Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 165 CRITICAL 7 HIGH 70 MEDIUM 81 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • 商用ライセンス有り
  • オープンソース
  • PostgreSQL Licence

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
21 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 8 5 0
22 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 11 7 1
23 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 13 8 1
24 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 17 13 1
25 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 20 14 1
26 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 24 15 1
27 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 26 12 0
28 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 44 40 0
29 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 36 51 3
30 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 36 41 4
31 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 26 23 2
32 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 26 25 1
33 PostgreSQL - - 4 22 17 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
21 5.4
-
MEDIUM
Network
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is pl… NVD-CWE-noinfo
CVE-2023-2455 cpe:2.3:a:postgresql:postgresql:*:* 15.0
14.0
13.0
12.0
11.0








15.3
14.8
13.11
12.15
11.20
2024-11-21 16:58
2023-06-10
Show GitHub Exploit DB Packet Storm
22 3.7
-
LOW
Network
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to… NVD-CWE-noinfo
CVE-2022-41862 cpe:2.3:a:postgresql:postgresql:*:* 15.0
14.0
13.0
12.0






15.2
14.7
13.10
12.14
2025-03-8 01:15
2023-03-4
Show GitHub Exploit DB Packet Storm
23 8.8
-
HIGH
Network
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRES… - CVE-2022-1552 cpe:2.3:a:postgresql:postgresql:*:* 14.0
13.0
12.0
11.0
10.0








14.3
13.7
12.11
11.16
10.21
2024-11-21 15:40
2022-09-1
Show GitHub Exploit DB Packet Storm
24 5.9
-
MEDIUM
Network
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to us… CWE-295
Improper Certificate Validation 
CVE-2021-43767 cpe:2.3:a:postgresql:postgresql:14.0:*
cpe:2.3:a:postgresql:postgresql:*:*
10.0
11.0
12.0
13.0
9.6.0








10.19
11.14
12.9
13.5
9.6.24
2024-11-21 15:29
2022-08-26
Show GitHub Exploit DB Packet Storm
25 8.0
-
HIGH
Network
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update a… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2022-2625 cpe:2.3:a:postgresql:postgresql:15:beta2
cpe:2.3:a:postgresql:postgresql:15:beta1
cpe:2.3:a:postgresql:postgresql…
10.0
11.0
12.0
13.0
14.0








10.22
11.17
12.12
13.8
14.5
2024-11-21 16:01
2022-08-19
Show GitHub Exploit DB Packet Storm
26 8.1
5.1
HIGH
Network
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection … - CVE-2021-23214 cpe:2.3:a:postgresql:postgresql:14.0:*
cpe:2.3:a:postgresql:postgresql:*:*
10.0
11.0
12.0
13.0








10.19
11.14
12.9
13.5
9.6.24
2024-11-21 14:51
2022-03-5
Show GitHub Exploit DB Packet Storm
27 5.9
4.3
MEDIUM
Network
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. - CVE-2021-23222 cpe:2.3:a:postgresql:postgresql:14.0:*
cpe:2.3:a:postgresql:postgresql:*:*
9.6
10.0
11.0
12.0
13.0








9.6.24
10.19
11.14
12.9
13.5
2024-11-21 14:51
2022-03-3
Show GitHub Exploit DB Packet Storm
28 6.5
4.0
MEDIUM
Network
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The … - CVE-2021-3677 cpe:2.3:a:postgresql:postgresql:*:* 13.0
12.0
11.0




13.4
12.8
11.13
2024-11-21 15:22
2022-03-3
Show GitHub Exploit DB Packet Storm
29 6.5
4.0
MEDIUM
Network
A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highe… NVD-CWE-noinfo
CVE-2021-32028 cpe:2.3:a:postgresql:postgresql:*:* 13.0
12.0
10.0
11.0
9.6.0








13.3
12.7
10.17
11.12
9.6.22
2024-11-21 15:06
2021-10-12
Show GitHub Exploit DB Packet Storm
30 6.5
4.0
MEDIUM
Network
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from t… CWE-125
Out-of-bounds Read
CVE-2021-32029 cpe:2.3:a:postgresql:postgresql:*:* 13.0
12.0
11.0




13.3
12.7
11.12
2024-11-21 15:06
2021-10-9
Show GitHub Exploit DB Packet Storm