Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Oracle

18,434 known vulnerabilities

837
CRITICAL
3,115
HIGH
3,892
MEDIUM
511
LOW

Top Products

mysql 856 vm virtualbox 407 jdk 350 solaris 338 jre 337 mysql server 311 peoplesoft enterprise peopletools 296 weblogic server 277 e-business suite 203 graalvm 193
8,355 CVEs · Page 75/168
5.5
CVE-2021-4115

There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor

6.1
CVE-2022-25256

SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel

9.8
CVE-2022-25315

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

7.5
CVE-2022-25314

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

6.5
CVE-2022-25313

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth

7.5
CVE-2021-39034

IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID

7.4
CVE-2022-23632

Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer sec

9.8
CVE-2021-3773

A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for furthe

7.8
CVE-2021-3551

A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the

9.8
CVE-2022-25236

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace

9.8
CVE-2022-25235

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT

7.5
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locato

7.5
CVE-2021-43859

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a

5.5
CVE-2022-0286

A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of serv

5.9
CVE-2021-4160

There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including

7.0
CVE-2022-23181

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1

7.5
CVE-2022-23990

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

6.5
CVE-2021-22570

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unche

6.5
CVE-2022-23437

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document

9.8
CVE-2022-23852

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_

9.8
CVE-2022-23221

H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IG

6.5
CVE-2022-22310

IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remo

6.6
CVE-2022-21403

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

4.8
CVE-2022-21402

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

6.6
CVE-2022-21401

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

5.4
CVE-2022-21400

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

6.6
CVE-2022-21399

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

5.4
CVE-2022-21398

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

5.4
CVE-2022-21397

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

5.4
CVE-2022-21396

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

7.2
CVE-2022-21395

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng

6.5
CVE-2022-21394

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

4.3
CVE-2022-21393

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.

8.8
CVE-2022-21392

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework)

9.9
CVE-2022-21391

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications

10.0
CVE-2022-21390

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications

10.0
CVE-2022-21389

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications

3.3
CVE-2022-21388

Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (componen

5.3
CVE-2022-21387

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supp

6.1
CVE-2022-21386

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve

4.3
CVE-2022-21383

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Log). Supp

7.7
CVE-2022-21382

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Su

6.4
CVE-2022-21381

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Su

6.3
CVE-2022-21380

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af

4.9
CVE-2022-21379

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versi

5.5
CVE-2022-21378

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af

5.4
CVE-2022-21377

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web API).

5.4
CVE-2022-21376

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Acces

5.5
CVE-2022-21375

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte

4.9
CVE-2022-21374

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions th

Frequently Asked Questions

How many CVEs affect Oracle?

Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Oracle vulnerabilities?

Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Oracle vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Oracle Vulnerabilities

CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.

Get Started