Mysql Server
Vendor:
First CVE: Feb 6, 2019 · Active for 7 years
278
Total CVEs
More Total CVEs than 100% of tracked products
34.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mysql Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2019
7 years ago
Most Recent CVE
Jun 16, 2026
39 days ago
CVE Severity & Scoring
Mysql Server278 CVEs
85%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (2.5%)
Network270 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low234 (84.2%)
High44 (15.8%)
Unknown0 (0.0%)
User Interaction
None268 (96.4%)
Unknown0 (0.0%)
Required10 (3.6%)
Privileges Required
Low42 (15.1%)
High196 (70.5%)
None40 (14.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (278 CVEs).
278 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21351CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arb | Mar 23, 2021 | 9.1 | 82 | NO | YES |
CVE-2021-3711CRITICAL In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim | Aug 24, 2021 | 9.8 | 79 | NO | NO |
CVE-2021-21344CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu | Mar 23, 2021 | 9.8 | 73 | NO | NO |
CVE-2022-1292HIGH The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom | May 3, 2022 | 7.3 | 68 | NO | NO |
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2021-3712HIGH ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This cont | Aug 24, 2021 | 7.4 | 53 | NO | NO |
CVE-2021-23840HIGH Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable | Feb 16, 2021 | 7.5 | 53 | NO | NO |
CVE-2019-5436HIGH A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | May 28, 2019 | 7.8 | 46 | NO | NO |
CVE-2021-2429MEDIUM Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows | Jul 21, 2021 | 5.9 | 42 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (278 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.4% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (278 CVEs).
Media Mentions
Signals from CVEs in this product scope (278 CVEs).
Top CNAs Publishing CVEs For Mysql Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.0 | 1 | 4.9 | 0.5% | 0 | 0 |
| 9.0.0 | 3 | 4.9 | 0.7% | 0 | 0 |
| 8.4.1 | 1 | 4.9 | 0.9% | 0 | 0 |
| 8.4.0 | 2 | 4.9 | 0.9% | 0 | 0 |
| 8.3.0 | 2 | 4.5 | 0.8% | 0 | 0 |
| 8.2.0 | 7 | 4.8 | 1.1% | 0 | 0 |
| 8.1.0 | 5 | 4.8 | 1.0% | 0 | 0 |
| 8.0.38 | 1 | 4.9 | 0.9% | 0 | 0 |
| 5.7.36 | 1 | 6.1 | 2.2% | 0 | 0 |