Oracle Mysql Server vulnerabilities
334 known vulnerabilities affecting oracle/mysql_server.
Total CVEs
334
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH22MEDIUM285LOW20
Vulnerabilities
Page 4 of 17
CVE-2023-21946P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.322023-04-18
CVE-2023-21946 [MEDIUM] CVE-2023-21946: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2025-21518P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.40≥ 8.4.0, ≤ 8.4.3+1 more2025-01-21
CVE-2025-21518 [MEDIUM] CWE-770 CVE-2025-21518: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vuln
nvd
CVE-2025-21522P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.40≥ 8.4.0, ≤ 8.4.3+1 more2025-01-21
CVE-2025-21522 [MEDIUM] CWE-770 CVE-2025-21522: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2025-21500P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.40≥ 8.4.0, ≤ 8.4.3+1 more2025-01-21
CVE-2025-21500 [MEDIUM] CWE-770 CVE-2025-21500: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vuln
nvd
CVE-2025-21501P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.40≥ 8.4.0, ≤ 8.4.3+1 more2025-01-21
CVE-2025-21501 [MEDIUM] CWE-770 CVE-2025-21501: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vuln
nvd
CVE-2025-21574P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.41≥ 8.4.0, ≤ 8.4.4+1 more2025-04-15
CVE-2025-21574 [MEDIUM] CWE-400 CVE-2025-21574: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2025-21575P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.41≥ 8.4.0, ≤ 8.4.4+1 more2025-04-15
CVE-2025-21575 [MEDIUM] CWE-400 CVE-2025-21575: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2024-21177P4MEDIUMCVSS 6.5≤ 8.0.37≥ 8.1.0, ≤ 8.4.02024-07-16
CVE-2024-21177 [MEDIUM] CWE-400 CVE-2024-21177: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can res
nvd
CVE-2025-30682P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.41≥ 8.4.0, ≤ 8.4.4+1 more2025-04-15
CVE-2025-30682 [MEDIUM] CWE-732 CVE-2025-30682: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2025-30688P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.41≥ 8.4.0, ≤ 8.4.4+1 more2025-04-15
CVE-2025-30688 [MEDIUM] CWE-732 CVE-2025-30688: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2025-30687P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.41≥ 8.4.0, ≤ 8.4.4+1 more2025-04-15
CVE-2025-30687 [MEDIUM] CWE-732 CVE-2025-30687: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2025-21577P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.41≥ 8.4.0, ≤ 8.4.4+1 more2025-04-15
CVE-2025-21577 [MEDIUM] CWE-400 CVE-2025-21577: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2025-21566P4MEDIUMCVSS 6.5≥ 9.0.0, ≤ 9.1.02025-01-21
CVE-2025-21566 [MEDIUM] CWE-732 CVE-2025-21566: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized a
nvd
CVE-2019-2897P3MEDIUMCVSS 6.4≥ 5.0.0, ≤ 5.7.34≥ 8.0.0, ≤ 8.0.252019-10-16
CVE-2019-2897 [MEDIUM] CVE-2019-2897: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2022-21457P4MEDIUMCVSS 5.9≥ 8.0.0, ≤ 8.0.282022-04-19
CVE-2022-21457 [MEDIUM] CVE-2022-21457: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2017-3273P4MEDIUMCVSS 6.5v5.6.34 and earlierv5.7.16 and earlier2017-01-27
CVE-2017-3273 [MEDIUM] CWE-20 CVE-2017-3273: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2017-3258P4MEDIUMCVSS 6.5v5.5.53 and earlierv5.6.34 and earlier+1 more2017-01-27
CVE-2017-3258 [MEDIUM] CWE-20 CVE-2017-3258: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2017-3257P4MEDIUMCVSS 6.5v5.6.34 and earlierv5.7.16 and earlier2017-01-27
CVE-2017-3257 [MEDIUM] CWE-269 CVE-2017-3257: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.34 and earlier5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can re
nvd
CVE-2022-21569P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.292022-07-19
CVE-2022-21569 [MEDIUM] CVE-2022-21569: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2024-20962P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-02-17
CVE-2024-20962 [MEDIUM] CWE-400 CVE-2024-20962: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can res
nvd