CPUJAN2025 Critical

Oracle Critical Patch Update Advisory - January 2025

Oracle Released: January 21, 2025 Updated: January 21, 2026 Restart Required

Fixed Vulnerabilities 218

CVE-2024-38475 N/A 0.9 ⚠️ KEV fixed
Jul 01, 2024

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to…

CVE-2024-38816 N/A 0.9 ⚠️ KEV fixed
Sep 13, 2024

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests…

CVE-2024-53677 N/A 0.9 ⚠️ KEV fixed
Dec 11, 2024

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead…

CVE-2024-38819 N/A 0.9 ⚠️ KEV fixed
Dec 19, 2024

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests…

CVE-2024-2961 N/A 0.9 ⚠️ KEV fixed
Apr 17, 2024

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes…

CVE-2024-38473 N/A 0.9 ⚠️ KEV fixed
Jul 01, 2024

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing…

CVE-2024-50379 N/A 0.9 ⚠️ KEV fixed
Dec 17, 2024

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is…

CVE-2024-38526 N/A 0.8 ⚠️ KEV fixed
Jun 26, 2024

pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and…

CVE-2024-27983 N/A 0.8 ⚠️ KEV fixed
Apr 09, 2024

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside.…

CVE-2024-21287 N/A 0.7 ⚠️ KEV fixed
Nov 18, 2024

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is…

CVE-2024-24549 N/A 0.6 ⚠️ KEV fixed
Mar 13, 2024

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any…

CVE-2016-1000027 N/A 0.6 ⚠️ KEV fixed
Jan 02, 2020

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how…

CVE-2024-34750 N/A 0.2 ⚠️ KEV fixed
Jul 03, 2024

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive…

CVE-2024-41817 N/A 0.2 ⚠️ KEV fixed
Jul 29, 2024

ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when…

CVE-2024-3596 N/A 0.1 ⚠️ KEV fixed
Jul 09, 2024

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to…

CVE-2024-22262 N/A 0.1 ⚠️ KEV fixed
Apr 16, 2024

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may…

CVE-2023-50868 N/A 0.1 ⚠️ KEV fixed
Feb 14, 2024

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial…

CVE-2024-56337 N/A 0.1 ⚠️ KEV fixed
Dec 20, 2024

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through…

CVE-2024-7885 N/A 0.1 ⚠️ KEV fixed
Aug 21, 2024

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes…

CVE-2024-27280 N/A 0.1 ⚠️ KEV fixed
May 14, 2024

A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on…

CVE-2024-6119 N/A 0.1 ⚠️ KEV fixed
Sep 03, 2024

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination…

CVE-2024-5535 N/A 0.1 ⚠️ KEV fixed
Jun 27, 2024

Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent…

CVE-2024-6232 N/A 0.0 ⚠️ KEV fixed
Sep 03, 2024

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar…

CVE-2023-38709 N/A 0.0 ⚠️ KEV fixed
Apr 04, 2024

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through…

CVE-2024-2511 N/A 0.0 ⚠️ KEV fixed
Apr 08, 2024

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations…

CVE-2024-37371 N/A 0.0 ⚠️ KEV fixed
Jun 28, 2024

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with…

CVE-2023-6129 N/A 0.0 ⚠️ KEV fixed
Jan 09, 2024

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based…

CVE-2024-52316 N/A 0.0 ⚠️ KEV fixed
Nov 18, 2024

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception…

CVE-2024-28834 N/A 0.0 ⚠️ KEV fixed
Mar 21, 2024

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks.…

CVE-2024-27281 N/A 0.0 ⚠️ KEV fixed
May 14, 2024

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as…

CVE-2024-6162 N/A 0.0 ⚠️ KEV fixed
Jun 20, 2024

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the…

CVE-2024-38820 N/A 0.0 ⚠️ KEV fixed
Oct 18, 2024

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVE-2024-49766 N/A 0.0 ⚠️ KEV fixed
Oct 25, 2024

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's…

CVE-2024-23672 N/A 0.0 ⚠️ KEV fixed
Mar 13, 2024

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource…

CVE-2024-54677 N/A 0.0 ⚠️ KEV fixed
Dec 17, 2024

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1…

CVE-2024-28757 N/A 0.0 ⚠️ KEV fixed
Mar 10, 2024

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

CVE-2024-45492 N/A 0.0 ⚠️ KEV fixed
Aug 30, 2024

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVE-2025-21524 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported versions that are affected are Prior to…

CVE-2024-4032 N/A 0.0 ⚠️ KEV fixed
Jun 17, 2024

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and…

CVE-2024-49767 N/A 0.0 ⚠️ KEV fixed
Oct 25, 2024

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data`…

CVE-2024-7592 N/A 0.0 ⚠️ KEV fixed
Aug 19, 2024

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the…

CVE-2024-24791 N/A 0.0 ⚠️ KEV fixed
Jul 02, 2024

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher)…

CVE-2025-21535 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability…

CVE-2024-29133 N/A 0.0 ⚠️ KEV fixed
Mar 21, 2024

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which…

CVE-2025-21556 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily…

CVE-2025-21515 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2024-11053 N/A 0.0 ⚠️ KEV fixed
Dec 11, 2024

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host…

CVE-2024-6763 N/A 0.0 ⚠️ KEV fixed
Oct 14, 2024

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI…

CVE-2024-9143 N/A 0.0 ⚠️ KEV fixed
Oct 16, 2024

Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or…

CVE-2024-33599 N/A 0.0 ⚠️ KEV fixed
May 06, 2024

nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent…

CVE-2023-50782 N/A 0.0 ⚠️ KEV fixed
Feb 05, 2024

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA…

CVE-2024-34064 N/A 0.0 ⚠️ KEV fixed
May 06, 2024

Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`,…

CVE-2024-28849 N/A 0.0 ⚠️ KEV fixed
Mar 14, 2024

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header…

CVE-2024-47561 N/A 0.0 ⚠️ KEV fixed
Oct 03, 2024

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade…

CVE-2023-5678 N/A 0.0 ⚠️ KEV fixed
Nov 06, 2023

Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications that…

CVE-2024-47803 N/A 0.0 ⚠️ KEV fixed
Oct 02, 2024

Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form…

CVE-2024-33602 N/A 0.0 ⚠️ KEV fixed
May 06, 2024

nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does…

CVE-2024-45491 N/A 0.0 ⚠️ KEV fixed
Aug 30, 2024

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVE-2023-7272 N/A 0.0 ⚠️ KEV fixed
Jul 17, 2024

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack…

CVE-2024-27282 N/A 0.0 ⚠️ KEV fixed
May 14, 2024

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary…

CVE-2025-21569 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that is affected is 11.2.19.0.000. Difficult to…

CVE-2024-40898 N/A 0.0 ⚠️ KEV fixed
Jul 18, 2024

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and…

CVE-2024-37370 N/A 0.0 ⚠️ KEV fixed
Jun 28, 2024

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing…

CVE-2024-45490 N/A 0.0 ⚠️ KEV fixed
Aug 30, 2024

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

CVE-2024-8096 N/A 0.0 ⚠️ KEV fixed
Sep 11, 2024

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is…

CVE-2020-13956 N/A 0.0 ⚠️ KEV fixed
Dec 02, 2020

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and…

CVE-2025-21547 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and…

CVE-2024-23807 N/A 0.0 ⚠️ KEV fixed
Feb 29, 2024

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended…

CVE-2025-21565 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability…

CVE-2024-47535 N/A 0.0 ⚠️ KEV fixed
Nov 12, 2024

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file…

CVE-2025-21510 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2025-21564 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily…

CVE-2024-8927 N/A 0.0 ⚠️ KEV fixed
Oct 08, 2024

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run…

CVE-2024-47804 N/A 0.0 ⚠️ KEV fixed
Oct 02, 2024

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API…

CVE-2024-26130 N/A 0.0 ⚠️ KEV fixed
Feb 21, 2024

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates`…

CVE-2025-21552 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to…

CVE-2024-27309 N/A 0.0 ⚠️ KEV fixed
Apr 12, 2024

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions…

CVE-2024-24786 N/A 0.0 ⚠️ KEV fixed
Mar 05, 2024

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which…

CVE-2024-26308 N/A 0.0 ⚠️ KEV fixed
Feb 19, 2024

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to…

CVE-2024-0397 N/A 0.0 ⚠️ KEV fixed
Jun 17, 2024

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race…

CVE-2023-51775 N/A 0.0 ⚠️ KEV fixed
Feb 29, 2024

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVE-2024-22019 N/A 0.0 ⚠️ KEV fixed
Feb 20, 2024

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial…

CVE-2025-21554 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and…

CVE-2025-21545 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows…

CVE-2024-4741 N/A 0.0 ⚠️ KEV fixed
Nov 13, 2024

Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use…

CVE-2025-21514 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2025-21490 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2019-11065 N/A 0.0 ⚠️ KEV fixed
Apr 10, 2019

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency…

CVE-2025-21568 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security). The supported version that is affected is 11.2.19.0.000. Easily…

CVE-2024-29025 N/A 0.0 ⚠️ KEV fixed
Mar 25, 2024

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to…

CVE-2024-33600 N/A 0.0 ⚠️ KEV fixed
May 06, 2024

nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache,…

CVE-2019-15052 N/A 0.0 ⚠️ KEV fixed
Aug 14, 2019

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also…

CVE-2023-4408 N/A 0.0 ⚠️ KEV fixed
Feb 13, 2024

The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic,…

CVE-2025-21562 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). The supported version that is affected is 9.2.…

CVE-2025-21504 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and…

CVE-2024-38827 N/A 0.0 ⚠️ KEV fixed
Dec 02, 2024

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

CVE-2024-43382 N/A 0.0 ⚠️ KEV fixed
Oct 30, 2024

Snowflake JDBC driver versions >= 3.2.6 and

CVE-2025-21516 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows…

CVE-2025-21506 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows…

CVE-2024-21211 N/A 0.0 ⚠️ KEV fixed
Oct 15, 2024

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are…

CVE-2024-38999 N/A 0.0 ⚠️ KEV fixed
Jul 01, 2024

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a…

CVE-2025-21570 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login). The supported version that is affected is 8.2.3. Easily…

CVE-2025-21561 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows…

CVE-2025-21560 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily…

CVE-2025-21527 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2024-47072 N/A 0.0 ⚠️ KEV fixed
Nov 08, 2024

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with…

CVE-2024-36138 N/A 0.0 ⚠️ KEV fixed
Sep 07, 2024

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious…

CVE-2024-37891 N/A 0.0 ⚠️ KEV fixed
Jun 17, 2024

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured…

CVE-2024-28219 N/A 0.0 ⚠️ KEV fixed
Apr 03, 2024

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

CVE-2025-21563 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). The supported version that is affected is 9.2.…

CVE-2024-29857 N/A 0.0 ⚠️ KEV fixed
May 14, 2024

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and…

CVE-2024-29131 N/A 0.0 ⚠️ KEV fixed
Mar 21, 2024

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which…

CVE-2025-21567 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability…

CVE-2025-21511 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2024-6923 N/A 0.0 ⚠️ KEV fixed
Aug 01, 2024

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for…

CVE-2024-0727 N/A 0.0 ⚠️ KEV fixed
Jan 26, 2024

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading…

CVE-2025-21553 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows…

CVE-2025-21509 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2025-21508 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2024-8088 N/A 0.0 ⚠️ KEV fixed
Aug 22, 2024

There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is unaffected. When iterating…

CVE-2025-21530 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability…

CVE-2025-21566 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows…

CVE-2025-21537 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.2. Easily exploitable…

CVE-2025-21512 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2025-21498 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows…

CVE-2024-22018 N/A 0.0 ⚠️ KEV fixed
Jul 10, 2024

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an…

CVE-2024-1442 N/A 0.0 ⚠️ KEV fixed
Mar 07, 2024

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing…

CVE-2025-21550 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.1,…

CVE-2025-21549 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows…

CVE-2025-21502 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are…

CVE-2023-46219 N/A 0.0 ⚠️ KEV fixed
Dec 12, 2023

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of…

CVE-2025-21517 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2024-25638 N/A 0.0 ⚠️ KEV fixed
Jul 22, 2024

dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to…

CVE-2024-47554 N/A 0.0 ⚠️ KEV fixed
Oct 03, 2024

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache…

CVE-2023-27043 N/A 0.0 ⚠️ KEV fixed
Apr 19, 2023

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified…

CVE-2025-21532 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows…

CVE-2025-21522 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and…

CVE-2025-21518 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and…

CVE-2025-21501 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and…

CVE-2025-21500 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and…

CVE-2024-24790 N/A 0.0 ⚠️ KEV fixed
Jun 05, 2024

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in…

CVE-2025-21540 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior…

CVE-2025-21521 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior…

CVE-2024-23635 N/A 0.0 ⚠️ KEV fixed
Feb 02, 2024

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation…

CVE-2019-16370 N/A 0.0 ⚠️ KEV fixed
Sep 16, 2019

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different…

CVE-2025-21544 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and…

CVE-2025-21539 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Easily exploitable vulnerability allows…

CVE-2025-21528 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5,…

CVE-2025-21526 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5,…

CVE-2024-33601 N/A 0.0 ⚠️ KEV fixed
May 06, 2024

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions…

CVE-2024-29041 N/A 0.0 ⚠️ KEV fixed
Mar 25, 2024

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an…

CVE-2024-0450 N/A 0.0 ⚠️ KEV fixed
Mar 19, 2024

An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to…

CVE-2024-22195 N/A 0.0 ⚠️ KEV fixed
Jan 11, 2024

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML…

CVE-2025-21559 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2025-21557 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network…

CVE-2025-21555 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2025-21548 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows high…

CVE-2024-38809 N/A 0.0 ⚠️ KEV fixed
Sep 27, 2024

Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed…

CVE-2024-34447 N/A 0.0 ⚠️ KEV fixed
May 03, 2024

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS)…

CVE-2025-21558 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5,…

CVE-2024-50602 N/A 0.0 ⚠️ KEV fixed
Oct 27, 2024

An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.

CVE-2024-22020 N/A 0.0 ⚠️ KEV fixed
Jul 09, 2024

A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code,…

CVE-2025-21538 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.2.…

CVE-2025-21495 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Enterprise Firewall product of Oracle MySQL (component: Firewall). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and…

CVE-2024-36114 N/A 0.0 ⚠️ KEV fixed
May 29, 2024

Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompressor implementations of Aircompressor (LZ4, LZO, Snappy,…

CVE-2024-21245 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to…

CVE-2023-52428 N/A 0.0 ⚠️ KEV fixed
Feb 11, 2024

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration…

CVE-2025-21523 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2025-21519 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior…

CVE-2025-21499 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.3 and prior and 9.1.0 and prior.…

CVE-2025-21493 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.4.3 and prior and 9.1.0 and…

CVE-2024-30171 N/A 0.0 ⚠️ KEV fixed
May 14, 2024

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of…

CVE-2025-21546 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior…

CVE-2025-21541 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable…

CVE-2025-21513 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2025-21497 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2025-21489 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability…

CVE-2024-7254 N/A 0.0 ⚠️ KEV fixed
Sep 19, 2024

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit…

CVE-2024-4603 N/A 0.0 ⚠️ KEV fixed
May 16, 2024

Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check…

CVE-2025-21543 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and…

CVE-2025-21542 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and…

CVE-2025-21536 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and…

CVE-2025-21534 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior…

CVE-2025-21533 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6.…

CVE-2025-21531 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2025-21529 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior…

CVE-2025-21525 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and…

CVE-2025-21507 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVE-2025-21505 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior…

CVE-2025-21503 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2024-36137 N/A 0.0 ⚠️ KEV fixed
Sep 07, 2024

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not…

CVE-2024-30172 N/A 0.0 ⚠️ KEV fixed
May 14, 2024

An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and…

CVE-2023-52070 N/A 0.0 ⚠️ KEV fixed
Apr 10, 2024

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who…

CVE-2023-6597 N/A 0.0 ⚠️ KEV fixed
Mar 19, 2024

An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks…

CVE-2025-0509 N/A 0.0 ⚠️ KEV fixed
Feb 04, 2025

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing…

CVE-2025-21491 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0…

CVE-2024-45801 N/A 0.0 ⚠️ KEV fixed
Sep 16, 2024

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can…

CVE-2025-21492 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable…

CVE-2024-37372 N/A 0.0 ⚠️ KEV fixed
Jan 09, 2025

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true.…

CVE-2024-45772 N/A 0.0 ⚠️ KEV fixed
Sep 30, 2024

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is…

CVE-2024-38807 N/A 0.0 ⚠️ KEV fixed
Aug 23, 2024

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that…

CVE-2024-35195 N/A 0.0 ⚠️ KEV fixed
May 20, 2024

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable…

CVE-2024-1135 N/A 0.0 ⚠️ KEV fixed
Apr 16, 2024

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security…

CVE-2024-28835 N/A 0.0 ⚠️ KEV fixed
Mar 21, 2024

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the…

CVE-2023-4785 N/A 0.0 ⚠️ KEV fixed
Sep 13, 2023

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a…

CVE-2024-4030 N/A 0.0 ⚠️ KEV fixed
May 07, 2024

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users,…

CVE-2025-21571 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6.…

CVE-2025-21551 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high…

CVE-2025-21520 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and…

CVE-2025-21494 N/A 0.0 ⚠️ KEV fixed
Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior…

CVE-2024-8006 N/A 0.0 ⚠️ KEV fixed
Aug 31, 2024

Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions…

CVE-2023-49582 N/A 0.0 ⚠️ KEV fixed
Aug 26, 2024

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing…

CVE-2024-25710 N/A 0.0 ⚠️ KEV fixed
Feb 19, 2024

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to…

CVE-2024-0232 N/A 0.0 ⚠️ KEV fixed
Jan 16, 2024

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim…

CVE-2019-12415 N/A 0.0 ⚠️ KEV fixed
Oct 23, 2019

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker…

CVE-2023-7256 N/A 0.0 ⚠️ KEV fixed
Aug 31, 2024

In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly…

CVE-2024-24789 N/A 0.0 ⚠️ KEV fixed
Jun 05, 2024

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to…

CVE-2024-38998 ⚠️ KEV fixed
Jul 01, 2024

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not…

Quick Info

Patch ID: CPUJAN2025
Vendor: Oracle
Severity: Critical
CVEs Fixed: 218
Restart: Required

Vendor

Oracle

Additional Info

cpu id: cpujan2025
cve count: 267
cpu quarter: 2025-Q1
rss description:

Share