Oracle Corporation Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Oracle Corporation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
32
In CISA KEV
27
Beyond CISA KEV
5
Sensor Observed
8
Virtual Patch Available
5
Oracle Corporation KEVs Added by Year
32 Oracle Corporation KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-21445
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions... |
Application Development Framework (ADF) | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2020-14644
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-21287
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The... |
Oracle Agile PLM Framework | Confirmed | In CISA | 21 Nov 2024 |
|
CVE-2020-2883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 07 Jan 2025 |
|
CVE-2024-20953
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily... |
Agile PLM Framework | Confirmed | In CISA | 24 Feb 2025 |
|
CVE-2019-2618
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... |
WebLogic Server | High | Not in CISA | 23 Apr 2019 |
|
CVE-2019-2588
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... |
BI Publisher (formerly XML Publisher) | High | Not in CISA | 23 Apr 2019 |
Common Vulnerability Classes (CWE)
- CWE-306 — Missing Authentication for Critical Function 7
- CWE-502 — Deserialization of Untrusted Data 4
- CWE-287 — Improper Authentication 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
- CWE-501 — Trust Boundary Violation 1
- CWE-269 — Improper Privilege Management 1
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology