Products: 6
    Vulnerabilities: 22
    Known Exploited: 0
    7
    Critical Level Threats
    10
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-25212

    Internal superuser privileges enable remote code execution in Percona PMM 3.6.x

    Last Modified: Apr 21, 2026
    Published: Apr 02, 2026

    CVE-2025-26701

    An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.

    Last Modified: Apr 15, 2026
    Published: Mar 11, 2025

    CVE-2024-7701

    Misuse of SHA256 to create an encryption key

    Last Modified: Aug 05, 2025
    Published: Dec 15, 2024

    CVE-2022-25834

    In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands.

    Last Modified: Jan 07, 2025
    Published: Jun 07, 2023

    CVE-2023-34409

    In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made against unauthenticated API routes, to access otherwise protected API routes leading to escalation of privileges and information disclosure.

    Last Modified: Jan 08, 2025
    Published: Jun 06, 2023
    Items Per Page