Browse vulnerabilities
2,346 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an origin server … |
| CVE-2020-14882 | Act now | 100.0% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow f… |
| CVE-2017-10271 | Act now | 100.0% | 7.5 | ● | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomp… |
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.4… |
| CVE-2019-2725 | Act now | 100.0% | 9.8 | ● | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomp… |
| CVE-2023-21839 | Act now | 99.9% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticate… |
| CVE-2025-61882 | Act now | 99.7% | 9.8 | ● | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (comp… |
| CVE-2018-2628 | Act now | 99.4% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenti… |
| CVE-2020-14750 | Act now | 99.3% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated a… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming conn… |
| CVE-2013-2465 | Act now | 98.8% | — | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2012-3152 | Act now | 98.8% | — | ● | Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allo… |
| CVE-2012-4681 | Act now | 98.5% | 9.8 | ● | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE… |
| CVE-2022-21587 | Act now | 98.3% | — | ● | Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticat… |
| CVE-2012-0507 | Act now | 98.1% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2020-14883 | Act now | 97.9% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability in the Console component with… |
| CVE-2020-2555 | Act now | 97.1% | — | ● | Multiple Oracle products contain a remote code execution vulnerability that allows an unau… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupporte… |
| CVE-2011-3544 | Act now | 96.7% | — | ● | An access control vulnerability exists in the Applet Rhino Script Engine component of Orac… |
| CVE-2021-35587 | Act now | 96.3% | — | ● | Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network ac… |
| CVE-2017-3506 | Act now | 96.3% | — | ● | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS comma… |
| CVE-2015-4852 | Act now | 96.0% | — | ● | Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within A… |
| CVE-2025-61884 | Act now | 95.9% | 7.5 | ● | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Ru… |
| CVE-2026-35273 | Act now | 95.5% | 9.8 | ● | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (compo… |
| CVE-2020-2883 | Act now | 94.9% | — | ● | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecif… |
| CVE-2021-4034 | Act now | 94.9% | 7.8 | ● | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexe… |
| CVE-2020-14644 | Act now | 94.5% | — | ● | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deseriali… |
| CVE-2012-1723 | Act now | 93.7% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2020-2551 | Act now | 93.2% | — | ● | Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components … |
| CVE-2016-3427 | Act now | 92.3% | — | ● | Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attack… |
| CVE-2019-2616 | Act now | 92.2% | — | ● | Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that al… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x… |
| CVE-2013-0431 | Act now | 90.3% | 5.3 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2025-61757 | Act now | 88.3% | — | ● | Oracle Fusion Middleware contains a missing authentication for critical function vulnerabi… |
| CVE-2020-14871 | Act now | 80.2% | — | ● | Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability c… |
| CVE-2024-21182 | Act now | 74.2% | — | ● | Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated … |
| CVE-2022-21445 | Act now | 62.5% | — | ● | Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deseria… |
| CVE-2026-21962 | Act now | 42.5% | 10.0 | ● | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of O… |
| CVE-2015-2590 | Act now | 25.5% | — | ● | An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an … |
| CVE-2015-4902 | Act now | 13.6% | — | ● | Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity vi… |
| CVE-2019-3010 | Act now | 13.4% | — | ● | Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows f… |
| CVE-2026-46817 | Act now | 13.0% | 9.8 | ● | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File T… |
| CVE-2012-1710 | Act now | 11.4% | 9.8 | ● | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fu… |
| CVE-2015-5287 | Act now | 5.0% | 7.8 | ● | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows… |
| CVE-2012-0518 | Act now | 4.7% | — | ● | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Ora… |
| CVE-2024-20953 | Act now | 3.9% | — | ● | Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability t… |
| CVE-2024-21287 | Act now | 1.7% | — | ● | Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulner… |
| CVE-2021-45105 | High | 100.0% | 5.9 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not prot… | |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.… | |
| CVE-2021-33037 | High | 75.4% | 5.3 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctl… |
Page 1 of 47
Next →