Oracle Corporation Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Oracle Corporation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

32

In CISA KEV

27

Beyond CISA KEV

5

Sensor Observed

8

Virtual Patch Available

5

Oracle Corporation KEVs Added by Year

Loading...

32 Oracle Corporation KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-46817

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are...

Confirmed In CISA 29 Jun 2026
CVE-2026-35273

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions...

Confirmed In CISA 11 Jun 2026
CVE-2024-21182

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

Confirmed In CISA 01 Jun 2026
CVE-2022-21500

Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable...

High Not in CISA 26 Jul 2025
CVE-2019-2768

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The...

High Not in CISA 15 Jul 2025
CVE-2018-2894

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are...

Confirmed Not in CISA 07 Jun 2025
CVE-2025-61757

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are...

Confirmed In CISA 01 Jun 2026
CVE-2025-61884

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are...

Confirmed In CISA 01 Jun 2026
CVE-2025-61882

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions...

Confirmed In CISA 29 May 2026
CVE-2020-14883

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

Confirmed In CISA 03 Nov 2021
CVE-2020-14882

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

Confirmed In CISA 03 Nov 2021
CVE-2020-14750

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

Confirmed In CISA 03 Nov 2021
CVE-2020-14871

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected...

Confirmed In CISA 03 Nov 2021
CVE-2020-2555

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are...

Confirmed In CISA 03 Nov 2021
CVE-2019-2725

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

Confirmed In CISA 10 Jan 2022
CVE-2020-14864

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported...

Confirmed In CISA 18 Jan 2022
CVE-2017-10271

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are...

Confirmed In CISA 10 Feb 2022
CVE-2019-2616

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

Confirmed In CISA 25 Mar 2022
CVE-2019-3010

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily...

Confirmed In CISA 25 May 2022
CVE-2018-2628

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

Confirmed In CISA 08 Sep 2022
CVE-2021-35587

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are...

Confirmed In CISA 28 Nov 2022
CVE-2022-21587

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are...

Confirmed In CISA 02 Feb 2023
CVE-2023-21839

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

Confirmed In CISA 01 May 2023
CVE-2020-2551

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are...

Confirmed In CISA 16 Nov 2023
CVE-2017-3506

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

Confirmed In CISA 03 Jun 2024

Common Vulnerability Classes (CWE)

  • CWE-306 — Missing Authentication for Critical Function 7
  • CWE-502 — Deserialization of Untrusted Data 4
  • CWE-287 — Improper Authentication 3
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
  • CWE-501 — Trust Boundary Violation 1
  • CWE-269 — Improper Privilege Management 1
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology