oracle records
12,967 published records for vendor oracle.
Researcher profile
- Entered KEV
- 84 · 0.6%
- Weaponized
- 174 · 1.3%
- Pre-auth RCE
- 269
- With a fix record
- 22.9%
- Median publish → KEV
- 1551 days
Recurring classes
- CWE-284 Improper Access Control1,925
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor334
- CWE-269 Improper Privilege Management310
- CWE-306 Missing Authentication for Critical Function282
- CWE-400 Uncontrolled Resource Consumption281
- CWE-20 Improper Input Validation141
The weakness classes this vendor ships most often: where to look.
CWEAll records
10,000+ records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2017-5638Weaponized | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Critical9.8 | KEV | 100.0% | Mar 10, 2017 |
99Now | CVE-2017-9841Weaponized | Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST daphpunit project · phpunit · CWE-94 | Critical9.8 | KEV | 100.0% | Jun 27, 2017 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2013-2251Weaponized | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Critical9.8 | KEV | 100.0% | Jul 19, 2013 |
99Now | CVE-2020-14882Weaponized | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).oracle · weblogic server | Critical9.8 | KEV | 100.0% | Oct 21, 2020 |
99Now | CVE-2021-41773Weaponized | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 5, 2021 |
99Now | CVE-2021-42013Weaponized | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 7, 2021 |
99Now | CVE-2019-2725Weaponized | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).oracle · agile product lifecycle management · CWE-74 | Critical9.8 | KEV | 100.0% | Apr 26, 2019 |
99Now | CVE-2018-2628Weaponized | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).oracle · weblogic server · CWE-502 | Critical9.8 | KEV | 100.0% | Apr 18, 2018 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2022-22963Weaponized | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user tovmware · spring cloud function · CWE-94 | Critical9.8 | KEV | 99.9% | Apr 1, 2022 |
99Now | CVE-2025-61882Weaponized | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).oracle · concurrent processing · CWE-287 | Critical9.8 | KEV | 99.7% | Oct 5, 2025 |
99Now | CVE-2017-1000353Weaponized | Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.jenkins · jenkins · CWE-502 | Critical9.8 | KEV | 99.7% | Jan 29, 2018 |
99Now | CVE-2022-22965Weaponized | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Critical9.8 | KEV | 99.6% | Apr 1, 2022 |
99Now | CVE-2020-1938Weaponized | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Critical9.8 | KEV | 99.3% | Feb 24, 2020 |
99Now | CVE-2020-14750Weaponized | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).oracle · weblogic server | Critical9.8 | KEV | 99.3% | Nov 2, 2020 |
99Now | CVE-2013-2465Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Critical9.8 | KEV | 98.8% | Jun 18, 2013 |
99Now | CVE-2012-4681Weaponized | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Critical9.8 | KEV | 98.5% | Aug 27, 2012 |
99Now | CVE-2022-21587Weaponized | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).oracle · e-business suite · CWE-306 | Critical9.8 | KEV | 98.3% | Oct 18, 2022 |
99Now | CVE-2022-22947Weaponized | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuatvmware · spring cloud gateway · CWE-94 | Critical10.0 | KEV | 98.3% | Mar 3, 2022 |
98Now | CVE-2012-0507Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Critical9.8 | KEV | 98.1% | Jun 7, 2012 |
98Now | CVE-2020-2555Weaponized | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).oracle · access manager · CWE-502 | Critical9.8 | KEV | 97.1% | Jan 15, 2020 |
98Now | CVE-2013-0422Weaponized | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Critical9.8 | KEV | 97.0% | Jan 10, 2013 |
98Now | CVE-2018-1273Weaponized | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Critical9.8 | KEV | 97.0% | Apr 11, 2018 |
98Now | CVE-2011-3544Weaponized | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Critical9.8 | KEV | 96.7% | Oct 19, 2011 |
- CVE-2017-563899Now
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · strutsMar 10, 2017
- CVE-2017-984199Now
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da
CriticalCVSS 9.8KEVWeaponizedEPSS 100%phpunit project · phpunitJun 27, 2017
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2013-225199Now
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · archivaJul 19, 2013
- CVE-2020-1488299Now
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · weblogic serverOct 21, 2020
- CVE-2021-4177399Now
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 5, 2021
- CVE-2021-4201399Now
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 7, 2021
- CVE-2019-272599Now
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · agile product lifecycle managementApr 26, 2019
- CVE-2018-262899Now
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · weblogic serverApr 18, 2018
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2022-2296399Now
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · spring cloud functionApr 1, 2022
- CVE-2025-6188299Now
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · concurrent processingOct 5, 2025
- CVE-2017-100035399Now
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%jenkins · jenkinsJan 29, 2018
- CVE-2022-2296599Now
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · spring frameworkApr 1, 2022
- CVE-2020-193899Now
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · geodeFeb 24, 2020
- CVE-2020-1475099Now
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · weblogic serverNov 2, 2020
- CVE-2013-246599Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · jreJun 18, 2013
- CVE-2012-468199Now
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · jdkAug 27, 2012
- CVE-2022-2158799Now
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
CriticalCVSS 9.8KEVWeaponizedEPSS 98%oracle · e-business suiteOct 18, 2022
- CVE-2022-2294799Now
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat
CriticalCVSS 10.0KEVWeaponizedEPSS 98%vmware · spring cloud gatewayMar 3, 2022
- CVE-2012-050798Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
CriticalCVSS 9.8KEVWeaponizedEPSS 98%oracle · jreJun 7, 2012
- CVE-2020-255598Now
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · access managerJan 15, 2020
- CVE-2013-042298Now
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkJan 10, 2013
- CVE-2018-127398Now
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
CriticalCVSS 9.8KEVWeaponizedEPSS 97%broadcom · spring data commonsApr 11, 2018
- CVE-2011-354498Now
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkOct 19, 2011