Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oracle

First CVE: Feb 6, 1997Active for: 29 yearsTotal CVEs: 10,713
56.4
VTI Score
TOP TARGET

Oracle's vulnerability footprint spans one of the largest and most widely deployed product portfolios in the enterprise technology landscape, encompassing databases, Java runtime environments, operating systems, and middleware that underpin critical infrastructure across virtually all industry sectors. The recurring exposure centers on flagship products such as MySQL, the Java Runtime Environment and Development Kit, Solaris, and the Oracle Database Server, reflecting the vendor's reach across data platforms, application runtimes, and system infrastructure. Vulnerabilities affecting the vendor recur through weakness classes including improper access control, exposure of sensitive information to unauthorized actors, and uncontrolled resource consumption, patterns consistent with the authentication, data-protection, and availability demands of large-scale database and middleware systems. Defenders should treat Oracle's coordinated quarterly patch cycles as high-priority across their enterprise footprint; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10,713
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Oracle over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 1997
29 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Self-Reporting Analysis

Of all the CVEs published by Oracle as a CNA, 86.1% affect products that Oracle develops as a vendor.

86.1%
13.9%
Self-reported: 8,428 (86.1%)
Third-party: 1,366 (13.9%)

Of all the CVEs published that affect products developed by Oracle, 78.7% are self-published by Oracle as a CNA.

78.7%
21.3%
Self-published: 8,428 (78.7%)
Other CNAs: 2,285 (21.3%)

Products(1,057 total)

Top CVEs

Signals from CVEs in this vendor scope (10713 CVEs).

10,713 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-35273CRITICAL
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8
Jun 11, 20269.899YESYES
CVE-2025-61882CRITICAL
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14
Oct 5, 20259.899YESYES
CVE-2022-22963CRITICAL
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r
Apr 1, 20229.899YESYES
CVE-2022-22947CRITICAL
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse
Mar 3, 202210.099YESYES
CVE-2021-42013CRITICAL
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori
Oct 7, 20219.899YESYES
CVE-2021-41773CRITICAL
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con
Oct 5, 20219.899YESYES
CVE-2021-3156HIGH
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
CVE-2020-14882CRITICAL
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 1
Oct 21, 20209.899YESYES
CVE-2020-1472CRITICAL
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
CVE-2020-1938CRITICAL
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
View all 10,713 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10,713 CVEs
9%
55%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1,055 (9.8%)
Network6,039 (56.4%)
Unknown3,511 (32.8%)
Physical25 (0.2%)
Adjacent Network83 (0.8%)
Attack Complexity
Low6,005 (56.1%)
High1,197 (11.2%)
Unknown3,511 (32.8%)
User Interaction
None5,113 (47.7%)
Unknown3,511 (32.8%)
Required2,089 (19.5%)
Privileges Required
Low2,141 (20.0%)
High1,494 (13.9%)
None3,567 (33.3%)
Unknown3,511 (32.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (10713 CVEs).

CISA KEV
82 CVEs
0.8% of CVEs· 99th percentile
Metasploit
141 CVEs
1.3% of CVEs· 97th percentile
Nuclei
96 CVEs
0.9% of CVEs· 95th percentile
ExploitDB
359 CVEs
3.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oracle.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oracle — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oracle's Products

View all 46 CNAs →

Top CWEs