Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
MySQL Comunity Edition Number Of NVD 1286 CRITICAL 7 HIGH 76 MEDIUM 1021 LOW 173
URL https://www.mysql.com/jp/products/community/
Explanation It is an open source, free relational database management system (RDBMS) that is used around the world.
Its performance and functionality are sufficient for commercial use, and it is used for more than just the backend of web applications.
With the merger of Sun Microsystems into Oracle, it was feared that it might no longer be available for free commercial use, but it is still available under the GPL license for cloud backend and internal use.
It is still used as a backend for many web applications (WordPress, Facebook, etc.).

Since it has been merged with Oracle, the development speed has been increased, and the latest version is a higher performance, higher functionality relational database management system (RDBMS).

You can also get technical support by paying a support fee.

It has become one of the open source combinations called LAMP (Linux, Apache, MySQL [MariaDB], PHP).
Tag
  • GPL v2
  • オープンソース
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://dev.mysql.com/downloads/mysql/
2 https://endoflife.software/applications/databases/mysql

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
421 MySQL 8.1 8.1.0 July 18, 2023 July 18, 2023 0 0 0 0
422 New!! MySQL 8 8.0.45 Jan. 20, 2029 April 19, 2018 April 19, 2026 4 25 565 54
423 MySQL 5.7 5.7.44 Oct. 25, 2023 Jan. 21, 2015 Oct. 21, 2023 6 26 356 33
424 MySQL 5.6 5.6.51 Jan. 20, 2021 Feb. 5, 2013 Feb. 5, 2021 5 28 359 90
425 MySQL 5.5 5.5.62 Oct. 22, 2018 Oct. 3, 2010 Jan. 3, 2018 3 26 347 92
426 MySQL 7.6 7.6.9 Jan. 1, 2000 0 2 40 16
427 MySQL 7.5 7.5.9 Jan. 1, 2000 0 2 39 15
428 MySQL 7.4 7.4.9 Jan. 1, 2000 0 2 38 14
429 MySQL 7.3 7.3.9 Jan. 1, 2000 0 2 13 0
430 MySQL 7.2 7.2.35 Jan. 1, 2000 0 0 12 0
431 MySQL 7.1 7.1.37 Jan. 1, 2000 0 0 12 0
432 MySQL 6.0 6.0.5 Jan. 1, 2000 0 0 18 1
433 MySQL 5.4 5.4.3 Jan. 1, 2000 0 3 132 41
434 MySQL 5.3 5.3.9 Jan. 1, 2000 0 3 133 41
435 MySQL 5.1 5.1.9 Dec. 31, 2013 0 10 221 60
436 MySQL 5.0 5.0.96 Jan. 9, 2012 0 8 168 54
437 MySQL 4.1 4.1.9 Jan. 1, 2000 0 5 136 47
438 MySQL 4.0 4.0.9 Jan. 1, 2000 0 11 139 48
439 MySQL 3.2 3.20.32a Jan. 1, 2000 0 10 128 45
440 MySQL 1.5 1.5.1 Jan. 1, 2000 0 6 127 44
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
421 4.9
4.0
MEDIUM
Network
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability al… NVD-CWE-noinfo
CVE-2020-14540 cpe:2.3:a:oracle:mysql:*:* 5.7.0
8.0.0
5.7.30
8.0.20


2024-11-21 14:03
2020-07-16
Show GitHub Exploit DB Packet Storm
422 6.5
4.0
MEDIUM
Network
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily expl… NVD-CWE-noinfo
CVE-2020-14539 cpe:2.3:a:oracle:mysql:*:* 5.6.0
5.7.0
8.0.0
5.6.48
5.7.30
8.0.20




2024-11-21 14:03
2020-07-16
Show GitHub Exploit DB Packet Storm
423 5.5
2.1
MEDIUM
Local
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. CWE-787
 Out-of-bounds Write
CVE-2020-15358 cpe:2.3:a:oracle:mysql:*:* 8.0.22 2024-11-21 14:05
2020-06-27
Show GitHub Exploit DB Packet Storm
424 7.5
5.0
HIGH
Network
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a… - CVE-2020-11080 cpe:2.3:a:oracle:mysql:*:* 8.0.0
7.6.0
7.3.0
7.4.0
7.5.0
8.0.21
7.6.15
7.3.30
7.4.29
7.5.19








2024-11-21 13:56
2020-06-4
Show GitHub Exploit DB Packet Storm
425 7.5
5.0
HIGH
Network
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat… CWE-476
 NULL Pointer Dereference
CVE-2020-1967 cpe:2.3:a:oracle:mysql:*:* 5.7.0
8.0.0
5.7.30
8.0.20
5.6.48




2024-11-21 14:11
2020-04-21
Show GitHub Exploit DB Packet Storm
426 4.4
3.5
MEDIUM
Network
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privil… NVD-CWE-noinfo
CVE-2020-2930 cpe:2.3:a:oracle:mysql:*:* 8.0.0 8.0.19 2024-11-21 14:26
2020-04-15
Show GitHub Exploit DB Packet Storm
427 4.9
4.0
MEDIUM
Network
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privi… NVD-CWE-noinfo
CVE-2020-2928 cpe:2.3:a:oracle:mysql:*:* 8.0.0 8.0.19 2024-11-21 14:26
2020-04-15
Show GitHub Exploit DB Packet Storm
428 4.4
3.5
MEDIUM
Network
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability all… NVD-CWE-noinfo
CVE-2020-2926 cpe:2.3:a:oracle:mysql:*:* 8.0.0 8.0.19 2024-11-21 14:26
2020-04-15
Show GitHub Exploit DB Packet Storm
429 4.9
4.0
MEDIUM
Network
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged a… NVD-CWE-noinfo
CVE-2020-2925 cpe:2.3:a:oracle:mysql:*:* 8.0.0 8.0.19 2024-11-21 14:26
2020-04-15
Show GitHub Exploit DB Packet Storm
430 4.9
4.0
MEDIUM
Network
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privi… NVD-CWE-noinfo
CVE-2020-2924 cpe:2.3:a:oracle:mysql:*:* 8.0.0 8.0.19 2024-11-21 14:26
2020-04-15
Show GitHub Exploit DB Packet Storm