📦

mysql

Vendor: mysql

Actively Exploited 0 CISA KEV List
PoC / Exploits 57 Code Available
Total RCEs 19 Remote Access
Total CVEs 1384 Total Indexed
Avg. EPSS 3.48% Exploit Prob.
Latest CVE CVE-2026-21964 Jan 20

Security Vulnerability Index

Page 134 / 139
4.6 CVSS

WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.

EPSS: 0.61%
4.6 CVSS
CVE-2001-0407
Exploit Found

Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).

EPSS: 2.22%
7.5 CVSS

Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.

EPSS: 9.63%
7.5 CVSS

Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.

EPSS: 11.29%
7.5 CVSS
CVE-2001-1274
Exploit Found

Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

EPSS: 5.43%
7.2 CVSS

MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.

EPSS: 0.53%
7.2 CVSS

MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.

EPSS: 1.93%
7.5 CVSS

MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.

EPSS: 4.74%
6.4 CVSS
CVE-2000-0045
Exploit Found

MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.

EPSS: 6.99%