Percona kayıtları
percona üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %57,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2016-6662Kavram kanıtı | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x beforeoracle · mysql · CWE-264 | Kritik9,8 | — | %67,7 | 20 Eyl 2016 |
40Planlayın | CVE-2021-27928Kavram kanıtı | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.mariadb · mariadb · CWE-94 | Yüksek7,2 | — | %38,4 | 18 Mar 2021 |
40Planlayın | CVE-2019-12301İstismar yok | The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank percona · percona server | Kritik9,8 | — | %2,0 | 23 May 2019 |
39İzleyin | CVE-2020-26542İstismar yok | An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in percona · percona server · CWE-287 | Kritik9,8 | — | %1,5 | 9 Kas 2020 |
39İzleyin | CVE-2023-34409İstismar yok | In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalizepercona · monitoring and management · CWE-22 | Kritik9,8 | — | %1,3 | 6 Haz 2023 |
39İzleyin | CVE-2026-25212Kavram kanıtı | An issue was discovered in Percona PMM before 3.7.percona · monitoring and management · CWE-250 | Kritik9,9 | — | %0,3 | 2 Nis 2026 |
38İzleyin | CVE-2020-15180İstismar yok | A flaw was found in the mysql-wsrep component of mariadb.mariadb · mariadb · CWE-20 | Kritik9,0 | — | %5,5 | 27 May 2021 |
36İzleyin | CVE-2017-15365İstismar yok | sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x befmariadb · mariadb | Yüksek8,8 | — | %3,3 | 25 Oca 2018 |
33İzleyin | CVE-2014-2029İstismar yok | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive informapercona · toolkit · CWE-200 | Yüksek8,1 | — | %2,0 | 28 Eyl 2017 |
32İzleyin | CVE-2020-10996İstismar yok | An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2.percona · xtradb cluster · CWE-798 | Yüksek8,1 | — | %1,5 | 27 Nis 2020 |
31İzleyin | CVE-2020-7920İstismar yok | pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.percona · monitoring and management · CWE-835 | Yüksek7,5 | — | %2,1 | 6 Şub 2020 |
31İzleyin | CVE-2022-25834İstismar yok | In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected cpercona · xtrabackup · CWE-77 | Yüksek7,8 | — | %0,5 | 6 Haz 2023 |
30İzleyin | CVE-2022-34968İstismar yok | An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL quepercona · percona server · CWE-89 | Yüksek7,5 | — | %1,0 | 2 Ağu 2022 |
29İzleyin | CVE-2016-6663Kavram kanıtı | Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x oracle · mysql · CWE-362 | Yüksek7,0 | — | %4,3 | 13 Ara 2016 |
29İzleyin | CVE-2016-6664Kavram kanıtı | mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.oracle · mysql · CWE-59 | Yüksek7,0 | — | %3,0 | 13 Ara 2016 |
26İzleyin | CVE-2022-26944İstismar yok | Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.percona · xtrabackup | Orta6,5 | — | %1,0 | 2 Haz 2022 |
26İzleyin | CVE-2020-10997İstismar yok | Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output.percona · xtrabackup · CWE-200 | Orta6,5 | — | %1,0 | 27 Nis 2020 |
23İzleyin | CVE-2015-1027İstismar yok | The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attackspercona · toolkit · CWE-200 | Orta5,9 | — | %1,2 | 28 Eyl 2017 |
23İzleyin | CVE-2016-6225İstismar yok | xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, whichpercona · xtrabackup · CWE-326 | Orta5,9 | — | %1,1 | 23 Mar 2017 |
20İzleyin | CVE-2024-7701İstismar yok | Misuse of SHA256 to create an encryption keypercona · toolkit · CWE-916 | Orta5,1 | — | %0,2 | 15 Ara 2024 |
8İzleyin | CVE-2013-6394İstismar yok | Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cpercona · xtrabackup · CWE-310 | Düşük2,1 | — | %0,4 | 13 Ara 2013 |
- CVE-2016-666259Planlayın
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
KritikCVSS 9,8Kavram kanıtıEPSS %68oracle · mysql20 Eyl 2016
- CVE-2021-2792840Planlayın
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.
YüksekCVSS 7,2Kavram kanıtıEPSS %38mariadb · mariadb18 Mar 2021
- CVE-2019-1230140Planlayın
The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank
KritikCVSS 9,8İstismar yokEPSS %2percona · percona server23 May 2019
- CVE-2020-2654239İzleyin
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in
KritikCVSS 9,8İstismar yokEPSS %2percona · percona server9 Kas 2020
- CVE-2023-3440939İzleyin
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize
KritikCVSS 9,8İstismar yokEPSS %1percona · monitoring and management6 Haz 2023
- CVE-2026-2521239İzleyin
An issue was discovered in Percona PMM before 3.7.
KritikCVSS 9,9Kavram kanıtıEPSS %0percona · monitoring and management2 Nis 2026
- CVE-2020-1518038İzleyin
A flaw was found in the mysql-wsrep component of mariadb.
KritikCVSS 9,0İstismar yokEPSS %6mariadb · mariadb27 May 2021
- CVE-2017-1536536İzleyin
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x bef
YüksekCVSS 8,8İstismar yokEPSS %3mariadb · mariadb25 Oca 2018
- CVE-2014-202933İzleyin
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive informa
YüksekCVSS 8,1İstismar yokEPSS %2percona · toolkit28 Eyl 2017
- CVE-2020-1099632İzleyin
An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2.
YüksekCVSS 8,1İstismar yokEPSS %2percona · xtradb cluster27 Nis 2020
- CVE-2020-792031İzleyin
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
YüksekCVSS 7,5İstismar yokEPSS %2percona · monitoring and management6 Şub 2020
- CVE-2022-2583431İzleyin
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected c
YüksekCVSS 7,8İstismar yokEPSS %0percona · xtrabackup6 Haz 2023
- CVE-2022-3496830İzleyin
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL que
YüksekCVSS 7,5İstismar yokEPSS %1percona · percona server2 Ağu 2022
- CVE-2016-666329İzleyin
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x
YüksekCVSS 7,0Kavram kanıtıEPSS %4oracle · mysql13 Ara 2016
- CVE-2016-666429İzleyin
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.
YüksekCVSS 7,0Kavram kanıtıEPSS %3oracle · mysql13 Ara 2016
- CVE-2022-2694426İzleyin
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.
OrtaCVSS 6,5İstismar yokEPSS %1percona · xtrabackup2 Haz 2022
- CVE-2020-1099726İzleyin
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output.
OrtaCVSS 6,5İstismar yokEPSS %1percona · xtrabackup27 Nis 2020
- CVE-2015-102723İzleyin
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks
OrtaCVSS 5,9İstismar yokEPSS %1percona · toolkit28 Eyl 2017
- CVE-2016-622523İzleyin
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which
OrtaCVSS 5,9İstismar yokEPSS %1percona · xtrabackup23 Mar 2017
- CVE-2024-770120İzleyin
Misuse of SHA256 to create an encryption key
OrtaCVSS 5,1İstismar yokEPSS %0percona · toolkit15 Ara 2024
- CVE-2013-63948İzleyin
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat c
DüşükCVSS 2,1İstismar yokEPSS %0percona · xtrabackup13 Ara 2013