Known Vulnerabilities for products from Mariadb

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Mariadb".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-49261 json Not Provided 2026-06-11 2026-06-12
CVE-2026-48188 json Not Provided 2026-06-01 2026-06-01
CVE-2026-48165 json MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11... Not Provided 2026-06-12 2026-06-16
CVE-2026-48163 json MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11... Not Provided 2026-06-12 2026-06-16
CVE-2026-47847 json Not Provided 2026-06-18 2026-06-18
CVE-2026-46446 json Not Provided 2026-05-14 2026-05-14
CVE-2026-44173 json MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11... Not Provided 2026-06-12 2026-06-16
CVE-2026-44172 json Not Provided 2026-06-12 2026-06-12
CVE-2026-44171 json Not Provided 2026-06-12 2026-06-12
CVE-2026-44170 json MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11... Not Provided 2026-06-12 2026-06-16
CVE-2026-44169 json MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7... Not Provided 2026-06-12 2026-06-17
CVE-2026-44168 json MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11... Not Provided 2026-06-12 2026-06-18
CVE-2026-35549 json An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the... Not Provided 2026-04-03 2026-06-02
CVE-2026-32710 json MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11... Not Provided 2026-03-20 2026-03-31
CVE-2023-40354 json An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service"... 6.5 - MEDIUM 2023-08-14 2023-08-22
CVE-2023-5157 json A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a... 7.5 - HIGH 2023-09-27 2023-12-04
CVE-2022-47015 json MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::pr... 6.5 - MEDIUM 2023-01-20 2023-11-07
CVE-2022-38791 json In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write ... 5.5 - MEDIUM 2022-08-27 2023-11-07
CVE-2022-32091 json MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sani... 7.5 - HIGH 2022-07-01 2023-11-07
CVE-2022-32089 json MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level. 7.5 - HIGH 2022-07-01 2023-11-07

Known software with vulnerabilities from Mariadb

Type Vendor Product Version
ApplicationMariadbConnector/c2.2.1
ApplicationMariadbMariadb-
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report