Oracle
oracle
10,864 CVEs • 1,061 products
Products (1,061)
Click to collapseToggle
Products (1,061)
Click to collapse
CVEs (10,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Liquibase Oracle2Liquibase SqlclJun 17, 2026 Mar 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0. |
2Oracle Vmware10Commerce Guided Search Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Console+7 moreJun 17, 2026 Mar 3, 2022 N/A· v4 10.0 CRITICAL· v3 6.8 MEDIUM· v2 In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a ma...Show more |
4Debian FedoraprojectLinux+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Mar 3, 2022 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages...Show more |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Mar 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version iden...Show more |
5Debian LinuxNetapp+2 more18Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+15 moreJun 17, 2026 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can s...Show more |
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreJun 17, 2026 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
2Jetbrains Oracle3Communications Cloud Native Core Binding Support Function Communications Pricing Design CenterKotlinJun 17, 2026 Feb 25, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects. |
4Debian NetappNodejs+1 more11Debian Linux Mysql ClusterMysql Connectors+8 moreJun 17, 2026 Feb 24, 2022 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one proper...Show more |
3Debian NodejsOracle9Debian Linux GraalvmMysql Cluster+6 moreJun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name th...Show more |
3Debian NodejsOracle9Debian Linux GraalvmMysql Cluster+6 moreJun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string...Show more |
2Nodejs Oracle8Graalvm Mysql ClusterMysql Connectors+5 moreJun 17, 2026 Feb 24, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2...Show more |
4Debian LinuxNetapp+1 more13Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+10 moreJun 17, 2026 Feb 24, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload. |
5Cyrusimap DebianFedoraproject+2 more8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Network Function Cloud Native Environment+5 moreJun 17, 2026 Feb 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. |
1Oracle 1Talent Acquisition Cloud Jun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Feb 21, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outa...Show more |
5Debian FedoraprojectLinux+2 more21Active Iq Unified Manager Aff A700s FirmwareAff Baseboard Management Controller Firmware+18 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remo...Show more |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element. |
2Oracle Traefik2Communications Unified Inventory Management TraefikJun 17, 2026 Feb 17, 2022 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a reques...Show more |