Navicat is a database management and development tool with a narrow product footprint centered on its core database IDE and Oracle-specific variant, positioned as a widely used client for remote database administration and SQL development. The observed vulnerability surface clusters around resource-management and authentication-handling issues, particularly improper resource cleanup and unverified password-change mechanisms, which reflect the stateful nature of database connections and session management in client applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Navicat over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25653MEDIUM Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password f | Mar 30, 2026 | 6.2 | 22 | NO | NO |
CVE-2024-1193MEDIUM A vulnerability was found in Navicat 12.0.29. It has been rated as problematic. This issue affects some unknown processing of the component MySQL Conecction Handler. The manipulati | Feb 2, 2024 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Navicat.
Media articles that mention a CVE ID that affects a product developed by Navicat — matched by CVE ID, not by vendor name.