Oracle
18,434 known vulnerabilities
Top Products
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apac
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 an
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on he
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certi
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Man
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excess
Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would heade
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that targ
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16,
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format,
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c b
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2,
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console). Supported versi
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch). T
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: In
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor
Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Learner Pages). The supported version that
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Inf
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Inf
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle Hospitality Suites Management component of Oracle Food and Beverage Applications. Supported
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). The supported ver
Frequently Asked Questions
How many CVEs affect Oracle?
Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Oracle vulnerabilities?
Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Oracle vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Oracle Vulnerabilities
CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.
Get Started