← Back to Vendors

oracle

Security Vendor Profile

1,005
Products
93,946
Total CVEs
6,140
Critical
11,332
High
45,884
Medium
30,590
Low

Average CVSS Score

4.17

Top Products by CVE Count

jre
182 Critical 564 CVEs
jdk
166 Critical 516 CVEs
jre
148 Critical 436 CVEs
jdk
132 Critical 410 CVEs
jre
77 Critical 377 CVEs
jdk
74 Critical 365 CVEs
solaris
29 Critical 285 CVEs
linux
17 Critical 184 CVEs
jre
75 Critical 176 CVEs
mysql
162 CVEs

Recent CVEs

Product: identity_manager

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Servi...

Published: Mar 20, 2026

9.8

CVSS

Product: web_services_manager

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Servi...

Published: Mar 20, 2026

9.8

CVSS

Product: okit

Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0....

Published: Mar 17, 2026

9.8

CVSS

Product: linux

A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names....

Published: Mar 16, 2026

5.5

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

8.2

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

8.1

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

8.2

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

8.2

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows unaut...

Published: Jan 20, 2026

7.1

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

6.0

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows hig...

Published: Jan 20, 2026

7.5

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows hig...

Published: Jan 20, 2026

7.5

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows una...

Published: Jan 20, 2026

7.5

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

4.6

CVSS

Product: life_sciences_central_coding

Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable v...

Published: Jan 20, 2026

6.5

CVSS

Product: flexcube_universal_banking

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Relationship Pricing). Supported versions that are affected are 14.0.0.0.0-14.8.0....

Published: Jan 20, 2026

6.5

CVSS

Product: business_intelligence

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Oracle Analytics Cloud). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0...

Published: Jan 20, 2026

7.1

CVSS

Product: java_virtual_machine

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 and 21.3-21.20. Easily exploitable vulnerability allows high privileged attacker...

Published: Jan 20, 2026

4.5

CVSS

Product: life_sciences_central_designer

Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable...

Published: Jan 20, 2026

5.3

CVSS

Product: flexcube_investor_servicing

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 14.5.0.15.0...

Published: Jan 20, 2026

8.1

CVSS

Product: configurator

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allo...

Published: Jan 20, 2026

5.3

CVSS

Product: peoplesoft_supply_chain_management_purchasing

Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows...

Published: Jan 20, 2026

5.4

CVSS

Product: life_sciences_central_designer

Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable...

Published: Jan 20, 2026

6.5

CVSS

Product: agile_product_lifecycle_management_for_process

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The supported version that is affected is 6.2.4. Easily exploi...

Published: Jan 20, 2026

9.8

CVSS

Product: mysql_server

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulne...

Published: Jan 20, 2026

6.5

CVSS

Product: hospitality_opera_5

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5....

Published: Jan 20, 2026

8.6

CVSS

Product: hospitality_opera_5

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26....

Published: Jan 20, 2026

6.1

CVSS

Product: mysql_server

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privi...

Published: Jan 20, 2026

2.7

CVSS

Product: mysql

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable ...

Published: Jan 20, 2026

4.9

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

6.0

CVSS

Product: http_server

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Prox...

Published: Jan 20, 2026

10.0

CVSS

Product: weblogic_server_proxy_plug-in

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Prox...

Published: Jan 20, 2026

10.0

CVSS

Product: peoplesoft_enterprise_hcm_human_resources

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Company Dir / Org Chart Viewer, Employee Snapshot). The supported version that is affected is ...

Published: Jan 20, 2026

6.1

CVSS

Product: applications_dba

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allo...

Published: Jan 20, 2026

6.5

CVSS

Product: workflow

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows ...

Published: Jan 20, 2026

4.9

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows hig...

Published: Jan 20, 2026

7.5

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

8.2

CVSS

Product: vm_virtualbox

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high ...

Published: Jan 20, 2026

8.2

CVSS

Product: mysql_server

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged at...

Published: Jan 20, 2026

4.9

CVSS

Product: peoplesoft_enterprise_peopletools

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable ...

Published: Jan 20, 2026

6.1

CVSS

Product: mysql_server

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged ...

Published: Jan 20, 2026

6.5

CVSS

Product: mysql_server

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged ...

Published: Jan 20, 2026

6.5

CVSS

Product: mysql_server

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulne...

Published: Jan 20, 2026

4.9

CVSS

Product: jdk

Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with networ...

Published: Jan 20, 2026

3.1

CVSS

Product: jre

Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with networ...

Published: Jan 20, 2026

3.1

CVSS

Product: jd_edwards_enterpriseone_tools

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.0. Easily exploitable vulnerabil...

Published: Jan 20, 2026

6.1

CVSS

Product: graalvm

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE...

Published: Jan 20, 2026

7.5

CVSS

Product: graalvm_for_jdk

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE...

Published: Jan 20, 2026

7.5

CVSS

Product: jdk

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE...

Published: Jan 20, 2026

7.5

CVSS

Product: jre

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE...

Published: Jan 20, 2026

7.5

CVSS