oracle
2,128 known vulnerabilities affecting oracle products.
Products
e-business_suite 161
coherence 99
helidon 99
agile_product_lifecycle_management 88
commerce_guided_search 82
hyperion_financial_management 80
commerce_experience_manager 77
webcenter_content 77
hyperion_infrastructure_technology 68
siebel_crm 60
weblogic_server 52
mysql_cluster 45
mysql_server 41
enterprise_manager_base_platform 41
reports_developer 41
jd_edwards_enterpriseone_tools 39
human_resources_management_system 38
communications_instant_messaging_server 38
vm_virtualbox 38
webcenter_portal 36
hyperion_calculation_manager 36
hyperion_data_relationship_management 35
application_testing_suite 34
communications_evolved_communications_application_server 32
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-71046 | Medium | 0.1% | 8.8 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component:… | |
| CVE-2026-71101 | Medium | 0.1% | 7.8 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (compon… | |
| CVE-2026-62536 | Medium | 0.1% | 7.1 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle… | |
| CVE-2026-71094 | Medium | 0.1% | 7.3 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of … | |
| CVE-2026-60159 | Medium | 0.1% | 7.5 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (comp… | |
| CVE-2026-62574 | Medium | 0.1% | 7.8 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Ente… | |
| CVE-2026-70796 | Medium | 0.1% | 7.2 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (c… | |
| CVE-2026-60975 | Medium | 0.1% | 7.5 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS… | |
| CVE-2026-70731 | Medium | 0.1% | 8.4 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analy… | |
| CVE-2026-70697 | Medium | 0.1% | 7.0 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle … | |
| CVE-2026-71098 | Medium | 0.1% | 7.0 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of … | |
| CVE-2026-13367 | Medium | 0.1% | 7.8 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation… | |
| CVE-2026-61202 | Medium | 0.1% | 7.5 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utilit… | |
| CVE-2026-71092 | Medium | 0.1% | 7.5 | Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of O… | |
| CVE-2026-60994 | Medium | 0.1% | 7.2 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion … | |
| CVE-2019-17569 | Low | 8.9% | 4.8 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and … | |
| CVE-2021-41183 | Low | 8.5% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2020-9281 | Low | 4.3% | 6.1 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEdit… | |
| CVE-2018-11039 | Low | 2.7% | 5.9 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18,… | |
| CVE-2021-36374 | Low | 2.6% | 5.5 | When reading a specially crafted ZIP archive, or a derived formats, an Apache An… | |
| CVE-2021-36373 | Low | 2.5% | 5.5 | When reading a specially crafted TAR archive an Apache Ant build can be made to … | |
| CVE-2021-26272 | Low | 2.2% | 6.5 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by … | |
| CVE-2019-10219 | Low | 2.2% | 6.1 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotat… | |
| CVE-2020-27193 | Low | 2.0% | 6.1 | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEdit… | |
| CVE-2021-26271 | Low | 2.0% | 6.5 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by … | |
| CVE-2021-3572 | Low | 1.8% | 5.7 | A flaw was found in python-pip in the way it handled Unicode separators in git r… | |
| CVE-2017-3577 | Low | 1.7% | 6.5 | Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Orac… | |
| CVE-2017-10039 | Low | 1.6% | 6.8 | Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products … | |
| CVE-2021-2421 | Low | 1.5% | 6.5 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle… | |
| CVE-2020-17521 | Low | 1.1% | 5.5 | Apache Groovy provides extension methods to aid with creating temporary director… | |
| CVE-2020-2912 | Low | 0.9% | 5.0 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle… | |
| CVE-2022-21467 | Low | 0.9% | 6.5 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component:… | |
| CVE-2025-4598 | Low | 0.8% | 4.7 | A vulnerability was found in systemd-coredump. This flaw allows an attacker to f… | |
| CVE-2024-21262 | Low | 0.6% | 6.5 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connec… | |
| CVE-2021-35606 | Low | 0.5% | 5.7 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle… | |
| CVE-2026-47008 | Low | 0.5% | 4.9 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (compon… | |
| CVE-2026-60171 | Low | 0.5% | 4.9 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server: O… | |
| CVE-2026-61128 | Low | 0.5% | 4.9 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (compon… | |
| CVE-2026-61144 | Low | 0.5% | 4.9 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (compon… | |
| CVE-2026-47052 | Low | 0.4% | 4.9 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (compon… | |
| CVE-2025-30714 | Low | 0.4% | 4.8 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connec… | |
| CVE-2026-61176 | Low | 0.4% | 6.7 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply… | |
| CVE-2026-62503 | Low | 0.4% | 6.7 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (c… | |
| CVE-2026-60174 | Low | 0.4% | 6.5 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (compon… | |
| CVE-2026-60243 | Low | 0.4% | 6.5 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo… | |
| CVE-2026-60311 | Low | 0.4% | 6.5 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (compon… | |
| CVE-2026-60324 | Low | 0.4% | 6.5 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (compon… | |
| CVE-2026-60399 | Low | 0.4% | 6.5 | Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Su… | |
| CVE-2026-60403 | Low | 0.4% | 6.5 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-M… | |
| CVE-2026-60404 | Low | 0.4% | 6.5 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-M… |