CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-59335 - Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Iden
CVE-2026-53572 - KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgres
CVE-2026-55769 - CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.
CVE-2026-55765 - CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.
CVE-2026-76635 - baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows au
CVE-2026-76212 - phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declare
CVE-2026-64657 - Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector
CVE-2026-74891 - openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server co
CVE-2026-48528 - Metacat is data repository software that helps researchers preserve, share, and discover data. Metac
CVE-2026-6471 - Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION priv
CVE-2026-6470 - Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of servi
CVE-2026-6469 - Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of d
CVE-2026-6464 - Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit executio
CVE-2026-19385 - Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator
CVE-2026-18408 - Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server
CVE-2026-18024 - Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after th
CVE-2026-16241 - Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary den
CVE-2026-16239 - Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as th
CVE-2026-16238 - Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitr
CVE-2026-15742 - Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of add
CVE-2026-15741 - SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a s
CVE-2026-14681 - Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GS
CVE-2026-14680 - Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary c
CVE-2026-14679 - Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unkno
CVE-2026-14678 - Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. Th
CVE-2026-14677 - Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause
CVE-2026-14676 - Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary c
CVE-2026-14673 - Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege t
CVE-2026-14672 - Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to
CVE-2026-14671 - Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as t
CVE-2026-14670 - Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute
CVE-2026-14669 - Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to ex
CVE-2026-14668 - Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object c
CVE-2026-14666 - Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database owner
CVE-2026-14664 - Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the o
CVE-2026-14663 - Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via di
CVE-2026-14662 - Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged dat
CVE-2026-73069 - Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty al
CVE-2026-72775 - n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigge
CVE-2026-72881 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and
CVE-2026-72869 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreB
CVE-2026-70635 - TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability th
CVE-2026-48080 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-10716 - Directus contains an authenticated SQL injection vulnerability in the collection creation flow when
CVE-2026-71276 - Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (reade
CVE-2026-48031 - go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In v
CVE-2026-45376 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0
CVE-2026-17566 - pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-s
CVE-2026-17351 - The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assist
CVE-2026-17346 - The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pg
CVE-2026-16503 - Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is publishe
CVE-2026-62845 - Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and
CVE-2026-54368 - CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchE
CVE-2026-51992 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHou
CVE-2026-50738 - A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can
CVE-2026-50737 - When applying replicated changes for a row that is missing one or more columns, pglogical evaluates
CVE-2026-50736 - The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a pub
CVE-2026-50735 - pglogical's apply worker does not sufficiently validate the length of certain fields in incoming rep
CVE-2026-55084 - DHIS2 is a flexible information system for data capture, management, validation, analytics and visua
CVE-2026-32806 - dataCycle is a data management system for centrally storing, managing, searching, finding, and distr
CVE-2026-9586 - An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997).
CVE-2026-62238 - OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint cross
CVE-2026-53536 - Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/
CVE-2026-62361 - listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk
CVE-2026-55410 - NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris
CVE-2026-52888 - NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris
CVE-2026-52887 - NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris
CVE-2026-45417 - DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasour
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware