cbcvebase.

Oracle Mysql Cluster vulnerabilities

89 known vulnerabilities affecting oracle/mysql_cluster.

Total CVEs
89
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM66LOW11

Vulnerabilities

Page 1 of 5
CVE-2021-22931P2CRITICALCVSS 9.8≤ 8.0.262021-08-16
CVE-2021-22931 [CRITICAL] CWE-170 CVE-2021-22931: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
nvd
CVE-2021-22883P2HIGHCVSS 7.5≤ 8.0.252021-03-03
CVE-2021-22883 [HIGH] CWE-400 CVE-2021-22883: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack wh Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also
nvd
CVE-2020-8277P3HIGHCVSS 7.5≤ 8.0.232020-11-19
CVE-2020-8277 [HIGH] CWE-400 CVE-2020-8277: A Node.js application that allows an attacker to trigger a DNS request for a host of their choice co A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
nvd
CVE-2021-22884P3HIGHCVSS 7.5≤ 8.0.252021-03-03
CVE-2021-22884 [HIGH] CVE-2021-22884: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection
nvd
CVE-2022-21824P3HIGHCVSS 8.2≤ 8.0.292022-02-24
CVE-2022-21824 [HIGH] CWE-471 CVE-2022-21824: Due to the formatting logic of the "console.table()" function it was not safe to allow user controll Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an em
nvd
CVE-2021-35590P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35590 [MEDIUM] CWE-787 CVE-2021-35590: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2022-21490P3MEDIUMCVSS 6.3≥ 7.4.00, ≤ 7.4.35≥ 7.5.00, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21490 [MEDIUM] CVE-2022-21490: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2021-44531P3HIGHCVSS 7.4≤ 8.0.292022-02-24
CVE-2021-44531 [HIGH] CWE-295 CVE-2021-44531: Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to us Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, N
nvd
CVE-2021-35592P3MEDIUMCVSS 6.3≥ 7.5.0, ≤ 7.5.23≥ 7.6.0, ≤ 7.6.19+1 more2021-10-20
CVE-2021-35592 [MEDIUM] CWE-129 CVE-2021-35592: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluste
nvd
CVE-2022-21550P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.36≥ 7.5.0, ≤ 7.5.26+2 more2022-07-19
CVE-2022-21550 [MEDIUM] CVE-2022-21550: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.36 and prior, 7.5.26 and prior, 7.6.22 and prior and and 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where th
nvd
CVE-2021-35593P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35593 [MEDIUM] CWE-787 CVE-2021-35593: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2021-35594P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35594 [MEDIUM] CWE-129 CVE-2021-35594: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2021-35598P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35598 [MEDIUM] CWE-129 CVE-2021-35598: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2020-8174P3HIGHCVSS 8.1≤ 7.3.30≥ 7.4.0, ≤ 7.4.29+3 more2020-07-24
CVE-2020-8174 [HIGH] CWE-119 CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
nvd
CVE-2026-60163P3HIGHCVSS 8.4≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-60163 [HIGH] CWE-284 CVE-2026-60163: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group R Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastru
nvd
CVE-2026-60315P3HIGHCVSS 8.2≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-60315 [HIGH] CWE-200 CVE-2026-60315: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugi Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols
nvd
CVE-2021-35621P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35621 [MEDIUM] CVE-2021-35621: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2020-8172P3HIGHCVSS 7.4≤ 7.3.30≥ 7.4.0, ≤ 7.4.29+3 more2020-06-08
CVE-2020-8172 [HIGH] CWE-295 CVE-2020-8172: TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 1 TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
nvd
CVE-2026-61094P3HIGHCVSS 7.2≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-61094 [HIGH] CWE-269 CVE-2026-61094: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replica Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protoco
nvd
CVE-2026-60316P3HIGHCVSS 7.2≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-60316 [HIGH] CWE-284 CVE-2026-60316: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugi Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols
nvd
Oracle Mysql Cluster vulnerabilities | cvebase