Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mariadb

First CVE: Apr 14, 2005Active for: 21 yearsTotal CVEs: 420
40.2
VTI Score
Medium

MariaDB's vulnerability footprint spans a modestly scoped but deeply embedded portfolio centered on its core relational database engine, connectors, and middleware components that serve a broad range of application stacks and deployment contexts. The recurring weakness classes across this portfolio—use-after-free conditions, SQL injection, improper locking, and code-injection flaws—reflect the memory-safety and query-processing complexity inherent to a large database system and its integration layers. Despite the substantial volume of disclosures, the vendor's exposure does not skew toward critical severity or widespread in-the-wild exploitation, allowing defenders to prioritize patch cycles based on deployment scope and network exposure rather than blanket urgency. Defenders should maintain awareness of updates across the database engine itself and its language-specific connectors, since application environments often embed multiple components from this vendor's stack. Current severity, exploitation activity, and exposure figures are shown alongside this summary.

FAUCET AI Generated
420
Total CVEs
More Total CVEs than 100% of tracked vendors
6.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mariadb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2005
21 years ago
Most Recent CVE
Jun 12, 2026
43 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (420 CVEs).

420 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-2122MEDIUM
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x
Jun 26, 20125.189NOYES
CVE-2014-0224HIGH
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
CVE-2014-0195MEDIUM
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS Clie
Jun 5, 20146.880NOYES
CVE-2009-4484HIGH
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5
Dec 30, 20097.579NOYES
CVE-2016-6662CRITICAL
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.
Sep 20, 20169.878NOYES
CVE-2022-0778HIGH
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi
Mar 15, 20227.565NONO
CVE-2014-0221MEDIUM
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (r
Jun 5, 20144.359NONO
CVE-2012-5613MEDIUM
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative
Dec 3, 20126.058NOYES
CVE-2014-3470MEDIUM
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows
Jun 5, 20144.357NONO
CVE-2018-25032HIGH
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Mar 25, 20227.556NONO
View all 420 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products420 CVEs
12%
68%
18%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local57 (13.6%)
Network183 (43.6%)
Unknown178 (42.4%)
Physical1 (0.2%)
Adjacent Network1 (0.2%)
Attack Complexity
Low190 (45.2%)
High52 (12.4%)
Unknown178 (42.4%)
User Interaction
None232 (55.2%)
Unknown178 (42.4%)
Required10 (2.4%)
Privileges Required
Low97 (23.1%)
High78 (18.6%)
None67 (16.0%)
Unknown178 (42.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (420 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
1.2% of CVEs· 97th percentile
Nuclei
1 CVE
0.2% of CVEs· 95th percentile
ExploitDB
14 CVEs
3.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mariadb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mariadb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mariadb's Products

View all 9 CNAs →

Top CWEs