Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 15 of 67
CVE-2020-2573P4MEDIUMCVSS 5.9≥ 5.7.0, ≤ 5.7.28≥ 8.0.0, ≤ 8.0.182020-01-15
CVE-2020-2573 [MEDIUM] CVE-2020-2573: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2020-2570P4MEDIUMCVSS 5.9≥ 5.7.0, ≤ 5.7.28≥ 8.0.0, ≤ 8.0.182020-01-15
CVE-2020-2570 [MEDIUM] CVE-2020-2570: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2014-2440P4MEDIUMCVSS 5.1≥ 5.5.0, ≤ 5.5.36≥ 5.6.0, ≤ 5.6.162014-04-16
CVE-2014-2440 [MEDIUM] CVE-2014-2440: Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-3588P4MEDIUMCVSS 5.9≤ 5.7.122016-07-21
CVE-2016-3588 [MEDIUM] CVE-2016-3588: Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote authenticated users to affect integrity and availability via vectors related to Server: InnoDB.
nvd
CVE-2026-34318P4MEDIUMCVSS 5.8≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-34318 [MEDIUM] CWE-200 CVE-2026-34318: Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell
nvd
CVE-2012-1703P4MEDIUMCVSS 6.8≥ 5.1.0, ≤ 5.1.61≥ 5.5.0, ≤ 5.5.212012-05-03
CVE-2012-1703 [MEDIUM] CVE-2012-1703: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
nvd
CVE-2007-1420P4LOWCVSS 2.1PoCv5.0.6v5.0.7+2 more2007-03-12
CVE-2007-1420 [LOW] CVE-2007-1420: MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performi
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.
nvd
CVE-2019-2758P4MEDIUMCVSS 5.5≥ 5.7.0, ≤ 5.7.26≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2758 [MEDIUM] CVE-2019-2758: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2008-7247P4MEDIUMCVSS 6.0v5.0.0v5.0.3+58 more2009-11-30
CVE-2008-7247 [MEDIUM] CWE-59 CVE-2008-7247: sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, wh
sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirector
nvd
CVE-2020-2760P4MEDIUMCVSS 5.5≥ 5.7.0, ≤ 5.7.29≥ 8.0.0, ≤ 8.0.192020-04-15
CVE-2020-2760 [MEDIUM] CVE-2020-2760: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2019-2778P4MEDIUMCVSS 5.4≥ 5.7.0, ≤ 5.7.26≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2778 [MEDIUM] CVE-2019-2778: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability
nvd
CVE-2002-1921P4HIGHCVSS 7.5v3.20.32av3.22.26+39 more2002-12-31
CVE-2002-1921 [HIGH] CVE-2002-1921: The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bi
The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.
nvd
CVE-2017-3455P4MEDIUMCVSS 5.4≤ 5.7.172017-04-24
CVE-2017-3455 [MEDIUM] CVE-2017-3455: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in un
nvd
CVE-2015-0382P4MEDIUMCVSS 4.3≥ 5.5.0, ≤ 5.5.40≥ 5.6.0, ≤ 5.6.212015-01-21
CVE-2015-0382 [MEDIUM] CVE-2015-0382: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
nvd
CVE-2012-1735P4MEDIUMCVSS 6.8≥ 5.5.0, ≤ 5.5.232012-07-17
CVE-2012-1735 [MEDIUM] CVE-2012-1735: Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2013-5860P4MEDIUMCVSS 6.8≤ 5.6.14v5.6.0+13 more2014-01-15
CVE-2013-5860 [MEDIUM] CVE-2013-5860: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.14 and earlier allows re
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.14 and earlier allows remote authenticated users to affect availability via vectors related to GIS.
nvd
CVE-2013-0389P4MEDIUMCVSS 6.8≥ 5.1.0, ≤ 5.1.66≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2013-0389 [MEDIUM] CVE-2013-0389: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2012-5060P4MEDIUMCVSS 6.8≥ 5.1.0, ≤ 5.1.65≥ 5.5.0, ≤ 5.5.272013-01-17
CVE-2012-5060 [MEDIUM] CVE-2012-5060: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
nvd
CVE-2022-21482P4MEDIUMCVSS 6.3≥ 8.0.0, ≤ 8.0.282022-04-19
CVE-2022-21482 [MEDIUM] CVE-2022-21482: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Success
nvd
CVE-2022-21290P4MEDIUMCVSS 6.3≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21290 [MEDIUM] CVE-2022-21290: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Success
nvd