Oracle Mysql Server vulnerabilities
334 known vulnerabilities affecting oracle/mysql_server.
Total CVEs
334
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH22MEDIUM285LOW20
Vulnerabilities
Page 2 of 17
CVE-2026-60315P3HIGHCVSS 8.2≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-60315 [HIGH] CWE-200 CVE-2026-60315: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugi
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols
nvd
CVE-2021-22926P3HIGHCVSS 7.5≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22926 [HIGH] CWE-840 CVE-2021-22926: libcurl-using applications can ask for a specific client certificate to be used in a transfer. This
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or with a file name - using the same opt
nvd
CVE-2026-61094P3HIGHCVSS 7.2≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-61094 [HIGH] CWE-269 CVE-2026-61094: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replica
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protoco
nvd
CVE-2026-60316P3HIGHCVSS 7.2≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-60316 [HIGH] CWE-284 CVE-2026-60316: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugi
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols
nvd
CVE-2021-36222P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.0.262021-07-22
CVE-2021-36222 [HIGH] CWE-476 CVE-2021-36222: ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5)
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.
nvd
CVE-2021-35583P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.0.252021-10-20
CVE-2021-35583 [HIGH] CVE-2021-35583: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Windows). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Windows). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2025-21521P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.0.39≥ 8.4.0, ≤ 8.4.2+1 more2025-01-21
CVE-2025-21521 [HIGH] CWE-770 CVE-2025-21521: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2022-27778P3HIGHCVSS 8.1≤ 5.7.38≥ 8.0.0, ≤ 8.0.292022-06-02
CVE-2022-27778 [HIGH] CWE-706 CVE-2022-27778: A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `-
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
nvd
CVE-2020-28196P3HIGHCVSS 7.5≤ 8.0.232020-11-06
CVE-2020-28196 [HIGH] CWE-674 CVE-2020-28196: MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an A
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
nvd
CVE-2023-21912P3HIGHCVSS 7.5≥ 5.7.0, ≤ 5.7.41≥ 8.0.0, ≤ 8.0.302023-04-18
CVE-2023-21912 [HIGH] CVE-2023-21912: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.41 and prior and 8.0.30 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2021-44532P3MEDIUMCVSS 5.3≤ 5.7.37≥ 8.0.0, ≤ 8.0.282022-02-24
CVE-2021-44532 [MEDIUM] CWE-296 CVE-2021-44532: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass o
nvd
CVE-2021-2389P3MEDIUMCVSS 5.9≥ 5.7.0, ≤ 5.7.34≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2389 [MEDIUM] CVE-2021-2389: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2026-60178P3MEDIUMCVSS 6.6≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-60178 [MEDIUM] CWE-284 CVE-2026-60178: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone P
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pr
nvd
CVE-2021-23841P3MEDIUMCVSS 5.9fixed in 5.7.33≥ 8.0.15, < 8.0.232021-02-16
CVE-2021-23841 [MEDIUM] CWE-476 CVE-2021-23841: The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This ma
nvd
CVE-2026-61109P3MEDIUMCVSS 6.5≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-61109 [MEDIUM] CWE-400 CVE-2026-61109: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON).
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to c
nvd
CVE-2021-22947P3MEDIUMCVSS 5.9≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-09-29
CVE-2021-22947 [MEDIUM] CWE-310 CVE-2021-22947: When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *b
nvd
CVE-2026-21949P3MEDIUMCVSS 6.5≥ 9.0.0, ≤ 9.5.02026-01-20
CVE-2026-21949 [MEDIUM] CWE-400 CVE-2026-21949: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2026-21950P3MEDIUMCVSS 6.5≥ 9.0.0, ≤ 9.5.02026-01-20
CVE-2026-21950 [MEDIUM] CWE-400 CVE-2026-21950: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2026-22009P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-22009 [MEDIUM] CWE-400 CVE-2026-22009: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2026-34272P3MEDIUMCVSS 6.5≥ 9.0.0, ≤ 9.6.02026-04-21
CVE-2026-34272 [MEDIUM] CWE-400 CVE-2026-34272: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abili
nvd