Oracle Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Oracle products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
53
In CISA KEV
44
Beyond CISA KEV
9
Sensor Observed
8
Virtual Patch Available
5
Oracle KEVs Added by Year
53 Oracle KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2012-4681
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute... |
Java SE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-2590
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect... |
Java SE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-4902
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to... |
Java SE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2019-2616
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... |
BI Publisher (formerly XML Publisher) | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2012-0518
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers... |
Fusion Middleware | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2012-5076
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to... |
Java SE | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2013-2465
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and... |
Java SE | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2010-0840
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and... |
Java SE | Confirmed | In CISA | 25 May 2022 |
|
CVE-2012-1710
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to... |
Fusion Middleware | Confirmed | In CISA | 25 May 2022 |
|
CVE-2013-0422
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public... |
Java | Confirmed | In CISA | 25 May 2022 |
|
CVE-2013-0431
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows... |
Java SE | Confirmed | In CISA | 25 May 2022 |
|
CVE-2013-2423
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote... |
Java SE | Confirmed | In CISA | 25 May 2022 |
|
CVE-2019-3010
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily... |
Solaris Operating System | Confirmed | In CISA | 25 May 2022 |
|
CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2021-35587
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are... |
Access Manager | Confirmed | In CISA | 28 Nov 2022 |
|
CVE-2022-21587
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are... |
Web Applications Desktop Integrator | Confirmed | In CISA | 02 Feb 2023 |
|
CVE-2023-21839
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 01 May 2023 |
|
CVE-2016-3427
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect... |
Java SE | Confirmed | In CISA | 12 May 2023 |
|
CVE-2020-2551
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 16 Nov 2023 |
|
CVE-2017-3506
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 03 Jun 2024 |
|
CVE-2022-21445
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions... |
Application Development Framework (ADF) | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2020-14644
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-21287
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The... |
Oracle Agile PLM Framework | Confirmed | In CISA | 21 Nov 2024 |
|
CVE-2020-2883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 07 Jan 2025 |
|
CVE-2024-20953
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily... |
Agile PLM Framework | Confirmed | In CISA | 24 Feb 2025 |
Common Vulnerability Classes (CWE)
- CWE-284 — Improper Access Control 8
- CWE-306 — Missing Authentication for Critical Function 7
- CWE-502 — Deserialization of Untrusted Data 5
- CWE-287 — Improper Authentication 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
- CWE-693 — Protection Mechanism Failure 2
- CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
- CWE-269 — Improper Privilege Management 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology