Oracle Mysql Server vulnerabilities
334 known vulnerabilities affecting oracle/mysql_server.
Total CVEs
334
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH22MEDIUM285LOW20
Vulnerabilities
Page 5 of 17
CVE-2024-20960P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.35≥ 8.1.0, ≤ 8.2.02024-02-17
CVE-2024-20960 [MEDIUM] CVE-2024-20960: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: RAPID). Supported ver
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: RAPID). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2021-2390P4MEDIUMCVSS 5.9≥ 5.7.0, ≤ 5.7.34≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2390 [MEDIUM] CWE-191 CVE-2021-2390: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2017-3256P4MEDIUMCVSS 6.5v5.7.16 and earlier2017-01-27
CVE-2017-3256 [MEDIUM] CWE-20 CVE-2017-3256: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2021-22925P4MEDIUMCVSS 5.3≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22925 [MEDIUM] CWE-200 CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revea
nvd
CVE-2022-21556P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.282022-07-19
CVE-2022-21556 [MEDIUM] CVE-2022-21556: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creatio
nvd
CVE-2023-21868P4MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.312023-01-18
CVE-2023-21868 [MEDIUM] CVE-2023-21868: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2026-60183P4MEDIUMCVSS 6.4≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-60183 [MEDIUM] CWE-269 CVE-2026-60183: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone P
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure wh
nvd
CVE-2026-60332P4MEDIUMCVSS 6.4≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-60332 [MEDIUM] CWE-284 CVE-2026-60332: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group R
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastr
nvd
CVE-2026-60331P4MEDIUMCVSS 6.4≥ 8.4.0, ≤ 8.4.10v9.7.0+1 more2026-07-21
CVE-2026-60331 [MEDIUM] CWE-284 CVE-2026-60331: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replica
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure whe
nvd
CVE-2023-22053P4MEDIUMCVSS 5.9≥ 5.0.0, ≤ 5.7.42≥ 8.0.0, ≤ 8.0.322023-07-18
CVE-2023-22053 [MEDIUM] CVE-2023-22053: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported v
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.42 and prior and 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2026-60181P4MEDIUMCVSS 6.7v9.7.0v9.7.12026-07-21
CVE-2026-60181 [MEDIUM] CWE-284 CVE-2026-60181: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configu
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to co
nvd
CVE-2021-2417P4MEDIUMCVSS 6.0≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2417 [MEDIUM] CVE-2021-2417: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2021-22897P4MEDIUMCVSS 5.3≤ 5.7.34≥ 8.0.0, ≤ 8.0.252021-06-11
CVE-2021-22897 [MEDIUM] CWE-840 CVE-2021-22897: curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake i
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple
nvd
CVE-2021-22923P4MEDIUMCVSS 5.3≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22923 [MEDIUM] CWE-319 CVE-2021-22923: When curl is instructed to get content using the metalink feature, and a user name and password are
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and witho
nvd
CVE-2025-21540P4MEDIUMCVSS 5.4≥ 8.0.0, ≤ 8.0.40≥ 8.4.0, ≤ 8.4.3+1 more2025-01-21
CVE-2025-21540 [MEDIUM] CWE-863 CVE-2025-21540: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2016-8318P4MEDIUMCVSS 6.8v5.6.34 and earlierv5.7.16 and earlier2017-01-27
CVE-2016-8318 [MEDIUM] CVE-2016-8318: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encrypt
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human int
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1fixed in 5.7.36≥ 8.0.0, < 8.0.27+1 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2021-35604P4MEDIUMCVSS 5.5≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35604 [MEDIUM] CVE-2021-35604: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2025-53053P4MEDIUMCVSS 5.5≥ 8.0.0, ≤ 8.0.42≥ 8.4.0, ≤ 8.4.6+1 more2025-10-21
CVE-2025-53053 [MEDIUM] CWE-400 CVE-2025-53053: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can res
nvd
CVE-2025-53054P4MEDIUMCVSS 5.5≥ 8.0.0, ≤ 8.0.42≥ 8.4.0, ≤ 8.4.6+1 more2025-10-21
CVE-2025-53054 [MEDIUM] CWE-400 CVE-2025-53054: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd