Oracle
oracle
10,864 CVEs • 1,061 products
Products (1,061)
Click to collapseToggle
Products (1,061)
Click to collapse
CVEs (10,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnera...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for t...Show more |
3Netapp OraclePhp3Clustered Data Ontap PhpSd Wan AwareJun 17, 2026 Oct 4, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can b...Show more |
8Apple DebianFedoraproject+5 more26Cloud Backup Clustered Data OntapCommerce Guided Search+23 moreJun 17, 2026 Sep 29, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl woul...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreJun 17, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
5Fedoraproject NetappOpenbsd+2 more12Active Iq Unified Manager Aff 500f FirmwareAff A250 Firmware+9 moreJul 14, 2026 Sep 26, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCom...Show more |
1Oracle 2Engineered Systems Utilities LinuxJun 17, 2026 Sep 24, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Linux...Show more |
8Apple DebianFedoraproject+5 more17Cloud Backup Clustered Data OntapDebian Linux+14 moreJun 17, 2026 Sep 23, 2021 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also...Show more |
3Apache OracleQuarkus8Communications Brm Elastic Charging Engine Communications Cloud Native Core PolicyFinancial Services Analytical Applications Infrastructure+5 moreJun 17, 2026 Sep 22, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgra...Show more |
3Apache DebianOracle18Agile Plm Commerce Guided SearchCommerce Platform+15 moreJun 17, 2026 Sep 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference e...Show more |
2Apache Oracle2Financial Services Crime And Compliance Management Studio ShiroJun 17, 2026 Sep 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. |
2Ansi Regex Project Oracle2Ansi Regex Communications Cloud Native Core PolicyJun 17, 2026 Sep 17, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ansi-regex is vulnerable to Inefficient Regular Expression Complexity |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreJun 17, 2026 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
6Apache DebianFedoraproject+3 more11Cloud Backup Clustered Data OntapDebian Linux+8 moreJun 17, 2026 Sep 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Serve...Show more |
6Apache BroadcomDebian+3 more13Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+10 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). |
8Apache BroadcomDebian+5 more18Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+15 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. |
2Oracle Set Value Project2Communications Cloud Native Core Policy Set ValueJun 17, 2026 Sep 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays. |
6Debian FedoraprojectLibssh+3 more7Cloud Backup Debian LinuxEnterprise Linux+4 moreJun 17, 2026 Aug 31, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, bo...Show more |
3Npmjs OracleSiemens3Arborist GraalvmSinec Infrastructure Network ServicesJun 17, 2026 Aug 31, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the...Show more |
3Npmjs OracleSiemens3Arborist GraalvmSinec Infrastructure Network ServicesJun 17, 2026 Aug 31, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and th...Show more |