CVE Tools

Postgres Pro Certified

61 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Postgres Pro Certified, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

Postgres Pro Certified CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Postgres Pro Certified CVEs per month
MonthCVEs
2024-100
2024-114
2024-120
2025-010
2025-021
2025-030
2025-040
2025-051
2025-060
2025-070
2025-083
2025-090
2025-100
2025-112
2025-120
2026-010
2026-025
2026-030
2026-040
2026-0511
2026-060
2026-070
2026-080
2026-090

Severity

How the 61 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical12%
  • High3252%
  • Medium1830%
  • Low1016%

Latest CVEs

The 15 most recently published vulnerabilities affecting Postgres Pro Certified.

  1. CVE-2026-6638PostgreSQL REFRESH PUBLICATION allows SQL injection via table name3.7
  2. CVE-2026-6637PostgreSQL refint allows stack buffer overflow and SQL injection8.8
  3. CVE-2026-6575PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array4.3
  4. CVE-2026-6478PostgreSQL discloses MD5-hashed passwords via covert timing channel6.5
  5. CVE-2026-6479PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion7.5
  6. CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory8.8
  7. CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice8.8
  8. CVE-2026-6476PostgreSQL pg_createsubscriber allows SQL injection via subscription name7.2
  9. CVE-2026-6474PostgreSQL timeofday() can disclose portions of server memory4.3
  10. CVE-2026-6473PostgreSQL server undersizes allocations, via integer wraparound8.8
  11. CVE-2026-6472PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege5.4
  12. CVE-2026-2007PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory8.2
  13. CVE-2026-2006PostgreSQL missing validation of multibyte character length executes arbitrary code8.8
  14. CVE-2026-2005PostgreSQL pgcrypto heap buffer overflow executes arbitrary code8.8
  15. CVE-2026-2004PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store