Oracle
18,434 known vulnerabilities
Top Products
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnera
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthent
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An una
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC p
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, l
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verificatio
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcar
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP add
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injecti
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet inject
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive inf
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be u
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's impleme
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers,
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allow
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request U
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementatio
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2
Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerabl
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source characte
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the dat
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to ru
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attri
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerbero
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via H
Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 19c.
Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported versio
Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version
Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Lo
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Suppor
Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: System Wide). Suppo
Frequently Asked Questions
How many CVEs affect Oracle?
Oracle has 18,434 CVE records in our database, including 1653 critical and 6617 high severity vulnerabilities. 49 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Oracle vulnerabilities?
Oracle has 1653 critical severity (CVSS 9.0+) and 6617 high severity (CVSS 7.0-8.9) vulnerabilities. 49 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Oracle vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Oracle products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Oracle Vulnerabilities
CyberStrike scans your infrastructure for Oracle vulnerabilities and provides real-time remediation guidance.
Get Started