CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Pgadmin Remove filter Clear all
CVE-2026-17566 CRITICAL

pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)

CVSS 9.4 EPSS 0.67% Jul 31, 2026
CVE-2026-17351 CRITICAL

pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)

CVSS 9.4 EPSS 0.48% Jul 31, 2026
CVE-2026-17350 MEDIUM

pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers

CVSS 5.3 EPSS 0.38% Jul 31, 2026
CVE-2026-17349 CRITICAL

pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner

CVSS 9.3 EPSS 0.40% Jul 31, 2026
CVE-2026-17348 MEDIUM

pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomple…

CVSS 6.9 EPSS 0.42% Jul 31, 2026
CVE-2026-17347 HIGH

pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution

CVSS 7.7 EPSS 0.72% Jul 31, 2026
CVE-2026-17346 HIGH

pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)

CVSS 8.7 EPSS 0.61% Jul 31, 2026
CVE-2026-12049 MEDIUM

pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter

CVSS 5.3 EPSS 0.38% Jun 18, 2026
CVE-2026-12048 CRITICAL

pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser

CVSS 9.3 EPSS 0.27% Jun 18, 2026
CVE-2026-12047 MEDIUM

pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text

CVSS 4.8 EPSS 0.22% Jun 18, 2026
CVE-2026-12046 CRITICAL

pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution

CVSS 9.5 EPSS 1.04% Jun 18, 2026
CVE-2026-12045 CRITICAL

pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution

CVSS 9.4 EPSS 0.66% Jun 18, 2026
CVE-2026-12050 MEDIUM

pgAdmin 4: SQL injection in named restore point endpoint

CVSS 5.3 EPSS 0.43% Jun 18, 2026
CVE-2026-12044 HIGH

pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates

CVSS 8.7 EPSS 0.71% Jun 18, 2026
CVE-2026-7820 MEDIUM

pgAdmin 4: Account-lockout bypass via Flask-Security default /login view

CVSS 6.9 EPSS 0.33% May 11, 2026
CVE-2026-7819 HIGH

pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write

CVSS 7.2 EPSS 0.48% May 11, 2026
CVE-2026-7818 HIGH

pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution

CVSS 7.3 EPSS 0.35% May 11, 2026
CVE-2026-7817 HIGH

pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints

CVSS 7.1 EPSS 0.35% May 11, 2026
CVE-2026-7816 HIGH

pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout

CVSS 8.7 EPSS 2.18% May 11, 2026
CVE-2026-7815 HIGH

pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution

CVSS 8.7 EPSS 0.64% May 11, 2026
CVE-2026-7814 MEDIUM

pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer

CVSS 4.8 EPSS 0.25% May 11, 2026
CVE-2026-7813 CRITICAL

pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode

CVSS 9.4 EPSS 0.65% May 11, 2026
CVE-2026-1707 HIGH

Restore restriction bypass via key disclosure vulnerability (pgAdmin 4)

CVSS 7.4 EPSS 0.45% Feb 5, 2026
CVE-2025-13780 CRITICAL

Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

CVSS 9.1 EPSS 0.94% Dec 11, 2025
CVE-2025-12765 HIGH

pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.

CVSS 7.5 EPSS 0.22% Nov 13, 2025

Showing 1 to 25 CVEs · page 1 (more available)