Mysql
Vendor:
First CVE: Dec 27, 1998 · Active for 27 years
1,328
Total CVEs
More Total CVEs than 100% of tracked products
47.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mysql over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 1998
27 years ago
Most Recent CVE
Apr 21, 2026
95 days ago
CVE Severity & Scoring
Mysql1,328 CVEs
14%
80%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local74 (5.6%)
Network818 (61.6%)
Unknown386 (29.1%)
Physical0 (0.0%)
Adjacent Network50 (3.8%)
Attack Complexity
Low741 (55.8%)
High201 (15.1%)
Unknown386 (29.1%)
User Interaction
None862 (64.9%)
Unknown386 (29.1%)
Required80 (6.0%)
Privileges Required
Low230 (17.3%)
High655 (49.3%)
None57 (4.3%)
Unknown386 (29.1%)
Top CVEs
Signals from CVEs in this product scope (1328 CVEs).
1,328 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2122MEDIUM sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x | Jun 26, 2012 | 5.1 | 89 | NO | YES |
CVE-2008-0226HIGH Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHel | Jan 10, 2008 | 7.5 | 84 | NO | YES |
CVE-2009-4484HIGH Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5 | Dec 30, 2009 | 7.5 | 79 | NO | YES |
CVE-2016-6662CRITICAL Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5. | Sep 20, 2016 | 9.8 | 78 | NO | YES |
CVE-2017-3599HIGH Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earli | Apr 24, 2017 | 7.5 | 76 | NO | YES |
CVE-2003-0780HIGH Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a lon | Sep 22, 2003 | 9.0 | 75 | NO | YES |
CVE-2020-5398HIGH In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R | Jan 17, 2020 | 7.5 | 73 | NO | NO |
CVE-2022-21489MEDIUM Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and pr | Apr 19, 2022 | 6.3 | 65 | NO | NO |
CVE-2022-21279MEDIUM Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and pr | Jan 19, 2022 | 6.3 | 63 | NO | NO |
CVE-2022-21280MEDIUM Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and pr | Jan 19, 2022 | 6.3 | 62 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (1328 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
0.3% of CVEs· 96th percentile
Nuclei
1 CVE
0.1% of CVEs· 96th percentile
ExploitDB
51 CVEs
3.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (1328 CVEs).
Media Mentions
Signals from CVEs in this product scope (1328 CVEs).
Top CNAs Publishing CVEs For Mysql
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.3.0 | 1 | 4.9 | 0.5% | 0 | 0 |
| 9.0.1 | 25 | 4.3 | 0.8% | 0 | 0 |
| 9.0.0 | 26 | 4.5 | 0.8% | 0 | 0 |
| 8.4.5 | 1 | 4.9 | 0.5% | 0 | 0 |
| 8.4.0 | 12 | 4.9 | 0.8% | 0 | 0 |
| 8.3.0 | 4 | 5.2 | 0.8% | 0 | 0 |
| 8.2.0 | 1 | 4.9 | 0.8% | 0 | 0 |
| 8.1.0 | 11 | 5.2 | 1.0% | 0 | 0 |
| 8.0.42 | 1 | 4.9 | 0.5% | 0 | 0 |
| 8.0 | 1 | 7.0 | 4.3% | 0 | 1 |
| 6.0.4 | 4 | 5.0 | 5.1% | 0 | 2 |
| 6.0.3 | 6 | 4.7 | 4.3% | 0 | 2 |
| 6.0.2 | 6 | 4.7 | 4.3% | 0 | 2 |
| 6.0.1 | 6 | 4.7 | 4.3% | 0 | 2 |
| 6.0.0 | 6 | 4.7 | 4.3% | 0 | 2 |
| 5.7.9 | 11 | 4.9 | 2.7% | 0 | 0 |
| 5.7.8 | 5 | 5.8 | 2.9% | 0 | 0 |
| 5.7.7 | 5 | 5.8 | 2.9% | 0 | 0 |
| 5.7.6 | 5 | 5.8 | 2.9% | 0 | 0 |
| 5.7.5 | 5 | 5.8 | 2.9% | 0 | 0 |