Percona records
21 published records for vendor percona.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-310 Cryptographic Issues1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2016-6662Proof of concept | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x beforeoracle · mysql · CWE-264 | Critical9.8 | — | 67.7% | Sep 20, 2016 |
40Plan | CVE-2021-27928Proof of concept | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.mariadb · mariadb · CWE-94 | High7.2 | — | 38.4% | Mar 18, 2021 |
40Plan | CVE-2019-12301No exploit | The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank percona · percona server | Critical9.8 | — | 2.0% | May 23, 2019 |
39Monitor | CVE-2020-26542No exploit | An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in percona · percona server · CWE-287 | Critical9.8 | — | 1.5% | Nov 9, 2020 |
39Monitor | CVE-2023-34409No exploit | In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalizepercona · monitoring and management · CWE-22 | Critical9.8 | — | 1.3% | Jun 6, 2023 |
39Monitor | CVE-2026-25212Proof of concept | An issue was discovered in Percona PMM before 3.7.percona · monitoring and management · CWE-250 | Critical9.9 | — | 0.3% | Apr 2, 2026 |
38Monitor | CVE-2020-15180No exploit | A flaw was found in the mysql-wsrep component of mariadb.mariadb · mariadb · CWE-20 | Critical9.0 | — | 5.5% | May 27, 2021 |
36Monitor | CVE-2017-15365No exploit | sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x befmariadb · mariadb | High8.8 | — | 3.3% | Jan 25, 2018 |
33Monitor | CVE-2014-2029No exploit | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive informapercona · toolkit · CWE-200 | High8.1 | — | 2.0% | Sep 28, 2017 |
32Monitor | CVE-2020-10996No exploit | An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2.percona · xtradb cluster · CWE-798 | High8.1 | — | 1.5% | Apr 27, 2020 |
31Monitor | CVE-2020-7920No exploit | pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.percona · monitoring and management · CWE-835 | High7.5 | — | 2.1% | Feb 6, 2020 |
31Monitor | CVE-2022-25834No exploit | In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected cpercona · xtrabackup · CWE-77 | High7.8 | — | 0.5% | Jun 6, 2023 |
30Monitor | CVE-2022-34968No exploit | An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL quepercona · percona server · CWE-89 | High7.5 | — | 1.0% | Aug 2, 2022 |
29Monitor | CVE-2016-6663Proof of concept | Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x oracle · mysql · CWE-362 | High7.0 | — | 4.3% | Dec 13, 2016 |
29Monitor | CVE-2016-6664Proof of concept | mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.oracle · mysql · CWE-59 | High7.0 | — | 3.0% | Dec 13, 2016 |
26Monitor | CVE-2020-10997No exploit | Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output.percona · xtrabackup · CWE-200 | Medium6.5 | — | 1.0% | Apr 27, 2020 |
26Monitor | CVE-2022-26944No exploit | Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.percona · xtrabackup | Medium6.5 | — | 0.9% | Jun 2, 2022 |
23Monitor | CVE-2015-1027No exploit | The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attackspercona · toolkit · CWE-200 | Medium5.9 | — | 1.2% | Sep 28, 2017 |
23Monitor | CVE-2016-6225No exploit | xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, whichpercona · xtrabackup · CWE-326 | Medium5.9 | — | 1.1% | Mar 23, 2017 |
20Monitor | CVE-2024-7701No exploit | Misuse of SHA256 to create an encryption keypercona · toolkit · CWE-916 | Medium5.1 | — | 0.2% | Dec 15, 2024 |
8Monitor | CVE-2013-6394No exploit | Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cpercona · xtrabackup · CWE-310 | Low2.1 | — | 0.4% | Dec 13, 2013 |
- CVE-2016-666259Plan
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
CriticalCVSS 9.8Proof of conceptEPSS 68%oracle · mysqlSep 20, 2016
- CVE-2021-2792840Plan
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.
HighCVSS 7.2Proof of conceptEPSS 38%mariadb · mariadbMar 18, 2021
- CVE-2019-1230140Plan
The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank
CriticalCVSS 9.8No exploitEPSS 2%percona · percona serverMay 23, 2019
- CVE-2020-2654239Monitor
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in
CriticalCVSS 9.8No exploitEPSS 2%percona · percona serverNov 9, 2020
- CVE-2023-3440939Monitor
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize
CriticalCVSS 9.8No exploitEPSS 1%percona · monitoring and managementJun 6, 2023
- CVE-2026-2521239Monitor
An issue was discovered in Percona PMM before 3.7.
CriticalCVSS 9.9Proof of conceptEPSS 0%percona · monitoring and managementApr 2, 2026
- CVE-2020-1518038Monitor
A flaw was found in the mysql-wsrep component of mariadb.
CriticalCVSS 9.0No exploitEPSS 6%mariadb · mariadbMay 27, 2021
- CVE-2017-1536536Monitor
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x bef
HighCVSS 8.8No exploitEPSS 3%mariadb · mariadbJan 25, 2018
- CVE-2014-202933Monitor
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive informa
HighCVSS 8.1No exploitEPSS 2%percona · toolkitSep 28, 2017
- CVE-2020-1099632Monitor
An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2.
HighCVSS 8.1No exploitEPSS 2%percona · xtradb clusterApr 27, 2020
- CVE-2020-792031Monitor
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
HighCVSS 7.5No exploitEPSS 2%percona · monitoring and managementFeb 6, 2020
- CVE-2022-2583431Monitor
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected c
HighCVSS 7.8No exploitEPSS 0%percona · xtrabackupJun 6, 2023
- CVE-2022-3496830Monitor
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL que
HighCVSS 7.5No exploitEPSS 1%percona · percona serverAug 2, 2022
- CVE-2016-666329Monitor
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x
HighCVSS 7.0Proof of conceptEPSS 4%oracle · mysqlDec 13, 2016
- CVE-2016-666429Monitor
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.
HighCVSS 7.0Proof of conceptEPSS 3%oracle · mysqlDec 13, 2016
- CVE-2020-1099726Monitor
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output.
MediumCVSS 6.5No exploitEPSS 1%percona · xtrabackupApr 27, 2020
- CVE-2022-2694426Monitor
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.
MediumCVSS 6.5No exploitEPSS 1%percona · xtrabackupJun 2, 2022
- CVE-2015-102723Monitor
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks
MediumCVSS 5.9No exploitEPSS 1%percona · toolkitSep 28, 2017
- CVE-2016-622523Monitor
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which
MediumCVSS 5.9No exploitEPSS 1%percona · xtrabackupMar 23, 2017
- CVE-2024-770120Monitor
Misuse of SHA256 to create an encryption key
MediumCVSS 5.1No exploitEPSS 0%percona · toolkitDec 15, 2024
- CVE-2013-63948Monitor
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat c
LowCVSS 2.1No exploitEPSS 0%percona · xtrabackupDec 13, 2013