← All vendors

oracle

2,128 known vulnerabilities affecting oracle products.

Products

e-business_suite 161 coherence 99 helidon 99 agile_product_lifecycle_management 88 commerce_guided_search 82 hyperion_financial_management 80 commerce_experience_manager 77 webcenter_content 77 hyperion_infrastructure_technology 68 siebel_crm 60 weblogic_server 52 mysql_cluster 45 mysql_server 41 enterprise_manager_base_platform 41 reports_developer 41 jd_edwards_enterpriseone_tools 39 human_resources_management_system 38 communications_instant_messaging_server 38 vm_virtualbox 38 webcenter_portal 36 hyperion_calculation_manager 36 hyperion_data_relationship_management 35 application_testing_suite 34 communications_evolved_communications_application_server 32

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2021-40438 Act now 100.0% 9.0 A crafted request uri-path can cause mod_proxy to forward the request to an orig…
CVE-2017-10271 Act now 100.0% 7.5 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar…
CVE-2017-12617 Act now 100.0% 8.1 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC…
CVE-2019-2725 Act now 100.0% 9.8 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar…
CVE-2025-61882 Act now 99.7% 9.8 Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business S…
CVE-2020-1938 Act now 99.3% 9.8 When using the Apache JServ Protocol (AJP), care must be taken when trusting inc…
CVE-2012-4681 Act now 98.5% 9.8 Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Orac…
CVE-2012-0507 Act now 98.1% 9.8 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora…
CVE-2018-1273 Act now 97.0% 9.8 Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older …
CVE-2025-61884 Act now 95.9% 7.5 Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (com…
CVE-2026-35273 Act now 95.5% 9.8 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS…
CVE-2021-4034 Act now 94.9% 7.8 A local privilege escalation vulnerability was found on polkit's pkexec utility.…
CVE-2012-1723 Act now 93.7% 9.8 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora…
CVE-2016-8735 Act now 90.3% 9.8 Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7…
CVE-2013-0431 Act now 90.3% 5.3 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora…
CVE-2026-21962 Act now 42.5% 10.0 Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr…
CVE-2026-46817 Act now 13.0% 9.8 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone…
CVE-2012-1710 Act now 11.4% 9.8 Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in…
CVE-2015-5287 Act now 5.0% 7.8 The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.…
CVE-2021-45105 High 100.0% 5.9 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di…
CVE-2020-13935 High 86.6% 7.5 The payload length in a WebSocket frame was not correctly validated in Apache To…
CVE-2021-33037 High 75.4% 5.3 Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no…
CVE-2020-13934 High 64.1% 7.5 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.…
CVE-2020-9484 High 56.6% 7.0 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.…
CVE-2021-41184 Medium 40.8% 6.5 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0…
CVE-2021-41182 Medium 39.4% 6.5 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0…
CVE-2019-10086 Medium 29.2% 7.3 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added wh…
CVE-2021-24122 Medium 22.9% 5.9 When serving resources from a network location using the NTFS file system, Apach…
CVE-2020-36179 Medium 21.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-9548 Medium 18.3% 9.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee…
CVE-2021-25122 Medium 18.1% 7.5 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1…
CVE-2020-25649 Medium 17.8% 7.5 A flaw was found in FasterXML Jackson Databind, where it did not have entity exp…
CVE-2020-35728 Medium 12.5% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2022-23437 Medium 11.6% 6.5 There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when …
CVE-2020-36188 Medium 10.9% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2020-36184 Medium 10.4% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2021-29425 Medium 10.2% 4.8 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normaliz…
CVE-2020-35491 Medium 9.6% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2021-25329 Medium 9.5% 7.0 The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to …
CVE-2020-24616 Medium 9.4% 8.1 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee…
CVE-2018-15756 Medium 9.2% 7.5 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr…
CVE-2020-14060 Medium 8.6% 8.1 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee…
CVE-2022-25762 Medium 8.4% 8.6 If a web application sends a WebSocket message concurrently with the WebSocket c…
CVE-2020-14062 Medium 8.1% 8.1 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee…
CVE-2020-10673 Medium 8.0% 8.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee…
CVE-2020-35490 Medium 7.8% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee…
CVE-2021-20190 Medium 7.5% 8.1 A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the i…
CVE-2021-40690 Medium 7.4% 7.5 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.…
CVE-2020-24750 Medium 7.3% 8.1 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee…
CVE-2020-10683 Medium 7.3% 9.8 dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti…
Page 1 of 43 Next →