Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 59 of 67
CVE-2016-0668P4MEDIUMCVSS 4.1≥ 5.6.0, ≤ 5.6.28≥ 5.7.0, ≤ 5.7.102016-04-21
CVE-2016-0668 [MEDIUM] CVE-2016-0668: Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB.
nvd
CVE-2015-4895P4LOWCVSS 3.5≥ 5.6.0, ≤ 5.6.252015-10-21
CVE-2015-4895 [LOW] CVE-2015-4895: Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2014-2434P4MEDIUMCVSS 4.0≤ 5.6.15v5.6.0+14 more2014-04-16
CVE-2014-2434 [MEDIUM] CVE-2014-2434: Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2013-3812P4LOWCVSS 3.5≥ 5.5.0, ≤ 5.5.31≥ 5.6.0, ≤ 5.6.112013-07-17
CVE-2013-3812 [LOW] CVE-2013-3812: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
nvd
CVE-2009-4030P4MEDIUMCVSS 4.4v5.1v5.1.1+21 more2009-11-30
CVE-2009-4030 [MEDIUM] CWE-59 CVE-2009-4030: MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TA
MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a sym
nvd
CVE-2013-5767P4MEDIUMCVSS 4.0≤ 5.6.12v5.6.0+11 more2013-10-16
CVE-2013-5767 [MEDIUM] CVE-2013-5767: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.12 and earlier allows re
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-4769P4LOWCVSS 3.5≤ 5.6.242015-07-16
CVE-2015-4769 [LOW] CVE-2015-4769: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4767.
nvd
CVE-2015-4771P4LOWCVSS 3.5≤ 5.6.242015-07-16
CVE-2015-4771 [LOW] CVE-2015-4771: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to RBR.
nvd
CVE-2015-4761P4LOWCVSS 3.5≤ 5.6.242015-07-16
CVE-2015-4761 [LOW] CVE-2015-4761: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.
nvd
CVE-2014-2450P4MEDIUMCVSS 4.0≤ 5.6.15v5.6.0+14 more2014-04-16
CVE-2014-2450 [MEDIUM] CVE-2014-2450: Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2025-50096P4MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.42≥ 8.4.0, ≤ 8.4.5+1 more2025-07-15
CVE-2025-50096 [MEDIUM] CWE-400 CVE-2025-50096: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerab
nvd
CVE-2019-2910P4LOWCVSS 3.7≥ 5.6.0, ≤ 5.6.45≥ 5.7.0, ≤ 5.7.272019-10-16
CVE-2019-2910 [LOW] CVE-2019-2910: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2015-0507P4LOWCVSS 3.5≤ 5.6.232015-04-16
CVE-2015-0507 [LOW] CVE-2015-0507: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.
nvd
CVE-2015-4890P4LOWCVSS 3.5≤ 5.6.262015-10-21
CVE-2015-4890 [LOW] CVE-2015-4890: Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Replication.
nvd
CVE-2013-1566P4LOWCVSS 3.5≤ 5.6.10v5.6.0+9 more2013-04-17
CVE-2013-1566 [LOW] CVE-2013-1566: Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2013-1511P4LOWCVSS 3.5≥ 5.5.0, ≤ 5.5.30≥ 5.6.0, ≤ 5.6.102013-04-17
CVE-2013-1511 [LOW] CVE-2013-1511: Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote au
Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2017-3318P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.53≥ 5.6.0, ≤ 5.6.34+1 more2017-01-27
CVE-2017-3318 [MEDIUM] CVE-2017-3318: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Su
nvd
CVE-2013-2381P4LOWCVSS 3.5≤ 5.6.10v5.1.51+46 more2013-04-17
CVE-2013-2381 [LOW] CVE-2013-2381: Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server Privileges.
nvd
CVE-2013-5793P4LOWCVSS 3.5≤ 5.6.12v5.6.0+11 more2013-10-16
CVE-2013-5793 [LOW] CVE-2013-5793: Unspecified vulnerability in Oracle MySQL Server 5.6.12 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-5786.
nvd
CVE-2016-8286P4LOWCVSS 3.1≤ 5.7.142016-10-25
CVE-2016-8286 [LOW] CWE-200 CVE-2016-8286: Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows remote authenticated users to affect confidentiality via vectors related to Server: Security: Privileges.
nvd