Oracle Corporation vendor intelligence
Oracle Corporation Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Oracle Corporation products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 33
- Known exploited vulnerabilities affecting Oracle Corporation products
- In CISA KEV
- 27
- Records also listed in the official catalog
- Beyond CISA KEV
- 6
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 9
- Oracle Corporation KEVs with sensor-observed exploitation activity
The catalog gap matters for Oracle Corporation exposure
Six of the 33 exploited Oracle Corporation CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 18% of this vendor portfolio.
- 82%
- Covered by CISA
- 18%
- Beyond CISA
- 17
- Product families
Attested Oracle Corporation CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-2109
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | High | Beyond CISA | 15 Aug 2026 |
|
CVE-2026-46817
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are... |
Oracle Payments | Confirmed | In CISA | 29 Jun 2026 |
|
CVE-2026-35273
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions... |
PeopleSoft Enterprise PeopleTools | Confirmed | In CISA | 11 Jun 2026 |
|
CVE-2024-21182
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-21500
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable... |
User Management | High | Beyond CISA | 26 Jul 2025 |
|
CVE-2019-2768
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The... |
BI Publisher (formerly XML Publisher) | High | Beyond CISA | 15 Jul 2025 |
|
CVE-2018-2894
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are... |
WebLogic Server | Confirmed | Beyond CISA | 07 Jun 2025 |
|
CVE-2025-61757
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are... |
Identity Manager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-61884
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are... |
Oracle Configurator | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-61882
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions... |
Oracle Concurrent Processing | Confirmed | In CISA | 29 May 2026 |
|
CVE-2020-14883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14750
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-14871
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected... |
Solaris Operating System | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-2555
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are... |
WebCenter Portal, Utilities Framework | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... |
Tape Library ACSLS | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2020-14864
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported... |
Business Intelligence Enterprise Edition | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2019-2616
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... |
BI Publisher (formerly XML Publisher) | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-3010
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily... |
Solaris Operating System | Confirmed | In CISA | 25 May 2022 |
|
CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2021-35587
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are... |
Access Manager | Confirmed | In CISA | 28 Nov 2022 |
|
CVE-2022-21587
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are... |
Web Applications Desktop Integrator | Confirmed | In CISA | 02 Feb 2023 |
|
CVE-2023-21839
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 01 May 2023 |
|
CVE-2020-2551
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 16 Nov 2023 |
|
CVE-2017-3506
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... |
WebLogic Server | Confirmed | In CISA | 03 Jun 2024 |
|
CVE-2022-21445
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions... |
Application Development Framework (ADF) | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2020-14644
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-21287
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The... |
Oracle Agile PLM Framework | Confirmed | In CISA | 21 Nov 2024 |
|
CVE-2020-2883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 07 Jan 2025 |
|
CVE-2024-20953
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily... |
Agile PLM Framework | Confirmed | In CISA | 24 Feb 2025 |
|
CVE-2019-2618
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... |
WebLogic Server | High | Beyond CISA | 23 Apr 2019 |
|
CVE-2019-2588
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... |
BI Publisher (formerly XML Publisher) | High | Beyond CISA | 23 Apr 2019 |
No Oracle Corporation CVEs match this search or filter.
Showing 33 of 33 Oracle Corporation known exploited vulnerabilities.
Recurring weakness patterns
Missing authentication for critical function, deserialization, and authentication account for fourteen mapped occurrences across this Oracle Corporation KEV portfolio.
CWE-306
Missing Authentication for Critical Function
CWE-502
Deserialization of Untrusted Data
CWE-287
Improper Authentication
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CWE-501
Trust Boundary Violation
CWE-269
Improper Privilege Management
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.