Oracle Corporation Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Oracle Corporation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
32
In CISA KEV
27
Beyond CISA KEV
5
Sensor Observed
8
Virtual Patch Available
5
Oracle Corporation KEVs Added by Year
32 Oracle Corporation KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-46817
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are... |
Oracle Payments | Confirmed | In CISA | 29 Jun 2026 |
|
CVE-2026-35273
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions... |
PeopleSoft Enterprise PeopleTools | Confirmed | In CISA | 11 Jun 2026 |
|
CVE-2024-21182
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-21500
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable... |
User Management | High | Not in CISA | 26 Jul 2025 |
|
CVE-2019-2768
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The... |
BI Publisher (formerly XML Publisher) | High | Not in CISA | 15 Jul 2025 |
|
CVE-2018-2894
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are... |
WebLogic Server | Confirmed | Not in CISA | 07 Jun 2025 |
|
CVE-2025-61757
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are... |
Identity Manager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-61884
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are... |
Oracle Configurator | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-61882
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions... |
Oracle Concurrent Processing | Confirmed | In CISA | 29 May 2026 |
|
CVE-2020-14883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14750
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14871
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected... |
Solaris Operating System | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-2555
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are... |
WebCenter Portal, Utilities Framework | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... |
Tape Library ACSLS | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2020-14864
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported... |
Business Intelligence Enterprise Edition | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2019-2616
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... |
BI Publisher (formerly XML Publisher) | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-3010
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily... |
Solaris Operating System | Confirmed | In CISA | 25 May 2022 |
|
CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2021-35587
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are... |
Access Manager | Confirmed | In CISA | 28 Nov 2022 |
|
CVE-2022-21587
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are... |
Web Applications Desktop Integrator | Confirmed | In CISA | 02 Feb 2023 |
|
CVE-2023-21839
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 01 May 2023 |
|
CVE-2020-2551
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 16 Nov 2023 |
|
CVE-2017-3506
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 03 Jun 2024 |
Common Vulnerability Classes (CWE)
- CWE-306 — Missing Authentication for Critical Function 7
- CWE-502 — Deserialization of Untrusted Data 4
- CWE-287 — Improper Authentication 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
- CWE-501 — Trust Boundary Violation 1
- CWE-269 — Improper Privilege Management 1
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology