Oracle MySQL vulnerabilities

1,328 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,328
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH71MEDIUM1064LOW181

Vulnerabilities

Page 5 of 67
CVE-2024-21050MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.342024-04-16
CVE-2024-21050 [MEDIUM] CWE-400 CVE-2024-21050: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2024-21061MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-04-16
CVE-2024-21061 [MEDIUM] CVE-2024-21061: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plug-in). Suppo Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plug-in). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2024-21102MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.36≥ 8.1.0, ≤ 8.3.02024-04-16
CVE-2024-21102 [MEDIUM] CVE-2024-21102: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supp Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resu
nvd
CVE-2024-21096MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.36≥ 8.1.0, ≤ 8.3.02024-04-16
CVE-2024-21096 [MEDIUM] CWE-829 CVE-2024-21096: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this
nvd
CVE-2024-21051MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.342024-04-16
CVE-2024-21051 [MEDIUM] CWE-400 CVE-2024-21051: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2024-21056MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.342024-04-16
CVE-2024-21056 [MEDIUM] CVE-2024-21056: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2024-21087MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.36≥ 8.1.0, ≤ 8.3.02024-04-16
CVE-2024-21087 [MEDIUM] CVE-2024-21087: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2024-21055MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.352024-04-16
CVE-2024-21055 [MEDIUM] CWE-400 CVE-2024-21055: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2024-21101LOWCVSS 2.2≥ 7.5.0, ≤ 7.5.33≥ 7.6.0, ≤ 7.6.29+2 more2024-04-16
CVE-2024-21101 [LOW] CWE-269 CVE-2024-21101: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.33 and prior, 7.6.29 and prior, 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful
nvd
CVE-2024-20971MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20971 [MEDIUM] CWE-400 CVE-2024-20971: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2024-20965MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20965 [MEDIUM] CWE-400 CVE-2024-20965: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2024-20973MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20973 [MEDIUM] CVE-2024-20973: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2024-20969MEDIUMCVSS 5.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20969 [MEDIUM] CWE-284 CVE-2024-20969: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2024-20975MEDIUMCVSS 6.5≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20975 [MEDIUM] CVE-2024-20975: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2024-20983MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.342024-01-16
CVE-2024-20983 [MEDIUM] CWE-400 CVE-2024-20983: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2024-20963MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20963 [MEDIUM] CVE-2024-20963: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2024-20985MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20985 [MEDIUM] CWE-400 CVE-2024-20985: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd
CVE-2024-20967MEDIUMCVSS 5.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20967 [MEDIUM] CVE-2024-20967: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Support Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2024-20961MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20961 [MEDIUM] CWE-400 CVE-2024-20961: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can re
nvd
CVE-2024-20981MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-01-16
CVE-2024-20981 [MEDIUM] CWE-400 CVE-2024-20981: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd