Oracle Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Oracle products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
53
In CISA KEV
44
Beyond CISA KEV
9
Sensor Observed
8
Virtual Patch Available
5
Oracle KEVs Added by Year
53 Oracle KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-46817
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are... |
Oracle Payments | Confirmed | In CISA | 29 Jun 2026 |
|
CVE-2026-35273
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions... |
PeopleSoft Enterprise PeopleTools | Confirmed | In CISA | 11 Jun 2026 |
|
CVE-2024-21182
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2017-1000028
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that... |
GlassFish Server Open Source Edition | High | Not in CISA | 07 Aug 2025 |
|
CVE-2016-0457
Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote... |
E-Business Suite | High | Not in CISA | 26 Jul 2025 |
|
CVE-2022-21500
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable... |
User Management | High | Not in CISA | 26 Jul 2025 |
|
CVE-2019-2768
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The... |
BI Publisher (formerly XML Publisher) | High | Not in CISA | 15 Jul 2025 |
|
CVE-2018-2894
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are... |
WebLogic Server | Confirmed | Not in CISA | 07 Jun 2025 |
|
CVE-2025-61757
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are... |
Identity Manager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-61884
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are... |
Oracle Configurator | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-61882
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions... |
Oracle Concurrent Processing | Confirmed | In CISA | 29 May 2026 |
|
CVE-2013-1493
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40... |
Java SE | High | Not in CISA | 04 Mar 2013 |
|
CVE-2020-14883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14750
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2015-4852
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14871
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected... |
Solaris Operating System | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2012-3152
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote... |
Fusion Middleware | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-2555
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are... |
WebCenter Portal, Utilities Framework | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... |
Tape Library ACSLS | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2020-14864
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported... |
Business Intelligence Enterprise Edition | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2011-3544
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote... |
Java SE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2012-0507
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and... |
Java SE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2012-1723
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5... |
Java SE | Confirmed | In CISA | 03 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-284 — Improper Access Control 8
- CWE-306 — Missing Authentication for Critical Function 7
- CWE-502 — Deserialization of Untrusted Data 5
- CWE-287 — Improper Authentication 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
- CWE-693 — Protection Mechanism Failure 2
- CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
- CWE-269 — Improper Privilege Management 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology