MariaDB
Security Risk Profile
50
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 443 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 20, 2005 to present
443
Total CVEs
96
Critical+High
1
Exploited
20
Unpatched
Threat Assessment
Avg CVSS
5.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
20
Critical/High
Risk Level
50/100
medium
⚠️ 1 Active Exploits⚡ 1 Zero-Days🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
12High
84Medium
301Low
42Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
6Age Distribution
Common Weaknesses (CWE)
1
Use After Free
16
2
Buffer Overflow
14
3
SQL Injection
11
4
OS Command Injection
5
5
Input Validation
5
Most Affected Products
1. MariaDB MariaDB1569
2. redhat/mariadb844
3. Oracle MySQL741
4. Canonical Ubuntu Linux633
5. redhat Enterprise Linux Eus485
Recent Vulnerabilities
See more →REDHAT-BUG-2488451
CVSS 7.0high
6/12/2026🔧 No Patch
REDHAT-BUG-2488450
CVSS 7.0high
6/12/2026🔧 No Patch
REDHAT-BUG-2488454
CVSS 7.0high
6/12/2026🔧 No Patch
REDHAT-BUG-2488460
CVSS 7.0high
6/12/2026🔧 No Patch
REDHAT-BUG-2488458
CVSS 7.0high
6/12/2026🔧 No Patch
REDHAT-BUG-2488453
CVSS 4.0medium
6/12/2026🔧 No Patch
CVE-2026-48165
CVSS 9.1critical
MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side
6/12/2026
CVE-2026-48163
CVSS 9.1critical
MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)
6/12/2026
CVE-2026-44173
CVSS 8.1high
MariaDB: FILE privilege was not checked for subqueries in the FROM clause
6/12/2026
CVE-2026-44172
CVSS 6.9medium
MariaDB: mysql_real_escape_string() incorrectly handled big5
6/12/2026
Monitor MariaDB in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.