Oracle
18,434 known vulnerabilities
Top Products
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could al
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted d
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and
This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during th
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the n
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite
The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite a
axios is vulnerable to Inefficient Regular Expression Complexity
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryp
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo functi
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML
An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An att
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no e
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to miss
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request spl
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the cli
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_RE
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CU
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches
Frequently Asked Questions
How many CVEs affect Oracle?
Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Oracle vulnerabilities?
Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Oracle vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Oracle Vulnerabilities
CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.
Get Started