Oracle
oracle
11,037 CVEs • 1,064 products
Products (1,064)
Click to collapseToggle
Products (1,064)
Click to collapse
CVEs (11,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache DebianNetapp+1 more12Blockchain Platform Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Policy+9 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 c...Show more |
6Debian FedoraprojectLxml+3 more8Communications Offline Mediation Controller Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Dec 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could...Show more |
6Apache FasterxmlFedoraproject+3 more39Agile Plm Agile Product Lifecycle Management Integration PackBanking Apis+36 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is...Show more |
4Apache NetappOracle+1 more17Active Iq Unified Manager Commerce Guided SearchCommunications Cloud Native Core Service Communication Proxy+14 moreJun 17, 2026 Dec 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request executio...Show more |
4Debian HibernateOracle+1 more5Communications Cloud Native Core Console Debian LinuxHibernate Orm+2 moreJun 17, 2026 Dec 2, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments...Show more |
5Apache DebianEclipse+2 more17Blockchain Platform Communications Converged Application Server Service ControllerCommunications Offline Mediation Controller+14 moreJun 17, 2026 Nov 28, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto...Show more |
3Debian HighlightjsOracle3Debian Linux Highlight.jsMysql Enterprise MonitorJun 17, 2026 Nov 24, 2020 N/A· v4 8.7 HIGH· v3 4.9 MEDIUM· v2 Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype p...Show more |
4Debian FedoraprojectMusl Libc+1 more4Debian Linux FedoraGraalvm+1 moreJun 17, 2026 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). |
3Fedoraproject IbmOracle6Aix Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+3 moreJun 17, 2026 Nov 20, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296. |
4C Ares Project FedoraprojectNodejs+1 more8Blockchain Platform C AresFedora+5 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a D...Show more |
3Oracle SiemensY18n Project3Graalvm Sinec Infrastructure Network ServicesY18nJun 17, 2026 Nov 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. |
5Apache DebianNetapp+2 more15Activemq Banking Cash ManagementBanking Corporate Lending Process Management+12 moreJun 17, 2026 Nov 16, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on b...Show more |
2Ckeditor Oracle9Agile Plm Application ExpressBanking Party Management+6 moreJun 17, 2026 Nov 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor...Show more |
2Apache Oracle18Api Gateway BatikBusiness Intelligence+15 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause...Show more |
3Apache NetappOracle6Business Intelligence Communications Messaging ServerCxf+3 moreJun 17, 2026 Nov 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, whic...Show more |
4Fedoraproject MitNetapp+1 more11Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Policy+8 moreJun 17, 2026 Nov 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recurs...Show more |
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploit...Show more |
2Codemirror Oracle6Application Express CodemirrorEnterprise Manager Express User Interface+3 moreJun 17, 2026 Oct 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac7...Show more |
5Apache DebianEclipse+2 more18Beam Communications Application Session ControllerCommunications Converged Application Server Service Controller+15 moreJun 17, 2026 Oct 23, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that syste...Show more |
3Fedoraproject OraclePython3Communications Cloud Native Core Network Function Cloud Native Environment FedoraPythonJun 17, 2026 Oct 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. |