Oracle Mysql Server vulnerabilities
334 known vulnerabilities affecting oracle/mysql_server.
Total CVEs
334
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH22MEDIUM285LOW20
Vulnerabilities
Page 8 of 17
CVE-2023-22056P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.332023-07-18
CVE-2023-22056 [MEDIUM] CVE-2023-22056: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2022-21418P4MEDIUMCVSS 5.0≥ 8.0.0, ≤ 8.0.282022-04-19
CVE-2022-21418 [MEDIUM] CVE-2022-21418: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2026-21952P4MEDIUMCVSS 4.9≥ 9.0.0, ≤ 9.5.02026-01-20
CVE-2026-21952 [MEDIUM] CWE-400 CVE-2026-21952: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2026-21937P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.44≥ 8.4.0, ≤ 8.4.7+1 more2026-01-20
CVE-2026-21937 [MEDIUM] CVE-2026-21937: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2026-21936P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.44≥ 8.4.0, ≤ 8.4.7+1 more2026-01-20
CVE-2026-21936 [MEDIUM] CVE-2026-21936: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2026-21941P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.44≥ 8.4.0, ≤ 8.4.7+1 more2026-01-20
CVE-2026-21941 [MEDIUM] CWE-400 CVE-2026-21941: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2026-21948P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.44≥ 8.4.0, ≤ 8.4.7+1 more2026-01-20
CVE-2026-21948 [MEDIUM] CWE-400 CVE-2026-21948: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2026-34267P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.452026-04-21
CVE-2026-34267 [MEDIUM] CWE-400 CVE-2026-34267: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abi
nvd
CVE-2026-34304P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-34304 [MEDIUM] CWE-400 CVE-2026-34304: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd
CVE-2026-22004P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-22004 [MEDIUM] CWE-400 CVE-2026-22004: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd
CVE-2026-21998P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-21998 [MEDIUM] CWE-400 CVE-2026-21998: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2026-34278P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.452026-04-21
CVE-2026-34278 [MEDIUM] CWE-400 CVE-2026-34278: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abi
nvd
CVE-2026-34293P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.452026-04-21
CVE-2026-34293 [MEDIUM] CWE-400 CVE-2026-34293: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2026-22002P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-22002 [MEDIUM] CWE-400 CVE-2026-22002: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2026-22005P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.45≥ 8.4.0, ≤ 8.4.8+1 more2026-04-21
CVE-2026-22005 [MEDIUM] CWE-400 CVE-2026-22005: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2026-35235P4MEDIUMCVSS 4.9≥ 9.0.0, ≤ 9.6.02026-04-21
CVE-2026-35235 [MEDIUM] CWE-284 CVE-2026-35235: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2026-35234P4MEDIUMCVSS 4.9≥ 9.0.0, ≤ 9.6.02026-04-21
CVE-2026-35234 [MEDIUM] CWE-284 CVE-2026-35234: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2021-22924P4LOWCVSS 3.7≥ 5.7.0, ≤ 5.7.36≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22924 [LOW] CWE-20 CVE-2021-22924: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or c
nvd
CVE-2021-2383P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2383 [MEDIUM] CVE-2021-2383: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2342P4MEDIUMCVSS 4.9≥ 5.7.0, ≤ 5.7.34≥ 6.0.0, ≤ 8.0.252021-07-21
CVE-2021-2342 [MEDIUM] CVE-2021-2342: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd