CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output in org.mariadb:r2dbc-mariadb
MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariadb-java-client
MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake
MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb
MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: true`
MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side
MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)
MariaDB: FILE privilege was not checked for subqueries in the FROM clause
MariaDB: mysql_real_escape_string() incorrectly handled big5
MariaDB: path traversal in mbstream
MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions
MariaDB: wsrep SST unsafe parameter handling on the donor side
MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL
MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
MariaDB Server: MariaDB Server: Denial of Service via large packet with caching_sha2_password authentication plugin
Heap-based Buffer Overflow in MariaDB
MariaDB Server Audit Plugin Comment Handling Bypass
MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability
An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.
mariadb: MariaDB Server Crash
mariadb: MariaDB Server Crash via Item_direct_view_ref
Showing 1 to 25 CVEs · page 1 (more available)