Oracle
18,434 known vulnerabilities
Top Products
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, conta
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, con
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, con
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen
Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allo
The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in a use count error th
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the defa
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker wi
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Ea
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can ea
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lea
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on caref
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebS
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uplo
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for i
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment,
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification w
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver
OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer
<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible t
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supp
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Financial Gatewa
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: User Interface). Suppor
Frequently Asked Questions
How many CVEs affect Oracle?
Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Oracle vulnerabilities?
Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Oracle vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Oracle Vulnerabilities
CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.
Get Started