Oracle Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Oracle products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

53

In CISA KEV

44

Beyond CISA KEV

9

Sensor Observed

8

Virtual Patch Available

5

Oracle KEVs Added by Year

Loading...

53 Oracle KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-9314

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the...

High Not in CISA 10 May 2020
CVE-2019-2618

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

High Not in CISA 23 Apr 2019
CVE-2019-2588

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

High Not in CISA 23 Apr 2019

Common Vulnerability Classes (CWE)

  • CWE-284 — Improper Access Control 8
  • CWE-306 — Missing Authentication for Critical Function 7
  • CWE-502 — Deserialization of Untrusted Data 5
  • CWE-287 — Improper Authentication 3
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
  • CWE-693 — Protection Mechanism Failure 2
  • CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 1
  • CWE-269 — Improper Privilege Management 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology