<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:41:58.810485+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-01295</id>
    <title>bdu:2019-01295</title>
    <updated>2026-10-03T22:41:58.832479+00:00</updated>
    <content>bdu:2019-01295</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-01295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-10925</id>
    <title>Withdrawn: BELL-CVE-2018-10925 — CVE-2018-10925 does not affect BellSoft software</title>
    <updated>2026-10-03T22:41:58.832522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-10925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-in55684</id>
    <title>CLEANSTART-2026-IN55684 — Security fix for CVE-2018-10925 applied in: postgresql15 10.5-r0</title>
    <updated>2026-10-03T22:41:58.832542+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: postgresql15</p>
<p>Security vulnerability affects the postgresql15 package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-in55684"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-02195</id>
    <title>cnvd-2020-02195</title>
    <updated>2026-10-03T22:41:58.832571+00:00</updated>
    <content>cnvd-2020-02195</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-02195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-64936</id>
    <title>EUVD-2026-64936</title>
    <updated>2026-10-03T22:41:58.832584+00:00</updated>
    <content>EUVD-2026-64936</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-64936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-10925</id>
    <title>fkie_cve-2018-10925</title>
    <updated>2026-10-03T22:41:58.832594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-10925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mr45-mwhc-fw72</id>
    <title>GHSA-mr45-mwhc-fw72</title>
    <updated>2026-10-03T22:41:58.832618+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mr45-mwhc-fw72"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-10925</id>
    <title>gsd-2018-10925</title>
    <updated>2026-10-03T22:41:58.832635+00:00</updated>
    <content>gsd-2018-10925</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-10925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1227-1</id>
    <title>openSUSE-SU-2020:1227-1 — Security update for postgresql96, postgresql10 and postgresql12</title>
    <updated>2026-10-03T22:41:58.832644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql96, postgresql10 and postgresql12</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1227-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2511</id>
    <title>RHSA-2018:2511 — Red Hat Security Advisory: rh-postgresql95-postgresql security update</title>
    <updated>2026-10-03T22:41:58.832665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql: Memory disclosure in JSON functions postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask postgresql: Uncontrolled search path element in pg_dump and other client applications postgresql: Certain host connection parameters defeat client-side security defenses postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:2564-1</id>
    <title>SUSE-SU-2018:2564-1 — Security update for postgresql10</title>
    <updated>2026-10-03T22:41:58.832690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql10</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:2564-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-10925</id>
    <title>UBUNTU-CVE-2018-10925</title>
    <updated>2026-10-03T22:41:58.832704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: postgresql-9.5, Ubuntu:18.04:LTS: postgresql-10</p>
<p>It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-10925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3749</id>
    <title>WID-SEC-W-2024-3749 — PostgreSQL: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:41:58.832726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3749"/>
  </entry>
</feed>
