cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 64 of 67
CVE-2021-2340P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2340 [LOW] CVE-2021-2340: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2022-21249P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21249 [LOW] CVE-2022-21249: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2020-14633P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14633 [LOW] CVE-2020-14633: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or de
nvd
CVE-2018-3082P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.112018-07-18
CVE-2018-3082 [LOW] CVE-2018-3082: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2021-35625P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35625 [LOW] CVE-2021-35625: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2021-35623P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35623 [LOW] CVE-2021-35623: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supp Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized rea
nvd
CVE-2020-2572P4LOWCVSS 2.7≥ 5.7.0, ≤ 5.7.28≥ 8.0.0, ≤ 8.0.182020-01-15
CVE-2020-2572 [LOW] CVE-2020-2572: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plugin). Support Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plugin). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2019-2730P4LOWCVSS 2.7≥ 5.6.0, ≤ 5.6.44≥ 5.7.0, ≤ 5.7.182019-07-23
CVE-2019-2730 [LOW] CVE-2019-2730: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior and 5.7.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2020-14860P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14860 [LOW] CVE-2020-14860: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supp Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized upd
nvd
CVE-2001-1255P4MEDIUMCVSS 4.6v3.232001-10-02
CVE-2001-1255 [MEDIUM] CVE-2001-1255: WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local use WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
nvd
CVE-2004-0381P4LOWCVSS 2.1v3.20.32av3.22.26+67 more2004-05-04
CVE-2004-0381 [LOW] CVE-2004-0381: mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.
nvd
CVE-2004-0388P4LOWCVSS 2.1v5.0.332004-06-01
CVE-2004-0388 [LOW] CVE-2004-0388: The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attac The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2010-1626P4LOWCVSS 3.6v5.0.18v5.0.19+31 more2010-05-21
CVE-2010-1626 [LOW] CVE-2010-1626: MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM t MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
nvd
CVE-2014-4240P4LOWCVSS 3.6≤ 5.6.17v5.6.0+16 more2014-07-17
CVE-2014-4240 [LOW] CVE-2014-4240: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows lo Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows local users to affect confidentiality and integrity via vectors related to SRREP.
nvd
CVE-2021-35633P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35633 [LOW] CVE-2021-35633: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2021-35640P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35640 [LOW] CVE-2021-35640: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2023-22113P4LOWCVSS 2.7≥ 8.0, ≤ 8.0.332023-10-17
CVE-2023-22113 [LOW] CWE-125 CVE-2023-22113: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in una
nvd
CVE-2020-14791P4LOWCVSS 2.2≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14791 [LOW] CVE-2020-14791: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2019-2814P4LOWCVSS 2.2≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2814 [LOW] CVE-2019-2814: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2013-5770P4LOWCVSS 2.1≤ 5.6.11v5.6.0+10 more2013-10-16
CVE-2013-5770 [LOW] CVE-2013-5770: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.
nvd
Oracle MySQL vulnerabilities | cvebase