Oracle vendor intelligence

Oracle Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Oracle products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Oracle KEVs Full KEV feed
Total KEVs
55
Known exploited vulnerabilities affecting Oracle products
In CISA KEV
44
Records also listed in the official catalog
Beyond CISA KEV
11
Additional exploited CVEs absent from CISA KEV
Sensor Observed
10
Oracle KEVs with sensor-observed exploitation activity

The catalog gap matters for Oracle exposure

Eleven of the 55 exploited Oracle CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-fifth of this vendor portfolio.

80%
Covered by CISA
20%
Beyond CISA
24
Product families

Attested Oracle CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2021-2109

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server High Beyond CISA 15 Aug 2026
CVE-2013-3821

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote...

PeopleSoft Products Confirmed Beyond CISA 07 Aug 2026
CVE-2026-46817

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are...

Oracle Payments Confirmed In CISA 29 Jun 2026
CVE-2026-35273

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions...

PeopleSoft Enterprise PeopleTools Confirmed In CISA 11 Jun 2026
CVE-2024-21182

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 01 Jun 2026
CVE-2017-1000028

Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that...

GlassFish Server Open Source Edition High Beyond CISA 07 Aug 2025
CVE-2016-0457

Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote...

E-Business Suite High Beyond CISA 26 Jul 2025
CVE-2022-21500

Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable...

User Management High Beyond CISA 26 Jul 2025
CVE-2019-2768

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The...

BI Publisher (formerly XML Publisher) High Beyond CISA 15 Jul 2025
CVE-2018-2894

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are...

WebLogic Server Confirmed Beyond CISA 07 Jun 2025
CVE-2025-61757

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are...

Identity Manager Confirmed In CISA 01 Jun 2026
CVE-2025-61884

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are...

Oracle Configurator Confirmed In CISA 01 Jun 2026
CVE-2025-61882

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions...

Oracle Concurrent Processing Confirmed In CISA 29 May 2026
CVE-2013-1493

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40...

Java SE High Beyond CISA 04 Mar 2013
CVE-2020-14883

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 03 Nov 2021
CVE-2020-14882

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 03 Nov 2021
CVE-2020-14750

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 03 Nov 2021
CVE-2015-4852

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary...

WebLogic Server Confirmed In CISA 03 Nov 2021
CVE-2020-14871

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected...

Solaris Operating System Confirmed In CISA 03 Nov 2021
CVE-2012-3152

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote...

Fusion Middleware Confirmed In CISA 03 Nov 2021
CVE-2020-2555

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are...

WebCenter Portal, Utilities Framework Confirmed In CISA 03 Nov 2021
CVE-2019-2725

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

Tape Library ACSLS Confirmed In CISA 10 Jan 2022
CVE-2020-14864

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported...

Business Intelligence Enterprise Edition Confirmed In CISA 18 Jan 2022
CVE-2017-10271

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are...

WebLogic Server Confirmed In CISA 10 Feb 2022
CVE-2011-3544

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote...

Java SE Confirmed In CISA 03 Mar 2022
CVE-2012-0507

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and...

Java SE Confirmed In CISA 03 Mar 2022
CVE-2012-1723

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5...

Java SE Confirmed In CISA 03 Mar 2022
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute...

Java SE Confirmed In CISA 03 Mar 2022
CVE-2015-2590

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect...

Java SE Confirmed In CISA 03 Mar 2022
CVE-2015-4902

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to...

Java SE Confirmed In CISA 03 Mar 2022
CVE-2019-2616

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

BI Publisher (formerly XML Publisher) Confirmed In CISA 25 Mar 2022
CVE-2012-0518

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers...

Fusion Middleware Confirmed In CISA 28 Mar 2022
CVE-2012-5076

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to...

Java SE Confirmed In CISA 28 Mar 2022
CVE-2013-2465

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and...

Java SE Confirmed In CISA 28 Mar 2022
CVE-2010-0840

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and...

Java SE Confirmed In CISA 25 May 2022
CVE-2012-1710

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to...

Fusion Middleware Confirmed In CISA 25 May 2022
CVE-2013-0422

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public...

Java Confirmed In CISA 25 May 2022
CVE-2013-0431

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows...

Java SE Confirmed In CISA 25 May 2022
CVE-2013-2423

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote...

Java SE Confirmed In CISA 25 May 2022
CVE-2019-3010

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily...

Solaris Operating System Confirmed In CISA 25 May 2022
CVE-2018-2628

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

WebLogic Server Confirmed In CISA 08 Sep 2022
CVE-2021-35587

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are...

Access Manager Confirmed In CISA 28 Nov 2022
CVE-2022-21587

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are...

Web Applications Desktop Integrator Confirmed In CISA 02 Feb 2023
CVE-2023-21839

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 01 May 2023
CVE-2016-3427

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect...

Java SE Confirmed In CISA 12 May 2023
CVE-2020-2551

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are...

WebLogic Server Confirmed In CISA 16 Nov 2023
CVE-2017-3506

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

WebLogic Server Confirmed In CISA 03 Jun 2024
CVE-2022-21445

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions...

Application Development Framework (ADF) Confirmed In CISA 18 Sep 2024
CVE-2020-14644

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 18 Sep 2024
CVE-2024-21287

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The...

Oracle Agile PLM Framework Confirmed In CISA 21 Nov 2024
CVE-2020-2883

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 07 Jan 2025
CVE-2024-20953

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily...

Agile PLM Framework Confirmed In CISA 24 Feb 2025
CVE-2020-9314

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the...

iPlanet Web Server High Beyond CISA 10 May 2020
CVE-2019-2618

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

WebLogic Server High Beyond CISA 23 Apr 2019
CVE-2019-2588

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

BI Publisher (formerly XML Publisher) High Beyond CISA 23 Apr 2019

Showing 55 of 55 Oracle known exploited vulnerabilities.

Recurring weakness patterns

Access control, missing authentication for critical function, and deserialization account for twenty mapped occurrences across this Oracle KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.