Mysql Connectors
Vendor:
First CVE: Apr 24, 2017 · Active for 9 years
32
Total CVEs
More Total CVEs than 97% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mysql Connectors over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2017
9 years ago
Most Recent CVE
Jul 21, 2026
7 days ago
CVE Severity & Scoring
Mysql Connectors32 CVEs
44%
53%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (50.0%)
High16 (50.0%)
Unknown0 (0.0%)
User Interaction
None24 (75.0%)
Unknown0 (0.0%)
Required8 (25.0%)
Privileges Required
Low8 (25.0%)
High4 (12.5%)
None20 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3711CRITICAL In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim | Aug 24, 2021 | 9.8 | 79 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2021-3712HIGH ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This cont | Aug 24, 2021 | 7.4 | 53 | NO | NO |
CVE-2020-1967HIGH Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand | Apr 21, 2020 | 7.5 | 51 | NO | NO |
CVE-2022-21824HIGH Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing | Feb 24, 2022 | 8.2 | 39 | NO | NO |
CVE-2021-3450HIGH The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1. | Mar 25, 2021 | 7.4 | 34 | NO | NO |
CVE-2026-60193HIGH Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability | Jul 21, 2026 | 8.5 | 32 | NO | NO |
CVE-2026-60192HIGH Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability | Jul 21, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-60586HIGH Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allo | Jul 21, 2026 | 7.7 | 30 | NO | NO |
CVE-2026-60317HIGH Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability | Jul 21, 2026 | 7.4 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (32 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (32 CVEs).
Media Mentions
Signals from CVEs in this product scope (32 CVEs).
Top CNAs Publishing CVEs For Mysql Connectors
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.27 | 1 | 6.1 | 2.2% | 0 | 0 |