cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 65 of 67
CVE-2012-4452P4LOWCVSS 2.1≤ 5.0.882012-10-09
CVE-2012-4452 [LOW] CVE-2012-4452: MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privil MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modi
nvd
CVE-2022-21485P4LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.35≥ 7.5.0, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21485 [LOW] CVE-2022-21485: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2022-21484P4LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.35≥ 7.5.0, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21484 [LOW] CVE-2022-21484: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2022-21486P4LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.35≥ 7.5.0, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21486 [LOW] CVE-2022-21486: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2022-21313P4LOWCVSS 2.9≥ 7.6.0, ≤ 7.6.20≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21313 [LOW] CVE-2022-21313: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQ
nvd
CVE-2022-21311P4LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21311 [LOW] CVE-2022-21311: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2022-21323P4LOWCVSS 2.9≥ 7.5.0, ≤ 7.5.24≥ 7.6.0, ≤ 7.6.20+1 more2022-01-19
CVE-2022-21323 [LOW] CVE-2022-21323: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes
nvd
CVE-2025-50081P4LOWCVSS 3.1≥ 8.0.0, ≤ 8.0.42≥ 8.4.0, ≤ 8.4.5+1 more2025-07-15
CVE-2025-50081 [LOW] CWE-284 CVE-2025-50081: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks require human interactio
nvd
CVE-2021-2301P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.232021-04-22
CVE-2021-2301 [LOW] CVE-2021-2301: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized re
nvd
CVE-2021-2308P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.232021-04-22
CVE-2021-2308 [LOW] CVE-2021-2308: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized re
nvd
CVE-2023-21882P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.312023-01-18
CVE-2023-21882 [LOW] CVE-2023-21882: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, in
nvd
CVE-2020-14771P4LOWCVSS 2.2≥ 5.7.0, ≤ 5.7.31≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14771 [LOW] CVE-2020-14771: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2017-3320P4LOWCVSS 2.4≤ 5.7.162017-01-27
CVE-2017-3320 [LOW] CVE-2017-3320: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encrypt Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.7.16 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person ot
nvd
CVE-2019-2513P4LOWCVSS 2.5≥ 8.0.0, < 8.0.132019-01-16
CVE-2019-2513 [LOW] CVE-2019-2513: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell). Supported version Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other th
nvd
CVE-1999-1188P4MEDIUMCVSS 4.6v3.211998-12-27
CVE-1999-1188 [MEDIUM] CVE-1999-1188: mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
nvd
CVE-2024-21244P4LOWCVSS 2.2≥ 8.4.0, ≤ 8.4.2v9.0.0+1 more2024-10-15
CVE-2024-21244 [LOW] CVE-2024-21244: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in un
nvd
CVE-2024-21243P4LOWCVSS 2.2≥ 8.4.0, ≤ 8.4.2v9.0.0+1 more2024-10-15
CVE-2024-21243 [LOW] CVE-2024-21243: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in un
nvd
CVE-2006-0369P4LOWCVSS 2.1v5.0.182006-01-22
CVE-2006-0369 [LOW] CWE-200 CVE-2006-0369: MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELEC MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access
nvd
CVE-2022-21331P4LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21331 [LOW] CVE-2022-21331: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
CVE-2022-21312P4LOWCVSS 2.9≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21312 [LOW] CVE-2022-21312: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL
nvd
Oracle MySQL vulnerabilities | cvebase