<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – MariaDB (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/mariadb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mariadb-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – MariaDB (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-48188 – An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48188</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48188</strong></p>
  <p>An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode.  This issue affects OTRS:     *  7.0.X   *  8.0.X   *  2023.X   *  2024.X   *  2025.X   *  2026…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46446 – SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46446</guid>
    <pubDate>Thu, 14 May 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46446</strong></p>
  <p>SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47091 – Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk &lt;2.4.0p2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47091</guid>
    <pubDate>Wed, 13 May 2026 10:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47091</strong></p>
  <p>Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MySQL' or 'MariaDB' (or with write access to a binary referenced by such a service) to execute arbitrary code in the context of the Checkmk agent service, which typically runs as SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40887 – Vendure is an open-source headless commerce platform. Starting in version 1.7.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40887</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40887</strong></p>
  <p>Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the dat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32710 – MariaDB server is a community developed fork of MySQL server. An authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32710</guid>
    <pubDate>Fri, 20 Mar 2026 19:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32710</strong></p>
  <p>MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab enviro…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47761 – MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47761</guid>
    <pubDate>Thu, 15 Jan 2026 16:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47761</strong></p>
  <p>MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which will execute with system privileges when the computer restarts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13699 – MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13699</guid>
    <pubDate>Tue, 23 Dec 2025 22:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13699</strong></p>
  <p>MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the handling of view names.…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67509 – Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67509</guid>
    <pubDate>Wed, 10 Dec 2025 23:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67509</strong></p>
  <p>Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass.  MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INT…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59681 – An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59681</guid>
    <pubDate>Wed, 01 Oct 2025 19:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59681</strong></p>
  <p>An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to these methods (on MySQL and MariaDB).</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56404 – An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56404</guid>
    <pubDate>Wed, 10 Sep 2025 14:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56404</strong></p>
  <p>An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26785 – MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26785</guid>
    <pubDate>Thu, 17 Oct 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26785</strong></p>
  <p>MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5456 – A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5456</guid>
    <pubDate>Tue, 05 Mar 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5456</strong></p>
  <p>A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27295 – Directus is a real-time API and App dashboard for managing SQL database content...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27295</guid>
    <pubDate>Fri, 01 Mar 2024 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27295</strong></p>
  <p>Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar email address as the victim with a one or more characters changed to use accents. This is due to the fact that by default MySQL/MariaDB are configured fo…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52082 – Lychee is a free photo-management tool.  Prior to 5.0.2, Lychee is vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52082</guid>
    <pubDate>Thu, 28 Dec 2023 16:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52082</strong></p>
  <p>Lychee is a free photo-management tool.  Prior to 5.0.2, Lychee is vulnerable to an SQL injection on any binding when using mysql/mariadb. This injection is only active for users with the `.env` settings set to DB_LOG_SQL=true and DB_LOG_SQL_EXPLAIN=true. The defaults settings of Lychee are safe.  The patch is provided on version 5.0.2.  To work around this issue, disable SQL EXPLAIN logging.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5157 – A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 456...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5157</guid>
    <pubDate>Wed, 27 Sep 2023 15:19:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5157</strong></p>
  <p>A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26567 – Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26567</guid>
    <pubDate>Wed, 26 Apr 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26567</strong></p>
  <p>Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39267 – Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39267</guid>
    <pubDate>Wed, 19 Oct 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39267</strong></p>
  <p>Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field in the request header. This issue has been patched in 1.8.8-release. There are no…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39219 – Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39219</guid>
    <pubDate>Mon, 26 Sep 2022 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39219</strong></p>
  <p>Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are cur…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32091 – MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32091</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32091</strong></p>
  <p>MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32089 – MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32089</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32089</strong></p>
  <p>MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32088 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32088</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32088</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32087 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32087</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32087</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32086 – MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32086</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32086</strong></p>
  <p>MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32085 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32085</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32085</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32084 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32084</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32084</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32083 – MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32083</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32083</strong></p>
  <p>MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32082 – MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table-&gt;...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32082</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32082</strong></p>
  <p>MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32081 – MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32081</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32081</strong></p>
  <p>MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27457 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27457</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27457</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27456 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27456</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27456</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27455 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27455</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27455</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27452 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27452</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27452</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27451 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27451</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27451</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27449 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27449</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27449</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27448 – There is an Assertion failure in MariaDB Server v10.9 and below via 'node-&gt;pcur-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27448</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27448</strong></p>
  <p>There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27447 – MariaDB Server v10.9 and below was discovered to contain a use-after-free via th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27447</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27447</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27446 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27446</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27446</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27445 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27445</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27445</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27444 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27444</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27444</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27387 – MariaDB Server v10.7 and below was discovered to contain a global buffer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27387</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27387</strong></p>
  <p>MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27386 – MariaDB Server v10.7 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27386</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27386</strong></p>
  <p>MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27385 – An issue in the component Used_tables_and_const_cache::used_tables_and_const_cac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27385</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27385</strong></p>
  <p>An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27384 – An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27384</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27384</strong></p>
  <p>An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27383 – MariaDB Server v10.6 and below was discovered to contain an use-after-free in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27383</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27383</strong></p>
  <p>MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27382 – MariaDB Server v10.7 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27382</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27382</strong></p>
  <p>MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27381 – An issue in the component Field::set_default of MariaDB Server v10.6 and below w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27381</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27381</strong></p>
  <p>An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27380 – An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27380</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27380</strong></p>
  <p>An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27379 – An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27379</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27379</strong></p>
  <p>An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27378 – An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27378</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27378</strong></p>
  <p>An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27377 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27377</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27377</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27376 – MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27376</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27376</strong></p>
  <p>MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24052 – MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24052</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24052</strong></p>
  <p>MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-suppli…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24051 – MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24051</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24051</strong></p>
  <p>MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24050 – MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24050</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24050</strong></p>
  <p>MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24048 – MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24048</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24048</strong></p>
  <p>MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-suppl…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-46669 – MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46669</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-46669</strong></p>
  <p>MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21664 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21664</guid>
    <pubDate>Thu, 06 Jan 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21664</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21662 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21662</guid>
    <pubDate>Thu, 06 Jan 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21662</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go ba…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21661 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21661</guid>
    <pubDate>Thu, 06 Jan 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21661</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37.…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41679 – A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41679</guid>
    <pubDate>Tue, 30 Nov 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41679</strong></p>
  <p>A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41678 – A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41678</guid>
    <pubDate>Tue, 30 Nov 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41678</strong></p>
  <p>A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41677 – A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41677</guid>
    <pubDate>Tue, 30 Nov 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41677</strong></p>
  <p>A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39202 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39202</guid>
    <pubDate>Thu, 09 Sep 2021 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39202</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This has been patched in WordPress 5.8. It was only present during the testing/beta ph…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39201 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39201</guid>
    <pubDate>Thu, 09 Sep 2021 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39201</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permission to post `unfiltered_html`. ### Patches This has been patched in WordPress…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-39379 – A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is bein...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39379</guid>
    <pubDate>Wed, 01 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-39379</strong></p>
  <p>A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-39378 – A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is bein...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39378</guid>
    <pubDate>Wed, 01 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-39378</strong></p>
  <p>A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-39377 – A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is bein...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39377</guid>
    <pubDate>Wed, 01 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-39377</strong></p>
  <p>A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-40353 – A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40353</guid>
    <pubDate>Wed, 01 Sep 2021 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-40353</strong></p>
  <p>A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15180 – A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitiza...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15180</guid>
    <pubDate>Thu, 27 May 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15180</strong></p>
  <p>A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 1…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29625 – Adminer is open-source database management software. A cross-site scripting vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29625</guid>
    <pubDate>Wed, 19 May 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29625</strong></p>
  <p>Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled). In…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27928 – A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27928</guid>
    <pubDate>Fri, 19 Mar 2021 03:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27928</strong></p>
  <p>A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this do…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28912 – With MariaDB running on Windows, when local clients connect to the server over n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28912</guid>
    <pubDate>Thu, 24 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28912</strong></p>
  <p>With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected use…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13249 – libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13249</guid>
    <pubDate>Wed, 20 May 2020 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13249</strong></p>
  <p>libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19346 – An insecure modification vulnerability in the /etc/passwd file was found in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19346</guid>
    <pubDate>Thu, 02 Apr 2020 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19346</strong></p>
  <p>An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7221 – mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7221</guid>
    <pubDate>Tue, 04 Feb 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7221</strong></p>
  <p>mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10748 – Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10748</guid>
    <pubDate>Tue, 29 Oct 2019 19:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10748</strong></p>
  <p>Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10752 – Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10752</guid>
    <pubDate>Thu, 17 Oct 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10752</strong></p>
  <p>Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16046 – `mariadb` was a malicious module published with the intent to hijack environment...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16046</guid>
    <pubDate>Mon, 04 Jun 2018 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16046</strong></p>
  <p>`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-506</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-10554 – sequelize is an Object-relational mapping, or a middleman to convert things from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10554</guid>
    <pubDate>Thu, 31 May 2018 20:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-10554</strong></p>
  <p>sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping, even though SQLite uses Postgres escaping.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-10553 – sequelize is an Object-relational mapping, or a middleman to convert things from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10553</guid>
    <pubDate>Thu, 31 May 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-10553</strong></p>
  <p>sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-10550 – sequelize is an Object-relational mapping, or a middleman to convert things from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10550</guid>
    <pubDate>Thu, 31 May 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-10550</strong></p>
  <p>sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements. This affects sequelize 3.16.0 and earlier.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10556 – sequelize is an Object-relational mapping, or a middleman to convert things from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10556</guid>
    <pubDate>Tue, 29 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10556</strong></p>
  <p>sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microsoft SQL Server there is an issue where arrays are treated as strings and improperly escaped. This causes potential SQL injection in sequelize 3.19.3 and earlier, where a malicious user could put `["tes…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15365 – sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15365</guid>
    <pubDate>Thu, 25 Jan 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15365</strong></p>
  <p>sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15945 – The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/perc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15945</guid>
    <pubDate>Fri, 27 Oct 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15945</strong></p>
  <p>The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-3302 – Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3302</guid>
    <pubDate>Sun, 12 Feb 2017 04:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-3302</strong></p>
  <p>Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6664 – mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6664</guid>
    <pubDate>Tue, 13 Dec 2016 21:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6664</strong></p>
  <p>mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privilege…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6663 – Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6663</guid>
    <pubDate>Tue, 13 Dec 2016 21:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6663</strong></p>
  <p>Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17 allows local users with…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6653 – The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-relea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6653</guid>
    <pubDate>Thu, 06 Oct 2016 10:59:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6653</strong></p>
  <p>The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information by reading syslog messages, as demonstrated by cleartext credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6662 – Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6662</guid>
    <pubDate>Tue, 20 Sep 2016 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6662</strong></p>
  <p>Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: thi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3477 – Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3477</guid>
    <pubDate>Thu, 21 Jul 2016 10:12:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3477</strong></p>
  <p>Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-0546 – Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0546</guid>
    <pubDate>Thu, 21 Jan 2016 03:01:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-0546</strong></p>
  <p>Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that thes…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-0001 – Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0001</guid>
    <pubDate>Fri, 31 Jan 2014 23:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-0001</strong></p>
  <p>Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0001">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
