Oracle
oracle
10,799 CVEs • 1,059 products
Products (1,059)
Click to collapseToggle
Products (1,059)
Click to collapse
CVEs (10,799)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Alibaba Oracle2Communications Cloud Native Core Unified Data Repository FastjsonJun 17, 2026 Jun 10, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vuln...Show more |
2Debian Oracle2Debian Linux LinuxJun 17, 2026 Jun 9, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect t...Show more |
4Haxx NetappOracle+1 more14Active Iq Unified Manager Bh500s FirmwareClustered Data Ontap+11 moreJun 17, 2026 Jun 2, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. |
2Dell Oracle5Bsafe Micro Edition Suite DatabaseHttp Server+2 moreJun 17, 2026 Jun 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. |
2Dell Oracle4Bsafe Micro Edition Suite Http ServerSecurity Service+1 moreJun 17, 2026 Jun 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability. |
1Oracle 2E Business Suite User ManagementJun 17, 2026 May 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compr...Show more |
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityJun 17, 2026 May 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatc...Show more |
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityJun 17, 2026 May 19, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder...Show more |
2Apache Oracle2Primavera Unifier TikaJun 17, 2026 May 16, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users...Show more |
2Apache Oracle2Primavera Unifier TikaJun 17, 2026 May 16, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. |
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application wil...Show more |
3Netapp OracleVmware4Cloud Secure Agent Financial Services Crime And Compliance Management StudioOncommand Insight+1 moreJun 17, 2026 May 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. |
3Netapp OracleVmware6Active Iq Unified Manager Brocade San NavigatorCloud Secure Agent+3 moreJun 17, 2026 May 12, 2022 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servle...Show more |
3Apache DebianOracle3Debian Linux Hospitality Cruise Shipboard Property Management SystemTomcatJun 17, 2026 May 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted...Show more |
3Netapp NettyOracle5Active Iq Unified Manager Financial Services Crime And Compliance Management StudioNetty+2 moreJun 17, 2026 May 6, 2022 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multip...Show more |
6Debian FedoraprojectNetapp+3 more35A250 Firmware A700s FirmwareActive Iq Unified Manager+32 moreJun 17, 2026 May 3, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more |
5Debian FedoraprojectNetapp+2 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 3, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to...Show more |
4Debian GoogleNetapp+1 more6Active Iq Unified Manager Debian LinuxFinancial Services Crime And Compliance Management Studio+3 moreJun 17, 2026 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
3Netapp OracleOwasp4Active Iq Unified Manager Enterprise Security ApiOncommand Workflow Automation+1 moreJun 17, 2026 Apr 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a inc...Show more |
4Fedoraproject NetappOracle+1 more5Communications Operations Monitor FedoraManagement Services For Element Software+2 moreJun 17, 2026 Apr 27, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of...Show more |