Known vulnerabilities in MariaDB

Vendor: Debian
Software: MariaDB
Software CPE: cpe:2.3:o:debian:mariadb:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 11
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting MariaDB MariaDB is affected by 11 known vulnerabilities: 1 high, 3 medium, 7 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131787 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-44168
CWE-78 Low
No
No
10.6.26, 10.11.17, 11.4.11, 11.8.7, 12.3.2 19.05.2026 SB2026051913
#VU131786 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-44171
CWE-22 Medium
No
No
10.6.26, 10.11.17, 11.4.11, 11.8.7, 12.3.2 19.05.2026 SB2026051913
#VU131785 - Incorrect Authorization
CVE-2026-44169
CWE-863 Low
No
No
11.4.11, 11.6.0, 11.7.0, 11.8.0, 11.8.7, 12.1.1, 12.2.1, 12.3.1, 12.3.2 19.05.2026 SB2026051913
#VU131784 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-44170
CWE-78 Low
No
No
10.6.26, 10.11.17, 11.4.11, 11.8.7, 12.3.2 19.05.2026 SB2026051913
#VU131783 - Incorrect Authorization
CVE-2026-44173
CWE-863 Low
No
No
10.6.26, 10.8.1, 10.9.1, 10.10.1, 10.11.1, 10.11.17, 11.1.1, 11.2.1, 11.3.0, 11.4.0, 11.4.11, 11.6.0, 11.7.0, 11.8.0, 11.8.7, 12.1.1, 12.2.1, 12.3.1, 12.3.2 19.05.2026 SB2026051913
#VU128347 - Heap-based Buffer Overflow
CVE-2026-32710
CWE-122 Medium
No
No
11.4.10, 11.8.6, 12.2.2 28.04.2026 SB2026042874
SB20260428163
#VU67656 - Resource Management Errors
CVE-2022-38791
CWE-399 Low
No
No
10.3.36, 10.4.26, 10.5.17, 10.6.9, 10.7.5, 10.8.4, 10.9.2 26.09.2022 SB2022092649
SB2022092659
SB2023030643
and 27 more
#VU63829 - Improper Locking
CVE-2022-31621
CWE-667 Low
No
No
10.2.41, 10.3.32, 10.4.22, 10.5.13, 10.6.5, 10.7.1 31.05.2022 SB2022053133
SB2024062638
SB2022071702
and 1 more
#VU63828 - Improper Resource Shutdown or Release
CVE-2022-31624
CWE-404 Low
No
No
10.7.1 31.05.2022 SB2022053132
SB2024062638
SB2024080691
and 2 more
#VU63827 - Use After Free
CVE-2021-46669
CWE-416 Medium
No
No
10.2.44, 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4 31.05.2022 SB2022061533
SB2022061727
SB2022062431
and 27 more
#VU24937 - Permissions, Privileges, and Access Controls
CVE-2020-7221
CWE-264 High
No
No
10.4.12 05.02.2020 SB2020020507