Browse vulnerabilities
116 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-20253 | Act now | 96.9% | 9.8 | ● | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthent… |
| CVE-2026-9586 | Act now | 19.0% | 9.8 | ● | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3… |
| CVE-2026-46624 | High | 0.7% | 9.9 | Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution … | |
| CVE-2026-34612 | High | 0.7% | 9.9 | Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kes… | |
| CVE-2026-48773 | High | 0.7% | 9.8 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 throug… | |
| CVE-2026-48772 | High | 0.2% | 10.0 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 thro… | |
| CVE-2026-42198 | Medium | 4.1% | 7.5 | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.… | |
| CVE-2026-87911 | Medium | 1.7% | 9.6 | An OS command injection weakness in the read-only enforcement of the SQL validation compon… | |
| CVE-2026-6473 | Medium | 1.5% | 8.8 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database … | |
| CVE-2026-32286 | Medium | 0.9% | 7.5 | The DataRow.Decode function fails to properly validate field lengths. A malicious or compr… | |
| CVE-2026-33324 | Medium | 0.8% | 8.8 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In ver… | |
| CVE-2026-61781 | Medium | 0.8% | 9.9 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-85878 | Medium | 0.8% | 9.9 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to e… | |
| CVE-2026-61817 | Medium | 0.7% | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-61819 | Medium | 0.7% | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-61820 | Medium | 0.7% | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-82526 | Medium | 0.7% | 9.8 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticat… | |
| CVE-2026-54368 | Medium | 0.7% | 8.8 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() a… | |
| CVE-2026-6477 | Medium | 0.7% | 8.8 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq l… | |
| CVE-2026-25879 | Medium | 0.7% | 9.8 | Langroid is a framework for building large-language-model-powered applications. Prior to v… | |
| CVE-2026-54354 | Medium | 0.7% | 8.2 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer… | |
| CVE-2026-16239 | Medium | 0.7% | 8.8 | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary … | |
| CVE-2026-17566 | Medium | 0.7% | 9.9 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolatin… | |
| CVE-2026-14669 | Medium | 0.7% | 8.8 | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the time… | |
| CVE-2026-73069 | Medium | 0.7% | 9.1 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0,… | |
| CVE-2026-72869 | Medium | 0.7% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backu… | |
| CVE-2026-48031 | Medium | 0.6% | 9.1 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by Postgr… | |
| CVE-2026-17346 | Medium | 0.6% | 8.8 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMME… | |
| CVE-2026-87016 | Medium | 0.6% | 8.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From… | |
| CVE-2026-82028 | Medium | 0.6% | 8.8 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and… | |
| CVE-2024-42450 | Medium | 0.6% | 10.0 | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data.… | |
| CVE-2026-15742 | Medium | 0.6% | 8.8 | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge ra… | |
| CVE-2026-45288 | Medium | 0.5% | 9.8 | Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1,… | |
| CVE-2026-59335 | Medium | 0.5% | 8.7 | Improper handling of case sensitivity (CWE-178) in the identity zone authorization check i… | |
| CVE-2026-6471 | Medium | 0.5% | 7.2 | Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLIC… | |
| CVE-2026-49948 | Medium | 0.5% | 8.1 | Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vuln… | |
| CVE-2026-72708 | Medium | 0.5% | 7.5 | SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQ… | |
| CVE-2026-74891 | Medium | 0.5% | 9.8 | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone… | |
| CVE-2026-61818 | Medium | 0.5% | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-76635 | Medium | 0.5% | 7.2 | baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that… | |
| CVE-2026-55765 | Medium | 0.5% | 8.5 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes envi… | |
| CVE-2026-62238 | Medium | 0.5% | 8.8 | OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datap… | |
| CVE-2026-17351 | Medium | 0.5% | 9.0 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the… | |
| CVE-2026-85388 | Medium | 0.5% | 8.1 | Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagina… | |
| CVE-2026-48528 | Medium | 0.5% | 9.8 | Metacat is data repository software that helps researchers preserve, share, and discover d… | |
| CVE-2026-72775 | Medium | 0.5% | 8.8 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Post… | |
| CVE-2026-48080 | Medium | 0.5% | 8.0 | OpenReception's appointment booking software provides an end-to-end encrypted appointment … | |
| CVE-2026-75513 | Medium | 0.5% | 9.1 | Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0… | |
| CVE-2026-15741 | Medium | 0.5% | 8.8 | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary … | |
| CVE-2026-14662 | Medium | 0.5% | 8.8 | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unpriv… |
Page 1 of 3
Next →