MySQL's vulnerability footprint centers on a narrow but ubiquitously embedded database product and related server components that occupy a foundational role across web applications, enterprise systems, and cloud infrastructure. Despite the focused product scope, the vendor appears among the most prominent in the vulnerability landscape, reflecting the widespread deployment and integration dependencies of MySQL across the software supply chain. The recurring weakness classes—encompassing memory-safety issues such as buffer-boundary violations, input-validation flaws, and file-access control problems—reflect the parsing and data-handling demands of a long-lived relational database engine. Vulnerabilities affecting MySQL have a strong tendency to acquire public exploit tooling, making timely patching a priority for any organization with exposed or internet-reachable instances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mysql over time
Signals from CVEs in this vendor scope (113 CVEs).
113 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0226HIGH Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHel | Jan 10, 2008 | 7.5 | 84 | NO | YES |
CVE-2006-4305HIGH Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client. | Aug 30, 2006 | 10.0 | 82 | NO | YES |
CVE-2005-0684HIGH Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter | Apr 25, 2005 | 10.0 | 79 | NO | YES |
CVE-2004-0627HIGH The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string. | Dec 6, 2004 | 10.0 | 78 | NO | YES |
CVE-2003-0780HIGH Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a lon | Sep 22, 2003 | 9.0 | 75 | NO | YES |
CVE-2004-0835HIGH MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER | Nov 3, 2004 | 7.5 | 46 | NO | YES |
CVE-2006-1518MEDIUM Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with | May 5, 2006 | 6.5 | 44 | NO | YES |
CVE-2009-2446HIGH Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause | Jul 13, 2009 | 8.5 | 41 | NO | YES |
CVE-2006-1516MEDIUM The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a usern | May 5, 2006 | 5.0 | 40 | NO | YES |
CVE-2006-4227MEDIUM MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote | Aug 18, 2006 | 6.5 | 37 | NO | YES |
Signals from CVEs in this vendor scope (113 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mysql.
Media articles that mention a CVE ID that affects a product developed by Mysql — matched by CVE ID, not by vendor name.