Oracle
oracle
11,112 CVEs • 1,067 products
Products (1,067)
Click to collapseToggle
Products (1,067)
Click to collapse
CVEs (11,112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack. |
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential da...Show more |
8Brocade CanonicalDebian+5 more12Cloud Backup Communications Network Charging And ControlDebian Linux+9 moreJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. |
8Apple BrocadeCanonical+5 more18Cloud Backup Communications Network Charging And ControlFabric Operating System+15 moreJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. |
9Apple BrocadeCanonical+6 more19Cloud Backup Communications Network Charging And ControlDebian Linux+16 moreJun 17, 2026 May 27, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. |
7Apple CanonicalDebian+4 more15Communications Cloud Native Core Policy Communications Network Charging And ControlDebian Linux+12 moreJun 17, 2026 May 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. |
7Apache CanonicalDebian+4 more26Agile Engineering Data Management Agile PlmCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 May 20, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is...Show more |
4Dpdk FedoraprojectOpensuse+1 more4Data Plane Development Kit Enterprise Communications BrokerFedora+1 moreJun 17, 2026 May 20, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descri...Show more |
4Dpdk FedoraprojectOpensuse+1 more4Data Plane Development Kit Enterprise Communications BrokerFedora+1 moreJun 17, 2026 May 20, 2020 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the...Show more |
2Oracle Tibco3Jasperreports Library Jasperreports ServerRetail Order BrokerJun 17, 2026 May 20, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO...Show more |
2Oracle Tibco2Jasperreports Server Retail Order BrokerJun 17, 2026 May 20, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theor...Show more |
4Jquery JuniperNetapp+1 more7Active Iq Unified Manager Cloud BackupJquery+4 moreJun 17, 2026 May 19, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in t...Show more |
5Canonical DpdkFedoraproject+2 more6Communications Session Border Controller Data Plane Development KitEnterprise Communications Broker+3 moreJun 17, 2026 May 19, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a...Show more |
5Canonical DpdkFedoraproject+2 more6Communications Session Border Controller Data Plane Development KitEnterprise Communications Broker+3 moreJun 17, 2026 May 19, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption. |
2Apache Oracle7Activemq Communications Diameter Signaling RouterCommunications Element Manager+4 moreJun 17, 2026 May 14, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. |
2Apache Oracle4Camel Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 moreJun 17, 2026 May 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |
2Apache Oracle4Camel Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 moreJun 17, 2026 May 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |
2Apache Oracle5Camel Communications Diameter Intelligence HubCommunications Diameter Signaling Router+2 moreJun 17, 2026 May 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0. |
5Apache CanonicalFedoraproject+2 more50Agile Engineering Data Management AntBanking Enterprise Collections+47 moreJun 17, 2026 May 14, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replacer...Show more |
4Apache FedoraprojectNetapp+1 more7Application Testing Suite FedoraHospitality Opera 5+4 moreNov 21, 2024 May 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration...Show more |