Oracle MySQL vulnerabilities

1,328 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,328
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH71MEDIUM1064LOW181

Vulnerabilities

Page 10 of 67
CVE-2022-21451MEDIUMCVSS 4.4≥ 5.7.0, ≤ 5.7.37≥ 8.0.0, ≤ 8.0.282022-04-19
CVE-2022-21451 [MEDIUM] CVE-2022-21451: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2022-21478MEDIUMCVSS 5.5≥ 8.0.0, ≤ 8.0.282022-04-19
CVE-2022-21478 [MEDIUM] CVE-2022-21478: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2022-21484LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.35≥ 7.5.0, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21484 [LOW] CVE-2022-21484: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2022-21486LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.35≥ 7.5.0, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21486 [LOW] CVE-2022-21486: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2022-21485LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.35≥ 7.5.0, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21485 [LOW] CVE-2022-21485: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2021-22570MEDIUMCVSS 5.5≤ 8.0.282022-01-26
CVE-2021-22570 [MEDIUM] CWE-476 CVE-2021-22570: Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
nvd
CVE-2022-21351HIGHCVSS 7.1≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21351 [HIGH] CVE-2022-21351: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2022-21278HIGHCVSS 7.1≥ 8.0.0, ≤ 8.0.262022-01-19
CVE-2022-21278 [HIGH] CVE-2022-21278: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2022-21270MEDIUMCVSS 4.9≥ 5.7.0, ≤ 5.7.36≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21270 [MEDIUM] CVE-2022-21270: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2022-21320MEDIUMCVSS 6.3≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21320 [MEDIUM] CVE-2022-21320: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Success
nvd
CVE-2022-21339MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21339 [MEDIUM] CVE-2022-21339: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2022-21335MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21335 [MEDIUM] CVE-2022-21335: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2022-21297MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.262022-01-19
CVE-2022-21297 [MEDIUM] CVE-2022-21297: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2022-21329MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21329 [MEDIUM] CVE-2022-21329: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2022-21310MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21310 [MEDIUM] CWE-129 CVE-2022-21310: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2022-21314MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21314 [MEDIUM] CVE-2022-21314: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2022-21279MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21279 [MEDIUM] CVE-2022-21279: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2022-21356MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21356 [MEDIUM] CVE-2022-21356: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2022-21330MEDIUMCVSS 6.3≥ 7.5.0, ≤ 7.5.24≥ 7.6.0, ≤ 7.6.20+1 more2022-01-19
CVE-2022-21330 [MEDIUM] CVE-2022-21330: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster execut
nvd
CVE-2022-21316MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21316 [MEDIUM] CVE-2022-21316: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Clust
nvd