Mysql

Vendor:

First CVE: Dec 27, 1998 · Active for 27 years

1,328
Total CVEs
More Total CVEs than 100% of tracked products
47.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mysql over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 1998
27 years ago
Most Recent CVE
Apr 21, 2026
95 days ago

CVE Severity & Scoring

Mysql1,328 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local74 (5.6%)
Network818 (61.6%)
Unknown386 (29.1%)
Physical0 (0.0%)
Adjacent Network50 (3.8%)
Attack Complexity
Low741 (55.8%)
High201 (15.1%)
Unknown386 (29.1%)
User Interaction
None862 (64.9%)
Unknown386 (29.1%)
Required80 (6.0%)
Privileges Required
Low230 (17.3%)
High655 (49.3%)
None57 (4.3%)
Unknown386 (29.1%)

Top CVEs

Signals from CVEs in this product scope (1328 CVEs).

1,328 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x
Jun 26, 20125.189NOYES
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHel
Jan 10, 20087.584NOYES
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5
Dec 30, 20097.579NOYES
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.
Sep 20, 20169.878NOYES
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earli
Apr 24, 20177.576NOYES
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a lon
Sep 22, 20039.075NOYES
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and pr
Apr 19, 20226.365NONO
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and pr
Jan 19, 20226.363NONO
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and pr
Jan 19, 20226.362NONO

Exploit Exposure

Signals from CVEs in this product scope (1328 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
0.3% of CVEs· 96th percentile
Nuclei
1 CVE
0.1% of CVEs· 96th percentile
ExploitDB
51 CVEs
3.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (1328 CVEs).

Media Mentions

Signals from CVEs in this product scope (1328 CVEs).

Top CNAs Publishing CVEs For Mysql

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3.014.90.5%00
9.0.1254.30.8%00
9.0.0264.50.8%00
8.4.514.90.5%00
8.4.0124.90.8%00
8.3.045.20.8%00
8.2.014.90.8%00
8.1.0115.21.0%00
8.0.4214.90.5%00
8.017.04.3%01
6.0.445.05.1%02
6.0.364.74.3%02
6.0.264.74.3%02
6.0.164.74.3%02
6.0.064.74.3%02
5.7.9114.92.7%00
5.7.855.82.9%00
5.7.755.82.9%00
5.7.655.82.9%00
5.7.555.82.9%00