitHub Exploit DB Packet Storm
50 7.5
6.0
HIGH
Network
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "h… CWE-89
SQL Injection
CVE-2018-10915 cpe:2.3:a:postgresql:postgresql:*:* 9.4.0
9.3.0
9.5.0
9.6.0
10.0








9.4.19
9.3.24
9.5.14
9.6.10
10.5
2024-11-21 12:42
2018-08-10
Show GitHub Exploit DB Packet Storm