VYPR
Vendor

Enterprisedb

Products
6
CVEs
15
Across products
17
Status
Private

Products

6

Recent CVEs

15
  • CVE-2026-50736CriJul 28, 2026
    risk 0.59cvss epss 0.00

    The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default…

  • CVE-2023-41119HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the function _dbms_aq_move_to_exception_queue that may be used to elevate a user's…

  • CVE-2023-41118HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It may allow an authenticated user to bypass authorization requirements and access underlying…

  • CVE-2023-41117HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately…

  • CVE-2019-10128HigMar 19, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default…

  • CVE-2024-4545HigMay 14, 2024
    risk 0.50cvss 7.7epss 0.01

    All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not…

  • CVE-2023-31043HigApr 23, 2023
    risk 0.49cvss 7.5epss 0.00

    EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are…

  • CVE-2025-14038HigDec 15, 2025
    risk 0.46cvss 7.0epss 0.00

    EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malformed data to certain gRPC endpoints. This…

  • CVE-2026-0949MedJan 16, 2026
    risk 0.42cvss 6.5epss 0.00

    PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript when creating a new chart, which is then executed by any user accessing the chart. By default only…

  • CVE-2023-41120MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a…

  • CVE-2023-41115MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTL_ENCODE, an authenticated user can read any large object, regardless of that user's…

  • CVE-2023-41114MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the functions get_url_as_text and get_url_as_bytea that are publicly executable, thus…

  • CVE-2023-41116MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to refresh any materialized view, regardless of that user's…

  • CVE-2023-41113MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to to obtain information about whether certain files exist on disk,…

  • CVE-2007-4639Aug 31, 2007
    risk 0.03cvss epss 0.05

    EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT…