In Oracle MySQL Server Optimizer component versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7 and 9.0.0 through 9.5.0 a medium severity vulnerability CVE-2026-21968 was detected. This vulnerability allows a low-privileged attacker with network access to cause a hang or repeatedly crash the MySQL Server, resulting in a complete denial of service. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21968.
Read more Newsflash DatabaseIn Oracle MySQL Server Thread Pooling component versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7 and 9.0.0 through 9.5.0 a medium severity vulnerability CVE-2026-21964 was detected. This vulnerability allows a high-privileged attacker with network access to cause a complete denial of service by triggering a hang or repeated crashes of the MySQL Server. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21964.
Read more Newsflash DatabaseIn Oracle MySQL Server versions 9.0.0 through 9.5.0 a medium severity vulnerability CVE-2026-21952 was detected. This vulnerability allows a high-privileged attacker with network access to cause a hang or a repeatedly reproducible crash, resulting in a complete denial of service (DoS) of the MySQL Server due to an issue in the Server Parser component. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21952.
Read more Newsflash DatabaseIn MongoDB Server versions prior to 7.0.28, 8.0.17, 8.2.3, 6.0.27, 5.0.32, 4.4.30, and versions greater than or equal to 4.2.0, 4.0.0, and 3.6.0 a high severity vulnerability CVE-2025-14847 was detected. This vulnerability may allow an unauthenticated client to read uninitialized heap memory due to mismatched length fields in Zlib compressed protocol headers. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14847.
Read more DatabaseIn MariaDB versions affected by CVE-2025-13699 a medium severity vulnerability was detected. This vulnerability allows remote attackers to execute arbitrary code via the mariadb-dump utility due to improper validation of user-supplied paths in view names, enabling directory traversal and code execution in the context of the current user. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13699.
Read more DatabaseIn MongoDB Server versions before 8.0.16, 7.0.26, and 8.2.2 a low severity vulnerability CVE-2025-14345 was detected. This vulnerability can cause temporary data inconsistencies in cross-shard transactions. To fix this issue, users should upgrade to MongoDB Server versions 8.0.16, 7.0.26 or 8.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14345.
Read more DatabaseIn MongoDB Server versions 7.0 prior to 7.0.26 and 8.0 prior to 8.0.14 a medium severity vulnerability CVE-2025-13643 was detected. This vulnerability allows a user with limited cluster privileges to terminate queries executed by other users, potentially causing denial of service by preventing some queries from completing successfully. To address this issue, users should upgrade MongoDB Server to versions 7.0.26, 8.0.14, or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13643.
Read more DatabaseIn MongoDB Server versions 7.0 prior to 7.0.26, 8.0 prior to 8.0.16, and 8.2 prior to 8.2.2 a medium severity vulnerability CVE-2025-12893 was detected. This vulnerability allows MongoDB servers running on Windows or Apple platforms to successfully complete TLS handshakes with client or server certificates that do not meet the documented Extended Key Usage (EKU) requirements. Specifically, certificates missing the clientAuth EKU may still authenticate as clients, and on Apple servers, certificates missing the serverAuth EKU may still authenticate as servers during egress TLS connections. To address this issue, users should upgrade MongoDB Server to versions 7.0.26, 8.0.16, or 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12893.
Read more DatabaseIn MongoDB Server versions 7.0 prior to 7.0.26, 8.0 prior to 8.0.13, and 8.1 prior to 8.1.2 a high severity vulnerability CVE-2025-13644 was detected. The issue allows a batched delete operation to trigger an invariant failure and crash the server when MongoDB incorrectly assumes multiple documents are present in a batch solely because a document exceeds BSONObjMaxSize. To address this issue, users should update to MongoDB Server 7.0.26, 8.0.13, or 8.1.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13644.
Read more Database