Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Oracle

18,434 known vulnerabilities

837
CRITICAL
3,115
HIGH
3,892
MEDIUM
511
LOW

Top Products

mysql 856 vm virtualbox 407 jdk 350 solaris 338 jre 337 mysql server 311 peoplesoft enterprise peopletools 296 weblogic server 277 e-business suite 203 graalvm 193
8,355 CVEs · Page 93/168
8.2
CVE-2020-11987

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPan

8.8
CVE-2021-22112

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported

5.9
CVE-2021-27568

An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is throw

7.5
CVE-2020-28491

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-

7.5
CVE-2021-20354

IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker co

3.7
CVE-2021-22174

Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture

3.7
CVE-2021-22173

Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted ca

5.9
CVE-2021-23841

The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer

7.5
CVE-2021-23840

Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases

3.7
CVE-2021-23839

OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both S

7.2
CVE-2021-23337

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

5.9
CVE-2021-23336

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9

5.3
CVE-2020-28500

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim a

5.3
CVE-2021-21702

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a

7.5
CVE-2020-13949

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory a

9.8
CVE-2020-14343

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code e

6.1
CVE-2020-13947

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console

6.2
CVE-2021-21290

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h

9.1
CVE-2020-36242

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB

5.3
CVE-2020-29582

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker wa

7.3
CVE-2020-28895

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated b

7.8
CVE-2021-3345

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest

7.5
CVE-2021-3326

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences i

7.5
CVE-2021-26117

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for

7.8
CVE-2021-3156 KEV

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege

6.5
CVE-2021-26272

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL

6.5
CVE-2021-26271

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted tex

8.8
CVE-2020-9492

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO auth

8.2
CVE-2020-4949

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w

5.3
CVE-2021-21275

The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was

6.3
CVE-2020-8554

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.exter

6.0
CVE-2021-2131

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

4.4
CVE-2021-2130

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

7.9
CVE-2021-2129

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

6.5
CVE-2021-2128

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

4.4
CVE-2021-2127

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

6.0
CVE-2021-2126

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

4.6
CVE-2021-2125

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

6.0
CVE-2021-2124

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

3.2
CVE-2021-2123

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

4.9
CVE-2021-2122

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected

6.0
CVE-2021-2121

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

6.0
CVE-2021-2120

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

6.0
CVE-2021-2119

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that

8.2
CVE-2021-2118

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supporte

5.4
CVE-2021-2117

Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported versio

5.4
CVE-2021-2116

Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported v

7.6
CVE-2021-2115

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supporte

8.2
CVE-2021-2114

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Cal

4.3
CVE-2021-2113

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli

Frequently Asked Questions

How many CVEs affect Oracle?

Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Oracle vulnerabilities?

Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Oracle vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Oracle Vulnerabilities

CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.

Get Started