PoC Archive PoC Archive

tag

Postgresql

pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780 web Unverified
CVE-2025-13780webCRITICAL 9.1Unverified2026-07-06pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945) EPSS 54%
CVE-2025-2945 web Patched
CVE-2025-2945webCRITICAL 9.9Patched2026-07-06PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005
CVE-2026-2005 binary Unverified
CVE-2026-2005binaryCRITICALUnverified2026-07-05PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664
CVE-2026-6664 network Patched
CVE-2026-6664networkHIGHPatched2026-07-05Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212 web Patched
CVE-2026-25212webCRITICAL 9.9Patched2026-07-05Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980 web Patched
CVE-2026-23980webMEDIUM 6.5Patched2026-07-05PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE
None assigned as of 2026-07-04 network Unverified
None assigned as of 2026-07-04networkHIGHUnverified2026-07-04Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253) KEV EPSS 97%
CVE-2026-20253 web Patched
CVE-2026-20253webCRITICALPatched2026-06-28Drupal Core PostgreSQL SQL Injection (CVE-2026-9082) KEV EPSS 88%
CVE-2026-9082 / SA-CORE-2026-004 web Patched
CVE-2026-9082 / SA-CORE-2026-004webCRITICALPatched2026-05-30