Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 9 of 67
CVE-2018-3060P4MEDIUMCVSS 6.5≥ 5.7.0, ≤ 5.7.22≥ 8.0.0, ≤ 8.0.112018-07-18
CVE-2018-3060 [MEDIUM] CVE-2018-3060: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2018-3133P4MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.61≥ 5.6.0, ≤ 5.6.41+2 more2018-10-17
CVE-2018-3133 [MEDIUM] CVE-2018-3133: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2020-14619P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14619 [MEDIUM] CVE-2020-14619: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2019-3011P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.172019-10-16
CVE-2019-3011 [MEDIUM] CVE-2019-3011: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported vers
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2019-3004P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.172019-10-16
CVE-2019-3004 [MEDIUM] CVE-2019-3004: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2021-35597P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35597 [MEDIUM] CVE-2021-35597: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2020-14769P4MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.49≥ 5.7.0, ≤ 5.7.31+1 more2020-10-21
CVE-2020-14769 [MEDIUM] CVE-2020-14769: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabil
nvd
CVE-2020-14775P4MEDIUMCVSS 6.5≥ 5.7.0, ≤ 5.7.31≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14775 [MEDIUM] CVE-2020-14775: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2020-2780P4MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2020-04-15
CVE-2020-2780 [MEDIUM] CVE-2020-2780: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2020-14846P4MEDIUMCVSS 6.5≤ 8.0.212020-10-21
CVE-2020-14846 [MEDIUM] CVE-2020-14846: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2023-21980P4HIGHCVSS 7.1≥ 5.0.0, ≤ 5.7.41≥ 8.0.0, ≤ 8.0.322023-04-18
CVE-2023-21980 [HIGH] CWE-284 CVE-2023-21980: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported v
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from
nvd
CVE-2016-2047P4MEDIUMCVSS 5.9≥ 5.5.0, ≤ 5.5.48≥ 5.6.0, ≤ 5.6.29+1 more2016-01-27
CVE-2016-2047 [MEDIUM] CWE-254 CVE-2016-2047: The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 1
The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName
nvd
CVE-2021-2024P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.222021-01-20
CVE-2021-2024 [MEDIUM] CVE-2021-2024: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2020-14539P4MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.48≥ 5.7.0, ≤ 5.7.30+1 more2020-07-15
CVE-2020-14539 [MEDIUM] CVE-2020-14539: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabil
nvd
CVE-2020-14576P4MEDIUMCVSS 6.5≥ 5.7.0, ≤ 5.7.30≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14576 [MEDIUM] CVE-2020-14576: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2021-2172P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.232021-04-22
CVE-2021-2172 [MEDIUM] CVE-2021-2172: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2021-2178P4MEDIUMCVSS 6.5≥ 5.7.0, ≤ 5.7.32≥ 8.0.0, ≤ 8.0.222021-04-22
CVE-2021-2178 [MEDIUM] CVE-2021-2178: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supporte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2020-14680P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14680 [MEDIUM] CVE-2020-14680: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-14836P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14836 [MEDIUM] CVE-2020-14836: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-14830P4MEDIUMCVSS 6.5≤ 8.0.212020-10-21
CVE-2020-14830 [MEDIUM] CVE-2020-14830: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd