Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pgadmin HIGH 7.5
CVE-2023-1907

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's s…

Fix: 7.0+
Fix from $1,950 2025-01-09
Pgagent HIGH 7.1
CVE-2025-0218

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an in…

Fix: 4.2.3+
Fix from $1,950 2025-01-07
Pgadmin 4 MEDIUM 6.5
CVE-2024-9014EPSS 10%

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially ob…

Fix: 8.12+
Fix from $1,600 2024-09-23
Pgadmin 4 MEDIUM 5.3
CVE-2024-6238

pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation dire…

Fix: 8.9+
Fix from $1,600 2024-06-25
Pgadmin 4 HIGH 8.8
CVE-2024-4215

pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimat…

Fix: 8.6+
Fix from $1,950 2024-05-02
Pgadmin 4 MEDIUM 5.4
CVE-2024-4216

pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute maliciou…

Fix: 8.6+
Fix from $1,600 2024-05-02
Pgadmin 4 CRITICAL 9.8
CVE-2024-3116EPSS 65%

pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers …

Fix: after 8.4
Fix from $2,300 2024-04-04
Pgadmin 4 CRITICAL 9.9
CVE-2024-2044EPSS 79%

pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is runni…

Fix: 8.4+
Fix from $2,300 2024-03-07
Pgadmin 4 HIGH 8.8
CVE-2023-5002

A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities su…

Fix: 7.7+
Fix from $1,950 2023-09-22
Pgadmin 4 MEDIUM 6.5
CVE-2023-0241EPSS 9%

pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the…

Fix: 6.19+
Fix from $1,600 2023-03-27
Pgadmin 4 MEDIUM 6.1
CVE-2023-22298

Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site…

Fix: 6.14+
Fix from $1,600 2023-01-17
Pgadmin 4 HIGH 8.8
CVE-2022-4223EPSS 80%

The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_d…

Fix: 6.17+
Fix from $1,950 2022-12-13
Pgadmin 4 MEDIUM 6.5
CVE-2022-0959

A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually uploa…

Fix: 6.7+
Fix from $1,600 2022-03-16