İçeriğe atla
Noroxi

oracle kayıtları

oracle üreticisine ait 12.967 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
84 · %0,6
Silahlaştırılmış
174 · %1,3
Pre-auth RCE
269
Düzeltme kaydı olan
%22,9
Yayından KEV’e ortanca
1551 gün

Tüm kayıtlar

10.000+ kayıt
  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · struts10 Mar 2017

  • Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    phpunit project · phpunit27 Haz 2017

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · archiva19 Tem 2013

  • Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · weblogic server21 Eki 2020

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server5 Eki 2021

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server7 Eki 2021

  • Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · agile product lifecycle management26 Nis 2019

  • Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · weblogic server18 Nis 2018

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · spring cloud function1 Nis 2022

  • Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · concurrent processing5 Eki 2025

  • Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    jenkins · jenkins29 Oca 2018

  • A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · spring framework1 Nis 2022

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · geode24 Şub 2020

  • Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    oracle · weblogic server2 Kas 2020

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    oracle · jre18 Haz 2013

  • Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    oracle · jdk27 Ağu 2012

  • Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    oracle · e-business suite18 Eki 2022

  • In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %98

    vmware · spring cloud gateway3 Mar 2022

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    oracle · jre7 Haz 2012

  • Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    oracle · access manager15 Oca 2020

  • Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    oracle · jdk10 Oca 2013

  • Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    broadcom · spring data commons11 Nis 2018

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    oracle · jdk19 Eki 2011