Oracle
18,434 known vulnerabilities
Top Products
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which c
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be pr
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerab
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid E
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protect
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure
IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it u
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni
IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses fr
IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they s
IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated us
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or a
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified ve
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *tes
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixe
An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a m
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.
IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of servic
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surpris
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen
Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported version
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Profiles). Support
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle Hospitality Inventory Management product of Oracle Food and Beverage Applications (component
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are af
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that
Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant). The supported
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Frequently Asked Questions
How many CVEs affect Oracle?
Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Oracle vulnerabilities?
Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Oracle vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Oracle Vulnerabilities
CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.
Get Started