Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Oracle

18,434 known vulnerabilities

837
CRITICAL
3,115
HIGH
3,892
MEDIUM
511
LOW

Top Products

mysql 856 vm virtualbox 407 jdk 350 solaris 338 jre 337 mysql server 311 peoplesoft enterprise peopletools 296 weblogic server 277 e-business suite 203 graalvm 193
8,355 CVEs · Page 107/168
7.7
CVE-2020-10725

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhos

7.3
CVE-2020-9410

The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for Act

9.8
CVE-2020-9409

The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS

6.1
CVE-2020-7656

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re

5.1
CVE-2020-10723

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on th

5.1
CVE-2020-10722

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_lo

6.1
CVE-2020-1941

In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a q

9.8
CVE-2020-11973

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1

9.8
CVE-2020-11972

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to

7.5
CVE-2020-11971

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affec

4.3
CVE-2020-4365

IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted reques

4.3
CVE-2020-4299

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user throug

6.5
CVE-2020-4259

IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information

6.3
CVE-2020-1945

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system propert

9.8
CVE-2018-1285

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. Thi

7.5
CVE-2020-9315

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/vers

4.8
CVE-2020-9314

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration c

5.3
CVE-2020-10693

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invali

9.8
CVE-2020-10683

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE

6.9
CVE-2020-11022

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one

6.9
CVE-2020-11023 KEV

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untru

7.5
CVE-2020-2575

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

7.5
CVE-2020-7067

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (un

3.7
CVE-2020-9488

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connectio

5.5
CVE-2020-9489

A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can a

7.5
CVE-2020-1967

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due

7.1
CVE-2020-2964

Vulnerability in the Oracle Financial Services Data Foundation product of Oracle Financial Services Applications (compon

7.2
CVE-2020-2963

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver

9.8
CVE-2020-2961

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framewo

8.6
CVE-2020-2959

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

7.5
CVE-2020-2958

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

8.1
CVE-2020-2956

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Suppo

6.3
CVE-2020-2955

Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Transact

6.1
CVE-2020-2954

Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Candidate Gateway). The support

9.8
CVE-2020-2953

Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications

6.5
CVE-2020-2952

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported ver

6.5
CVE-2020-2951

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

9.8
CVE-2020-2950

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana

5.3
CVE-2020-2949

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation).

4.3
CVE-2020-2947

Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Manag

6.0
CVE-2020-2946

Vulnerability in the Application Performance Management product of Oracle Enterprise Manager (component: EM Request Moni

7.1
CVE-2020-2945

Vulnerability in the Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management product of O

8.8
CVE-2020-2944

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version

7.1
CVE-2020-2943

Vulnerability in the Oracle Financial Services Liquidity Risk Measurement and Management product of Oracle Financial Ser

7.1
CVE-2020-2942

Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applica

7.1
CVE-2020-2941

Vulnerability in the Oracle Financial Services Funds Transfer Pricing product of Oracle Financial Services Applications

7.1
CVE-2020-2940

Vulnerability in the Oracle Financial Services Profitability Management product of Oracle Financial Services Application

7.1
CVE-2020-2939

Vulnerability in the Oracle Financial Services Asset Liability Management product of Oracle Financial Services Applicati

7.1
CVE-2020-2938

Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Servic

7.1
CVE-2020-2937

Vulnerability in the Oracle Insurance Accounting Analyzer product of Oracle Financial Services Applications (component:

Frequently Asked Questions

How many CVEs affect Oracle?

Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Oracle vulnerabilities?

Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Oracle vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Oracle Vulnerabilities

CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.

Get Started