> For the complete documentation index, see [llms.txt](https://mariadb.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mariadb.com/docs/server/security/cve.md).

# Security Vulnerabilities (CVE) Fixed in MariaDB

{% hint style="info" %}
This page is about security vulnerabilities fixed in MariaDB products. If you are looking for information on securing your MariaDB installation, see [Securing MariaDB](/docs/server/security/securing-mariadb.md).
{% endhint %}

{% hint style="danger" %}
Sensitive security issues can be reported on <https://hackerone.com/mariadb> or sent directly to the persons responsible for MariaDB security: security \[AT] mariadb (dot) org.
{% endhint %}

## What is a CVE?

**Common Vulnerabilities and Exposures** (CVE) relate to flaws "in a software, firmware, hardware, or service component resulting from a weakness that can be exploited, causing a negative impact to the confidentiality, integrity, or availability of an impacted component or components."

It is a publicly available and free-to-use database of known software vulnerabilities maintained at <https://cve.mitre.org/>.

For additional information, see [CVE Glossary at cve.org](https://www.cve.org/ResourcesSupport/Glossary)

## What is a CVSS Score?

**Common Vulnerability Scoring System** (CVSS) is "an open framework for communicating the characteristics and severity of software vulnerabilities."

For additional information, see [Vulnerability Metrics](https://nvd.nist.gov/vuln-metrics/cvss) at nvd.nist.gov

## Fixed Security Vulnerabilities

{% columns %}
{% column %}
{% content-ref url="/pages/vI6fH9yChQXjPM6Ap2d0" %}
[Security Vulnerabilities (CVE) Fixed in MariaDB Enterprise Server](/docs/server/security/cve/enterprise-server.md)
{% endcontent-ref %}
{% endcolumn %}

{% column %}
This page contains a full list of CVEs fixed in all versions and series of MariaDB Enterprise Server.
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column %}
{% content-ref url="/pages/rYSyN2lNt1b9yIngo0Em" %}
[Security Vulnerabilities (CVE) Fixed in MariaDB Community Server](/docs/server/security/cve/community-server.md)
{% endcontent-ref %}
{% endcolumn %}

{% column %}
This page contains a full list of CVEs fixed in all versions and series of MariaDB Community Server.
{% endcolumn %}
{% endcolumns %}

Some CVE apply to MySQL but are not present in MariaDB Enterprise Server or MariaDB Community Server; these are listed on the [Security Vulnerabilities fixed in Oracle MySQL that did not exist in MariaDB](/docs/server/security/cve/security-vulnerabilities-in-oracle-mysql-that-did-not-exist-in-mariadb.md) page.

<sub>*This page is licensed: CC BY-SA / Gnu FDL*</sub>

{% @marketo/form formId="4316" %}
