Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A missing authorization vulnerability in PostgreSQL logical decoding allows a non-superuser with REPLICATION privilege to load arbitrary files via the logical decoding plugin mechanism. This can lead to execution of arbitrary code with the operating system privileges of the PostgreSQL server process. Versions prior to PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.6 are affected. A patch is available to address this issue. Join the discussion | GCVE Database | 08/19/2026, 08:53:05 UTC Added: 08/13/2026, 17:48:21 UTC |
A missing authorization check in PostgreSQL allows an object creator to cause denial of service on ALTER and DROP operations of a type by creating dependencies on that type. This occurs because certain DDL commands, such as assigning a range subtype and referencing the type from an SQL expression, do not properly verify USAGE privileges. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. A patch is available to address this issue. Join the discussion | GCVE Database | 08/19/2026, 08:53:04 UTC Added: 08/13/2026, 17:48:22 UTC |
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. Join the discussion | CVE Database V5 | 08/19/2026, 08:53:03 UTC Added: 08/13/2026, 13:26:49 UTC |
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. Join the discussion | CVE Database V5 | 08/19/2026, 08:53:02 UTC Added: 08/13/2026, 13:26:49 UTC |
A heap buffer overflow vulnerability exists in PostgreSQL's pg_dump utility when processing long function transform lists. This flaw allows an object creator to execute arbitrary code with the privileges of the operating system user running pg_dump. The issue affects multiple PostgreSQL versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24. A patch is available to address this vulnerability. Join the discussion | GCVE Database | 08/19/2026, 08:52:55 UTC Added: 08/13/2026, 17:48:22 UTC |
0 Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. Join the discussion | CVE Database V5 | 08/19/2026, 08:52:54 UTC Added: 08/13/2026, 13:26:49 UTC |
A buffer over-read vulnerability exists in the PostgreSQL ascii() SQL function that allows disclosure of up to 3 bytes beyond the allocated buffer when processing a crafted text value. This vulnerability affects multiple PostgreSQL versions prior to 14.24, 15.19, 16.15, 17.11, and 18.6. The issue is similar to a previously fixed defect (CVE-2026-2006) but with less impact. A patch is available to address this vulnerability. Join the discussion | GCVE Database | 08/19/2026, 08:52:52 UTC Added: 08/13/2026, 17:48:22 UTC |
An integer underflow vulnerability exists in PostgreSQL ECPG client that can cause the client to crash when processing a bytea value missing its mandatory prefix. This flaw allows a database server administrator to trigger a temporary denial of service against the ECPG client. The client may overwrite a large memory region with uncontrolled bytes, typically resulting in a segmentation fault (SIGSEGV). In rare cases, this could lead to client-specific integrity impacts. Versions before PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.6 are affected. Join the discussion | GCVE Database | 08/19/2026, 08:52:51 UTC Added: 08/13/2026, 17:48:22 UTC |
0 Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. Join the discussion | GCVE Database | 08/19/2026, 08:52:50 UTC Added: 08/13/2026, 17:48:22 UTC |
0 A type confusion vulnerability in PostgreSQL's pg_restore_attribute_stats() function allows an object creator to execute arbitrary code as the operating system user running the database. This occurs due to conflation of range and multirange values. The issue affects PostgreSQL major version 18, specifically versions before 18.6. Versions prior to 18.0 are not affected. A patch is available to address this vulnerability. Join the discussion | GCVE Database | 08/19/2026, 08:52:49 UTC Added: 08/13/2026, 17:48:22 UTC |
Showing 1 to 10 of 65 results