Known vulnerabilities in MySQL Workbench

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*
Total vulnerabilities: 51
Public exploits: 12
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting MySQL Workbench MySQL Workbench is affected by 51 known vulnerabilities: 1 critical, 12 high, 24 medium, 14 low Critical High Medium Low

Vulnerabilities (51)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122076 - Stack-based buffer overflow
CVE-2025-15467
CWE-121 High
Available
No
- 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 66 more
#VU118777 - Heap-based Buffer Overflow
CVE-2025-65018
CWE-122 Critical
Available
No
- 26.11.2025 SB2025112638
SB2025112639
SB2025112819
and 46 more
#VU116213 - Out-of-bounds write
CVE-2025-9230
CWE-787 Medium
No
No
- 01.10.2025 SB2025100119
SB2025100132
SB2025100133
and 108 more
#VU113156 - Memory corruption
CVE-2025-6965
CWE-119 Medium
No
No
- 22.07.2025 SB2025072254
SB2025072807
SB2025072890
and 100 more
#VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4517
CWE-22 High
Available
No
- 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 77 more
#VU111900 - Out-of-bounds read
CVE-2025-5318
CWE-125 Medium
No
No
- 24.06.2025 SB2025062451
SB2025062454
SB20250704157
and 61 more
#VU111223 - Type confusion
CVE-2025-49796
CWE-843 Medium
No
No
- 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 84 more
#VU107596 - Heap-based Buffer Overflow
CVE-2025-32415
CWE-122 High
No
No
- 17.04.2025 SB2025041758
SB2025041880
SB2025042531
and 56 more
#VU103600 - Covert Timing Channel
CVE-2024-13176
CWE-385 Medium
No
No
8.0.42 04.02.2025 SB2025020454
SB2025020456
SB2025020656
and 59 more
#VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-9287
CWE-78 Low
No
No
- 28.10.2024 SB2024102836
SB2024102838
SB20241101111
and 117 more
#VU96997 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-40896
CWE-611 High
No
No
8.0.42 10.09.2024 SB2024091054
SB2024091056
SB2024091071
and 10 more
#VU93424 - Out-of-bounds read
CVE-2024-5535
CWE-125 Low
Available
No
8.0.40 27.06.2024 SB2024062720
SB20240717135
SB2024072154
and 157 more
#VU87685 - Resource exhaustion
CVE-2024-0450
CWE-400 Medium
No
No
8.0.38 21.03.2024 SB2024032107
SB2024032110
SB2024040848
and 80 more
#VU86052 - Use After Free
CVE-2024-25062
CWE-416 High
No
No
8.0.38 05.02.2024 SB2024020507
SB2024020508
SB2024020742
and 115 more
#VU85170 - State Issues
CVE-2023-6129
CWE-371 Medium
No
No
8.0.38 09.01.2024 SB2024010929
SB2024012250
SB2024012612
and 69 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
8.0.38 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU82349 - Cryptographic Issues
CVE-2023-5363
CWE-310 Low
No
No
8.0.36 24.10.2023 SB2023102443
SB2023102448
SB2023102534
and 46 more
#VU80585 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-41105
CWE-22 Low
No
No
8.0.36 11.09.2023 SB2023082825
SB2023100328
SB2023100362
and 18 more
#VU75740 - Improper Authentication
CVE-2023-2283
CWE-287 High
No
No
8.0.36 04.05.2023 SB2023050456
SB2023050501
SB2023052441
and 84 more
#VU70528 - Security Features
CVE-2022-46908
CWE-254 Low
No
No
8.0.36 28.12.2022 SB2022122824
SB2022122826
SB2022122827
and 24 more


Showing elements 1 - 20 out of 51