Skip to main content

Vendor archive

percona CVEs

Beta · best-effort

21 CVEs tagged to vendor percona6 Critical, 9 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2026-25212

Published Apr 2, 2026

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add da…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-7701

Published Dec 15, 2024

Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25834

Published Jun 7, 2023

In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary com…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34409

Published Jun 6, 2023

In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34968

Published Aug 3, 2022

An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26944

Published Jun 2, 2022

Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when -…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26542

Published Nov 9, 2020

An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Dir…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10997

Published Apr 27, 2020

Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10996

Published Apr 27, 2020

An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key e…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12301

Published May 23, 2019

The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upon an upgrade. This was fixed i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1027

Published Sep 29, 2017

The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2029

Published Sep 29, 2017

The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by lever…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6662

Published Sep 20, 2016

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
31.5

CVE-2013-6394

Published Dec 13, 2013

Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1