Oracle
18,434 known vulnerabilities
Top Products
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth
IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer sec
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for furthe
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locato
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a
A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of serv
There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unche
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IG
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remo
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework)
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (componen
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supp
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Log). Supp
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Su
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Su
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web API).
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Acces
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions th
Frequently Asked Questions
How many CVEs affect Oracle?
Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Oracle vulnerabilities?
Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Oracle vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Oracle Vulnerabilities
CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.
Get Started