MariaDB / Server
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48165 | MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side | CRITICAL | 9.1 | Jun 12, 2026 |
| CVE-2026-48163 | MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync) | CRITICAL | 9.1 | Jun 12, 2026 |
| CVE-2026-44173 | MariaDB: FILE privilege was not checked for subqueries in the FROM clause | HIGH | 8.1 | Jun 12, 2026 |
| CVE-2026-44172 | MariaDB: mysql_real_escape_string() incorrectly handled big5 | MEDIUM | 6.9 | Jun 12, 2026 |
| CVE-2026-44171 | MariaDB: path traversal in mbstream | HIGH | 7.8 | Jun 12, 2026 |
| CVE-2026-44169 | MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions | MEDIUM | 4.3 | Jun 12, 2026 |
| CVE-2026-44168 | MariaDB: wsrep SST unsafe parameter handling on the donor side | HIGH | 8.0 | Jun 12, 2026 |
| CVE-2026-44170 | MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL | MEDIUM | 6.3 | Jun 12, 2026 |
| CVE-2026-49261 | MariaDB server has unsafe parameter handling in `wsrep_notify_cmd` | CRITICAL | 10.0 | Jun 11, 2026 |
| CVE-2026-32710 | Heap-based Buffer Overflow in MariaDB | CRITICAL | 9.9 | Mar 20, 2026 |
Showing 1 to 10 of 10 CVEs