Oracle
First CVE: Oct 14, 2008Active for: 18 years
9,794
CVEs Published
More CVEs Published than 98% of tracked CNAs
515.5
Avg CVEs / Year
More Avg CVEs / Year than 98% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 12% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 84% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Oracle as a CNA, 86.1% affect products that Oracle develops as a vendor.
86.1%
13.9%
Self-reported: 8,428Third-party: 1,366
Of all the CVEs published that affect products developed by Oracle, 78.7% are self-published by Oracle as a CNA.
78.7%
21.3%
Self-published: 8,428Published by other CNAs: 2,285
Trends Over Time
The number and severity of CVEs published by Oracle over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2008
17 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by Oracle as a CNA, regardless of affected vendor or product.
9,794 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35273CRITICAL Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8 | Jun 11, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-61882CRITICAL Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14 | Oct 5, 2025 | 9.8 | 99 | YES | YES |
CVE-2020-14882CRITICAL Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 1 | Oct 21, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-2725CRITICAL Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. | Apr 26, 2019 | 9.8 | 99 | YES | YES |
CVE-2018-2628CRITICAL Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, | Apr 19, 2018 | 9.8 | 99 | YES | YES |
CVE-2025-61757CRITICAL Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easil | Oct 21, 2025 | 9.8 | 98 | YES | YES |
CVE-2025-61884HIGH Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu | Oct 12, 2025 | 7.5 | 98 | YES | YES |
CVE-2023-21839HIGH Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. | Jan 18, 2023 | 7.5 | 98 | YES | YES |
CVE-2022-21587CRITICAL Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Eas | Oct 18, 2022 | 9.8 | 98 | YES | YES |
CVE-2021-35587CRITICAL Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2. | Jan 19, 2022 | 9.8 | 98 | YES | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA9,794 CVEs
10%
55%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local953 (9.7%)
Network5,927 (60.5%)
Unknown2,793 (28.5%)
Physical21 (0.2%)
Adjacent Network100 (1.0%)
Attack Complexity
Low5,776 (59.0%)
High1,225 (12.5%)
Unknown2,793 (28.5%)
User Interaction
None5,068 (51.7%)
Unknown2,793 (28.5%)
Required1,933 (19.7%)
Privileges Required
Low2,374 (24.2%)
High1,624 (16.6%)
None3,003 (30.7%)
Unknown2,793 (28.5%)
Exploit Exposure
Signals from CVEs in this cna scope (9794 CVEs).
CISA KEV
43 CVEs
0.4% of CVEs· 84th percentile
Metasploit
80 CVEs
0.8% of CVEs· 85th percentile
Nuclei
41 CVEs
0.4% of CVEs· 74th percentile
ExploitDB
165 CVEs
1.7% of CVEs· 86th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Oracle as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Oracle as a CNA — matched by CVE ID, not by organization name.