Oracle Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Oracle products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

53

In CISA KEV

44

Beyond CISA KEV

9

Sensor Observed

8

Virtual Patch Available

5

Oracle KEVs Added by Year

Loading...

53 Oracle KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute...

Confirmed In CISA 03 Mar 2022
CVE-2015-2590

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect...

Confirmed In CISA 03 Mar 2022
CVE-2015-4902

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to...

Confirmed In CISA 03 Mar 2022
CVE-2019-2616

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

Confirmed In CISA 25 Mar 2022
CVE-2012-0518

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers...

Confirmed In CISA 28 Mar 2022
CVE-2012-5076

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to...

Confirmed In CISA 28 Mar 2022
CVE-2013-2465

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and...

Confirmed In CISA 28 Mar 2022
CVE-2010-0840

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and...

Confirmed In CISA 25 May 2022
CVE-2012-1710

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to...

Confirmed In CISA 25 May 2022
CVE-2013-0422

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public...

Confirmed In CISA 25 May 2022
CVE-2013-0431

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows...

Confirmed In CISA 25 May 2022
CVE-2013-2423

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote...

Confirmed In CISA 25 May 2022
CVE-2019-3010

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily...

Confirmed In CISA 25 May 2022
CVE-2018-2628

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

Confirmed In CISA 08 Sep 2022
CVE-2021-35587

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are...

Confirmed In CISA 28 Nov 2022
CVE-2022-21587

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are...

Confirmed In CISA 02 Feb 2023
CVE-2023-21839

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

Confirmed In CISA 01 May 2023
CVE-2016-3427

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect...

Confirmed In CISA 12 May 2023
CVE-2020-2551

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are...

Confirmed In CISA 16 Nov 2023
CVE-2017-3506

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

Confirmed In CISA 03 Jun 2024
CVE-2022-21445

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions...

Confirmed In CISA 18 Sep 2024
CVE-2020-14644

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

Confirmed In CISA 18 Sep 2024
CVE-2024-21287

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The...

Confirmed In CISA 21 Nov 2024
CVE-2020-2883

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

Confirmed In CISA 07 Jan 2025
CVE-2024-20953

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily...

Confirmed In CISA 24 Feb 2025

Common Vulnerability Classes (CWE)

  • CWE-284 — Improper Access Control 8
  • CWE-306 — Missing Authentication for Critical Function 7
  • CWE-502 — Deserialization of Untrusted Data 5
  • CWE-287 — Improper Authentication 3
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
  • CWE-693 — Protection Mechanism Failure 2
  • CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
  • CWE-269 — Improper Privilege Management 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology