Записи oracle
12 967 опубликованных записей вендора oracle.
Профиль для исследователя
- Попали в KEV
- 84 · 0,6 %
- С эксплойтом
- 174 · 1,3 %
- Pre-auth RCE
- 269
- С записью об исправлении
- 22,9 %
- Медиана: публикация → KEV
- 1551 дн.
Повторяющиеся классы
- CWE-284 Improper Access Control1 925
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor334
- CWE-269 Improper Privilege Management310
- CWE-306 Missing Authentication for Critical Function282
- CWE-400 Uncontrolled Resource Consumption281
- CWE-20 Improper Input Validation141
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 000+ записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2017-5638Готовый эксплойт | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Критическая9,8 | KEV | 100,0 % | 10 мар. 2017 г. |
99Срочно | CVE-2017-9841Готовый эксплойт | Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST daphpunit project · phpunit · CWE-94 | Критическая9,8 | KEV | 100,0 % | 27 июн. 2017 г. |
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2013-2251Готовый эксплойт | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2013 г. |
99Срочно | CVE-2020-14882Готовый эксплойт | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).oracle · weblogic server | Критическая9,8 | KEV | 100,0 % | 21 окт. 2020 г. |
99Срочно | CVE-2021-41773Готовый эксплойт | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 5 окт. 2021 г. |
99Срочно | CVE-2021-42013Готовый эксплойт | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 7 окт. 2021 г. |
99Срочно | CVE-2019-2725Готовый эксплойт | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).oracle · agile product lifecycle management · CWE-74 | Критическая9,8 | KEV | 100,0 % | 26 апр. 2019 г. |
99Срочно | CVE-2018-2628Готовый эксплойт | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).oracle · weblogic server · CWE-502 | Критическая9,8 | KEV | 100,0 % | 18 апр. 2018 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2022-22963Готовый эксплойт | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user tovmware · spring cloud function · CWE-94 | Критическая9,8 | KEV | 99,9 % | 1 апр. 2022 г. |
99Срочно | CVE-2025-61882Готовый эксплойт | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).oracle · concurrent processing · CWE-287 | Критическая9,8 | KEV | 99,7 % | 5 окт. 2025 г. |
99Срочно | CVE-2017-1000353Готовый эксплойт | Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.jenkins · jenkins · CWE-502 | Критическая9,8 | KEV | 99,7 % | 29 янв. 2018 г. |
99Срочно | CVE-2022-22965Готовый эксплойт | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Критическая9,8 | KEV | 99,6 % | 1 апр. 2022 г. |
99Срочно | CVE-2020-1938Готовый эксплойт | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Критическая9,8 | KEV | 99,3 % | 24 февр. 2020 г. |
99Срочно | CVE-2020-14750Готовый эксплойт | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).oracle · weblogic server | Критическая9,8 | KEV | 99,3 % | 2 нояб. 2020 г. |
99Срочно | CVE-2013-2465Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Критическая9,8 | KEV | 98,8 % | 18 июн. 2013 г. |
99Срочно | CVE-2012-4681Готовый эксплойт | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Критическая9,8 | KEV | 98,5 % | 27 авг. 2012 г. |
99Срочно | CVE-2022-21587Готовый эксплойт | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).oracle · e-business suite · CWE-306 | Критическая9,8 | KEV | 98,3 % | 18 окт. 2022 г. |
99Срочно | CVE-2022-22947Готовый эксплойт | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuatvmware · spring cloud gateway · CWE-94 | Критическая10,0 | KEV | 98,3 % | 3 мар. 2022 г. |
98Срочно | CVE-2012-0507Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Критическая9,8 | KEV | 98,1 % | 7 июн. 2012 г. |
98Срочно | CVE-2020-2555Готовый эксплойт | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).oracle · access manager · CWE-502 | Критическая9,8 | KEV | 97,1 % | 15 янв. 2020 г. |
98Срочно | CVE-2013-0422Готовый эксплойт | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Критическая9,8 | KEV | 97,0 % | 10 янв. 2013 г. |
98Срочно | CVE-2018-1273Готовый эксплойт | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Критическая9,8 | KEV | 97,0 % | 11 апр. 2018 г. |
98Срочно | CVE-2011-3544Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Критическая9,8 | KEV | 96,7 % | 19 окт. 2011 г. |
- CVE-2017-563899Срочно
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · struts10 мар. 2017 г.
- CVE-2017-984199Срочно
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %phpunit project · phpunit27 июн. 2017 г.
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2013-225199Срочно
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · archiva19 июл. 2013 г.
- CVE-2020-1488299Срочно
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · weblogic server21 окт. 2020 г.
- CVE-2021-4177399Срочно
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server5 окт. 2021 г.
- CVE-2021-4201399Срочно
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server7 окт. 2021 г.
- CVE-2019-272599Срочно
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · agile product lifecycle management26 апр. 2019 г.
- CVE-2018-262899Срочно
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · weblogic server18 апр. 2018 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2022-2296399Срочно
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring cloud function1 апр. 2022 г.
- CVE-2025-6188299Срочно
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · concurrent processing5 окт. 2025 г.
- CVE-2017-100035399Срочно
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %jenkins · jenkins29 янв. 2018 г.
- CVE-2022-2296599Срочно
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring framework1 апр. 2022 г.
- CVE-2020-193899Срочно
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · geode24 февр. 2020 г.
- CVE-2020-1475099Срочно
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · weblogic server2 нояб. 2020 г.
- CVE-2013-246599Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jre18 июн. 2013 г.
- CVE-2012-468199Срочно
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jdk27 авг. 2012 г.
- CVE-2022-2158799Срочно
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %oracle · e-business suite18 окт. 2022 г.
- CVE-2022-2294799Срочно
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %vmware · spring cloud gateway3 мар. 2022 г.
- CVE-2012-050798Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %oracle · jre7 июн. 2012 г.
- CVE-2020-255598Срочно
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · access manager15 янв. 2020 г.
- CVE-2013-042298Срочно
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk10 янв. 2013 г.
- CVE-2018-127398Срочно
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %broadcom · spring data commons11 апр. 2018 г.
- CVE-2011-354498Срочно
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk19 окт. 2011 г.