cbcvebase.

Oracle Mysql Cluster vulnerabilities

89 known vulnerabilities affecting oracle/mysql_cluster.

Total CVEs
89
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM66LOW11

Vulnerabilities

Page 2 of 5
CVE-2025-30722P3MEDIUMCVSS 6.8≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-30722 [MEDIUM] CVE-2025-30722: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can resu
nvd
CVE-2021-44532P3MEDIUMCVSS 5.3≤ 8.0.292022-02-24
CVE-2021-44532 [MEDIUM] CWE-296 CVE-2021-44532: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass o
nvd
CVE-2026-60178P3MEDIUMCVSS 6.6≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-60178 [MEDIUM] CWE-284 CVE-2026-60178: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone P Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pr
nvd
CVE-2026-61109P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-61109 [MEDIUM] CWE-400 CVE-2026-61109: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to c
nvd
CVE-2026-47064P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-47064 [MEDIUM] CWE-284 CVE-2026-47064: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocol
nvd
CVE-2021-22939P4MEDIUMCVSS 5.3≤ 8.0.262021-08-16
CVE-2021-22939 [MEDIUM] CWE-295 CVE-2021-22939: If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthori If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
nvd
CVE-2026-60718P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60718 [MEDIUM] CWE-400 CVE-2026-60718: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Succes
nvd
CVE-2026-60174P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60174 [MEDIUM] CWE-400 CVE-2026-60174: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2026-61093P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-61093 [MEDIUM] CWE-400 CVE-2026-61093: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2021-44533P4MEDIUMCVSS 5.3fixed in 8.0.29v8.0.292022-02-24
CVE-2021-44533 [MEDIUM] CWE-295 CVE-2021-44533: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguis Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allo
nvd
CVE-2026-60311P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60311 [MEDIUM] CWE-400 CVE-2026-60311: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.0.0-9.7.1; MySQL Cluster: 9.0.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2026-61108P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-61108 [MEDIUM] CWE-400 CVE-2026-61108: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS). Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successf
nvd
CVE-2026-60324P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60324 [MEDIUM] CWE-400 CVE-2026-60324: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2025-21518P4MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.32≥ 8.0.0, ≤ 8.0.40+2 more2025-01-21
CVE-2025-21518 [MEDIUM] CWE-770 CVE-2025-21518: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vuln
nvd
CVE-2025-21574P4MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-21574 [MEDIUM] CWE-400 CVE-2025-21574: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2025-21575P4MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.33≥ 8.0.0, ≤ 8.0.41+2 more2025-04-15
CVE-2025-21575 [MEDIUM] CWE-400 CVE-2025-21575: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2024-21177P4MEDIUMCVSS 6.5≤ 7.5.34≥ 7.6.0, ≤ 7.6.30+2 more2024-07-16
CVE-2024-21177 [MEDIUM] CWE-400 CVE-2024-21177: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can res
nvd
CVE-2026-60183P4MEDIUMCVSS 6.4≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-60183 [MEDIUM] CWE-269 CVE-2026-60183: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone P Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure wh
nvd
CVE-2026-60332P4MEDIUMCVSS 6.4≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-60332 [MEDIUM] CWE-284 CVE-2026-60332: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group R Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastr
nvd
CVE-2026-60331P4MEDIUMCVSS 6.4≥ 8.0.0, ≤ 8.0.47≥ 8.4.0, ≤ 8.4.10+2 more2026-07-21
CVE-2026-60331 [MEDIUM] CWE-284 CVE-2026-60331: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replica Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure whe
nvd
Oracle Mysql Cluster vulnerabilities | cvebase