cbcvebase.

Oracle Mysql Server vulnerabilities

334 known vulnerabilities affecting oracle/mysql_server.

Total CVEs
334
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH22MEDIUM285LOW20

Vulnerabilities

Page 3 of 17
CVE-2026-34303P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-34303 [MEDIUM] CWE-400 CVE-2026-34303: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2026-34276P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-34276 [MEDIUM] CWE-400 CVE-2026-34276: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2026-34271P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-34271 [MEDIUM] CWE-400 CVE-2026-34271: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2026-34308P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-34308 [MEDIUM] CWE-400 CVE-2026-34308: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported vers Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can res
nvd
CVE-2026-34270P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-34270 [MEDIUM] CWE-400 CVE-2026-34270: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2026-22017P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-22017 [MEDIUM] CWE-400 CVE-2026-22017: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2026-47064P3MEDIUMCVSS 6.5≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-47064 [MEDIUM] CWE-284 CVE-2026-47064: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocol
nvd
CVE-2020-1971P3MEDIUMCVSS 5.9≤ 5.7.32≥ 8.0.15, ≤ 8.0.222020-12-08
CVE-2020-1971 [MEDIUM] CWE-476 CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A
nvd
CVE-2017-3238P3MEDIUMCVSS 6.5v5.5.53 and earlierv5.6.34 and earlier+1 more2017-01-27
CVE-2017-3238 [MEDIUM] CVE-2017-3238: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2021-22922P3MEDIUMCVSS 6.5≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22922 [MEDIUM] CWE-840 CVE-2021-22922: When curl is instructed to download content using the metalink feature, thecontents is verified agai When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several o
nvd
CVE-2019-5443P3HIGHCVSS 7.8≥ 5.0.0, ≤ 5.7.27≥ 8.0.0, ≤ 8.0.172019-07-02
CVE-2019-5443 [HIGH] CWE-94 CVE-2019-5443: A non-privileged user or program can put code and a config file in a known non-privileged path (unde A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
nvd
CVE-2026-60718P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60718 [MEDIUM] CWE-400 CVE-2026-60718: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Succes
nvd
CVE-2026-60174P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60174 [MEDIUM] CWE-400 CVE-2026-60174: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2026-61093P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-61093 [MEDIUM] CWE-400 CVE-2026-61093: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2021-44533P4MEDIUMCVSS 5.3≤ 5.7.37≥ 8.0.0, ≤ 8.0.282022-02-24
CVE-2021-44533 [MEDIUM] CWE-295 CVE-2021-44533: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguis Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allo
nvd
CVE-2026-60311P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60311 [MEDIUM] CWE-400 CVE-2026-60311: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.0.0-9.7.1; MySQL Cluster: 9.0.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2026-61108P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-61108 [MEDIUM] CWE-400 CVE-2026-61108: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS). Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successf
nvd
CVE-2026-21968P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.44≥ 8.4.0, ≤ 8.4.7+1 more2026-01-20
CVE-2026-21968 [MEDIUM] CVE-2026-21968: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2026-60324P3MEDIUMCVSS 6.5v9.7.0v9.7.12026-07-21
CVE-2026-60324 [MEDIUM] CWE-400 CVE-2026-60324: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimiz Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.
nvd
CVE-2017-3244P4MEDIUMCVSS 6.5v5.5.53 and earlierv5.6.34 and earlier+1 more2017-01-27
CVE-2017-3244 [MEDIUM] CVE-2017-3244: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
Oracle Mysql Server vulnerabilities | cvebase