Percona
percona
21 CVEs • 5 products
Products (5)
Click to collapseToggle
Products (5)
Click to collapse
CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Percona 1Monitoring And Management Jul 24, 2026 Apr 2, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the da...Show more |
Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0. |
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands. |
1Percona 1Monitoring And Management Jun 17, 2026 Jun 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauth...Show more |
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query. |
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this comm...Show more |
4Debian GaleraclusterMariadb+1 more4Debian Linux Galera Cluster For MysqlMariadb+1 moreJun 17, 2026 May 27, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera c...Show more |
4Debian GaleraclusterMariadb+1 more4Debian Linux MariadbPercona Server+1 moreJun 17, 2026 Mar 19, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for...Show more |
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw tha...Show more |
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, th...Show more |
An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key expected. |
1Percona 1Monitoring And Management Jun 17, 2026 Feb 6, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service. |
The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upon an upgrade. This was fixed in 5.6.44-85.0-2. |
3Fedoraproject MariadbPercona3Fedora MariadbXtradb ClusterNov 21, 2024 Jan 25, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass i...Show more |
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to...Show more |
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configurati...Show more |
3Fedoraproject OpensusePercona3Fedora LeapXtrabackupMay 13, 2026 Mar 23, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information...Show more |
3Mariadb OraclePercona4Mariadb MysqlPercona Server+1 moreMay 6, 2026 Dec 13, 2016 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster befo...Show more |
3Mariadb OraclePercona4Mariadb MysqlPercona Server+1 moreMay 6, 2026 Dec 13, 2016 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5....Show more |
5Debian MariadbOracle+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreMay 6, 2026 Sep 20, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5...Show more |