oracle
2,128 known vulnerabilities affecting oracle products.
Products
e-business_suite 161
coherence 99
helidon 99
agile_product_lifecycle_management 88
commerce_guided_search 82
hyperion_financial_management 80
commerce_experience_manager 77
webcenter_content 77
hyperion_infrastructure_technology 68
siebel_crm 60
weblogic_server 52
mysql_cluster 45
mysql_server 41
enterprise_manager_base_platform 41
reports_developer 41
jd_edwards_enterpriseone_tools 39
human_resources_management_system 38
communications_instant_messaging_server 38
vm_virtualbox 38
webcenter_portal 36
hyperion_calculation_manager 36
hyperion_data_relationship_management 35
application_testing_suite 34
communications_evolved_communications_application_server 32
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2017-10271 | Act now | 100.0% | 7.5 | ● | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar… |
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC… |
| CVE-2019-2725 | Act now | 100.0% | 9.8 | ● | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar… |
| CVE-2025-61882 | Act now | 99.7% | 9.8 | ● | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business S… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting inc… |
| CVE-2012-4681 | Act now | 98.5% | 9.8 | ● | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Orac… |
| CVE-2012-0507 | Act now | 98.1% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older … |
| CVE-2025-61884 | Act now | 95.9% | 7.5 | ● | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (com… |
| CVE-2026-35273 | Act now | 95.5% | 9.8 | ● | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS… |
| CVE-2021-4034 | Act now | 94.9% | 7.8 | ● | A local privilege escalation vulnerability was found on polkit's pkexec utility.… |
| CVE-2012-1723 | Act now | 93.7% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7… |
| CVE-2013-0431 | Act now | 90.3% | 5.3 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora… |
| CVE-2026-21962 | Act now | 42.5% | 10.0 | ● | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr… |
| CVE-2026-46817 | Act now | 13.0% | 9.8 | ● | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone… |
| CVE-2012-1710 | Act now | 11.4% | 9.8 | ● | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in… |
| CVE-2015-5287 | Act now | 5.0% | 7.8 | ● | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.… |
| CVE-2021-45105 | High | 100.0% | 5.9 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di… | |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache To… | |
| CVE-2021-33037 | High | 75.4% | 5.3 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no… | |
| CVE-2020-13934 | High | 64.1% | 7.5 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.… | |
| CVE-2020-9484 | High | 56.6% | 7.0 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.… | |
| CVE-2021-41184 | Medium | 40.8% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2021-41182 | Medium | 39.4% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2019-10086 | Medium | 29.2% | 7.3 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added wh… | |
| CVE-2021-24122 | Medium | 22.9% | 5.9 | When serving resources from a network location using the NTFS file system, Apach… | |
| CVE-2020-36179 | Medium | 21.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-9548 | Medium | 18.3% | 9.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2021-25122 | Medium | 18.1% | 7.5 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1… | |
| CVE-2020-25649 | Medium | 17.8% | 7.5 | A flaw was found in FasterXML Jackson Databind, where it did not have entity exp… | |
| CVE-2020-35728 | Medium | 12.5% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2022-23437 | Medium | 11.6% | 6.5 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when … | |
| CVE-2020-36188 | Medium | 10.9% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2020-36184 | Medium | 10.4% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2021-29425 | Medium | 10.2% | 4.8 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normaliz… | |
| CVE-2020-35491 | Medium | 9.6% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2021-25329 | Medium | 9.5% | 7.0 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to … | |
| CVE-2020-24616 | Medium | 9.4% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee… | |
| CVE-2018-15756 | Medium | 9.2% | 7.5 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr… | |
| CVE-2020-14060 | Medium | 8.6% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee… | |
| CVE-2022-25762 | Medium | 8.4% | 8.6 | If a web application sends a WebSocket message concurrently with the WebSocket c… | |
| CVE-2020-14062 | Medium | 8.1% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee… | |
| CVE-2020-10673 | Medium | 8.0% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee… | |
| CVE-2020-35490 | Medium | 7.8% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee… | |
| CVE-2021-20190 | Medium | 7.5% | 8.1 | A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the i… | |
| CVE-2021-40690 | Medium | 7.4% | 7.5 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.… | |
| CVE-2020-24750 | Medium | 7.3% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee… | |
| CVE-2020-10683 | Medium | 7.3% | 9.8 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti… |
Page 1 of 43
Next →