Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 43 CVEs matching "oracle" · CISA KEV

CVE-2019-3010KEV
High

Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.

OracleEPSS 47.1%
CVE-2012-1710KEV
High

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.

OracleEPSS 55.4%
CVE-2012-0518KEV
High

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors

OracleEPSS 16.1%
CVE-2013-2465KEV
High

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D

OracleEPSS 93.2%
CVE-2012-5076KEV
High

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.

OracleEPSS 91.7%
CVE-2019-2616KEV
High

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

OracleEPSS 94.2%
CVE-2012-0507KEV
High

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleEPSS 93.6%
CVE-2015-2590KEV
High

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

OracleEPSS 61.5%
CVE-2012-4681KEV
High

The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

OracleEPSS 94.1%
CVE-2012-1723KEV
High

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.

OracleEPSS 94.1%
CVE-2011-3544KEV
High

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleEPSS 92.6%
CVE-2008-3431KEV
High

An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.

OracleEPSS 5.4%
CVE-2015-4902KEV
High

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

OracleEPSS 7.7%
CVE-2017-10271KEV
High

Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.

OracleEPSS 94.4%
CVE-2020-14864KEV
High

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

OracleEPSS 94.0%
CVE-2019-2725KEV
High

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

OracleEPSS 94.5%
CVE-2020-2555KEV
High

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

OracleEPSS 93.1%
CVE-2012-3152KEV
High

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

OracleEPSS 93.5%
CVE-2020-14750KEV
High

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

OracleEPSS 94.4%
CVE-2020-14871KEV
High

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

OracleEPSS 88.9%