Oracle
18,434 known vulnerabilities
Top Products
Vulnerability in the PeopleSoft Enterprise SCM product of Oracle PeopleSoft (component: Supplier Portal). The supported
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is aff
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected
Vulnerability in the Oracle Deal Management product of Oracle E-Business Suite (component: Miscellaneous). Supported ver
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Quotes). Supported versions
Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: BIS Operations Intell
Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Content Item Manager). Suppor
Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Invoice Approvals). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported ver
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Session Management). S
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The su
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle Web Analytics product of Oracle E-Business Suite (component: Admin). Supported versions that
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affe
Vulnerability in the Oracle Communications Interactive Session Recorder product of Oracle Communications (component: Pro
Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routin
Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routin
Vulnerability in the Oracle LogMiner component of Oracle Database Server. Supported versions that are affected are 12.1.
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework)
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/fired
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside thi
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, an
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path
An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path trave
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing a
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string libr
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel se
Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Red
Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RES
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send mal
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure
Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis
Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts ex
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality vi
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio
Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitab
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_
Frequently Asked Questions
How many CVEs affect Oracle?
Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Oracle vulnerabilities?
Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Oracle vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Oracle Vulnerabilities
CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.
Get Started