Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Monitoring And Management CRITICAL 9.9
CVE-2026-25212

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admi…

Fix: 3.7.0+
Fix from $2,300 2026-04-02
Toolkit HIGH 7.5
CVE-2024-7701

Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affec…

Mitigation only
Fix from $1,950 2024-12-15
Xtrabackup HIGH 7.8
CVE-2022-25834

In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command sh…

Fix: after 8.0.27-19
Fix from $1,950 2023-06-07
Monitoring And Management CRITICAL 9.8
CVE-2023-34409

In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sani…

Fix: 2.37.1+
Fix from $2,300 2023-06-06
Percona Server HIGH 7.5
CVE-2022-34968

An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

No fix yet
Fix from $1,950 2022-08-03
Xtrabackup MEDIUM 6.5
CVE-2022-26944

Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at…

Mitigation only
Fix from $1,600 2022-06-02
Percona Server CRITICAL 9.8
CVE-2020-26542

An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjuncti…

Fix: after 2020-10-02
Fix from $2,300 2020-11-09
Xtradb Cluster HIGH 8.1
CVE-2020-10996

An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processe…

Fix: 5.7.28-31.41.2+
Fix from $1,950 2020-04-27
Xtrabackup MEDIUM 6.5
CVE-2020-10997

Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments pa…

Fix: 2.4.20 / 8.0.11+
Fix from $1,600 2020-04-27
Monitoring And Management HIGH 7.5
CVE-2020-7920

pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.

Fix: 2.2.1+
Fix from $1,950 2020-02-06
Percona Server CRITICAL 9.8
CVE-2019-12301

The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upo…

Mitigation only
Fix from $2,300 2019-05-23
Toolkit HIGH 8.1
CVE-2014-2029

The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or e…

Patch available
Fix from $1,950 2017-09-29
Toolkit MEDIUM 5.9
CVE-2015-1027

The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man …

Fix: after 2.2.12
Fix from $1,600 2017-09-29