Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Oracle

18,434 known vulnerabilities

837
CRITICAL
3,115
HIGH
3,892
MEDIUM
511
LOW

Top Products

mysql 856 vm virtualbox 407 jdk 350 solaris 338 jre 337 mysql server 311 peoplesoft enterprise peopletools 296 weblogic server 277 e-business suite 203 graalvm 193
8,355 CVEs · Page 113/168
9.8
CVE-2020-8840

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apac

6.5
CVE-2020-7060

When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.

6.5
CVE-2020-7059

When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 an

9.8
CVE-2019-15606

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on he

9.8
CVE-2019-15605

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

7.5
CVE-2019-15604

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certi

7.5
CVE-2015-2802

An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Man

6.5
CVE-2019-4614

IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service

5.9
CVE-2019-4568

IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause

7.5
CVE-2020-7226

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excess

7.1
CVE-2019-16792

Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would heade

5.3
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that targ

7.5
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16,

6.1
CVE-2019-17573

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This

7.5
CVE-2019-12423

Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format,

7.5
CVE-2020-7044

In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c b

3.9
CVE-2020-2731

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2,

5.4
CVE-2020-2730

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli

5.4
CVE-2020-2729

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console). Supported versi

7.5
CVE-2020-2728

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch). T

6.0
CVE-2020-2727

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

7.5
CVE-2020-2726

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

6.5
CVE-2020-2725

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

4.3
CVE-2020-2724

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In

7.1
CVE-2020-2723

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In

5.4
CVE-2020-2722

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In

6.5
CVE-2020-2721

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In

5.4
CVE-2020-2720

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In

4.3
CVE-2020-2719

Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core

7.1
CVE-2020-2718

Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core

5.4
CVE-2020-2717

Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core

6.5
CVE-2020-2716

Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core

5.4
CVE-2020-2715

Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core

4.3
CVE-2020-2714

Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor

7.1
CVE-2020-2713

Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor

5.4
CVE-2020-2712

Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor

6.5
CVE-2020-2711

Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor

5.4
CVE-2020-2710

Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor

4.7
CVE-2020-2709

Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Learner Pages). The supported version that

5.4
CVE-2020-2707

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering

6.5
CVE-2020-2705

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

6.5
CVE-2020-2704

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

6.5
CVE-2020-2703

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

7.5
CVE-2020-2702

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

7.5
CVE-2020-2701

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

4.3
CVE-2020-2700

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Inf

7.1
CVE-2020-2699

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Inf

7.5
CVE-2020-2698

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar

4.9
CVE-2020-2697

Vulnerability in the Oracle Hospitality Suites Management component of Oracle Food and Beverage Applications. Supported

8.8
CVE-2020-2696

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). The supported ver

Frequently Asked Questions

How many CVEs affect Oracle?

Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Oracle vulnerabilities?

Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Oracle vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Oracle Vulnerabilities

CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.

Get Started