Oracle Mysql Cluster vulnerabilities

48 known vulnerabilities affecting oracle/mysql_cluster.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM32LOW8

Vulnerabilities

Page 1 of 3
CVE-2026-21936MEDIUMCVSS 4.9≥ 7.6.0, ≤ 7.6.36≥ 8.0.0, ≤ 8.0.44+2 more2026-01-20
CVE-2026-21936 [MEDIUM] CVE-2026-21936: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2025-50068MEDIUMCVSS 6.7≥ 8.0.0, ≤ 8.0.42≥ 8.4.0, ≤ 8.4.5+1 more2025-07-15
CVE-2025-50068 [MEDIUM] CVE-2025-50068: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster. Successful attacks of this vu
nvd
CVE-2025-53023MEDIUMCVSS 4.9≥ 7.6.0, ≤ 7.6.34≥ 8.0.0, ≤ 8.0.422025-07-15
CVE-2025-53023 [MEDIUM] CWE-400 CVE-2025-53023: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Support Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.42. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2025-21574MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-21574 [MEDIUM] CWE-400 CVE-2025-21574: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2025-30710MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.41≥ 8.4.0, ≤ 8.4.4+1 more2025-04-15
CVE-2025-30710 [MEDIUM] CWE-284 CVE-2025-30710: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vuln
nvd
CVE-2025-21575MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-21575 [MEDIUM] CWE-400 CVE-2025-21575: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2025-30722MEDIUMCVSS 6.8≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-30722 [MEDIUM] CVE-2025-30722: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can res
nvd
CVE-2025-30693MEDIUMCVSS 5.5≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-30693 [MEDIUM] CWE-284 CVE-2025-30693: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2025-30681LOWCVSS 2.7≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-30681 [LOW] CWE-400 CVE-2025-30681: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Support Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2025-21531MEDIUMCVSS 4.9≥ 7.6.0, ≤ 7.6.32≥ 8.0.0, ≤ 8.0.40+2 more2025-01-21
CVE-2025-21531 [MEDIUM] CWE-770 CVE-2025-21531: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability
nvd
CVE-2025-21518MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.32≥ 8.0.0, ≤ 8.0.40+2 more2025-01-21
CVE-2025-21518 [MEDIUM] CWE-770 CVE-2025-21518: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vul
nvd
CVE-2025-21543MEDIUMCVSS 4.9≥ 7.6.0, ≤ 7.6.32≥ 8.0.0, ≤ 8.0.40+2 more2025-01-21
CVE-2025-21543 [MEDIUM] CWE-770 CVE-2025-21543: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vu
nvd
CVE-2025-21520LOWCVSS 1.8≥ 7.6.0, ≤ 7.6.32≥ 8.0.0, ≤ 8.0.40+2 more2025-01-21
CVE-2025-21520 [LOW] CWE-732 CVE-2025-21520: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported v Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful att
nvd
CVE-2024-21177MEDIUMCVSS 6.5≤ 7.5.34≥ 7.6.0, ≤ 7.6.30+2 more2024-07-16
CVE-2024-21177 [MEDIUM] CWE-400 CVE-2024-21177: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can re
nvd
CVE-2023-21860MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.38≥ 7.5.0, ≤ 7.5.28+2 more2023-01-18
CVE-2023-21860 [MEDIUM] CWE-284 CVE-2023-21860: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations) Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected are 7.4.38 and prior, 7.5.28 and prior, 7.6.24 and prior and 8.0.31 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the
nvd
CVE-2022-21519MEDIUMCVSS 5.9≤ 8.0.292022-07-19
CVE-2022-21519 [MEDIUM] CVE-2022-21519: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2022-21550MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.36≥ 7.5.0, ≤ 7.5.26+2 more2022-07-19
CVE-2022-21550 [MEDIUM] CVE-2022-21550: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.36 and prior, 7.5.26 and prior, 7.6.22 and prior and and 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where th
nvd
CVE-2022-21490MEDIUMCVSS 6.3≥ 7.4.00, ≤ 7.4.35≥ 7.5.00, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21490 [MEDIUM] CVE-2022-21490: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2021-44531HIGHCVSS 7.4≤ 8.0.292022-02-24
CVE-2021-44531 [HIGH] CWE-295 CVE-2021-44531: Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to us Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, N
nvd
CVE-2022-21824HIGHCVSS 8.2≤ 8.0.292022-02-24
CVE-2022-21824 [HIGH] CWE-471 CVE-2022-21824: Due to the formatting logic of the "console.table()" function it was not safe to allow user controll Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an em
nvd