Oracle's vulnerability footprint spans one of the largest and most widely deployed product portfolios in the enterprise technology landscape, encompassing databases, Java runtime environments, operating systems, and middleware that underpin critical infrastructure across virtually all industry sectors. The recurring exposure centers on flagship products such as MySQL, the Java Runtime Environment and Development Kit, Solaris, and the Oracle Database Server, reflecting the vendor's reach across data platforms, application runtimes, and system infrastructure. Vulnerabilities affecting the vendor recur through weakness classes including improper access control, exposure of sensitive information to unauthorized actors, and uncontrolled resource consumption, patterns consistent with the authentication, data-protection, and availability demands of large-scale database and middleware systems. Defenders should treat Oracle's coordinated quarterly patch cycles as high-priority across their enterprise footprint; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oracle over time
Of all the CVEs published by Oracle as a CNA, 86.1% affect products that Oracle develops as a vendor.
Of all the CVEs published that affect products developed by Oracle, 78.7% are self-published by Oracle as a CNA.
Signals from CVEs in this vendor scope (10713 CVEs).
10,713 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35273CRITICAL Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8 | Jun 11, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-61882CRITICAL Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14 | Oct 5, 2025 | 9.8 | 99 | YES | YES |
CVE-2022-22963CRITICAL In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r | Apr 1, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-22947CRITICAL In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse | Mar 3, 2022 | 10.0 | 99 | YES | YES |
CVE-2021-42013CRITICAL It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori | Oct 7, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-41773CRITICAL A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con | Oct 5, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2020-14882CRITICAL Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 1 | Oct 21, 2020 | 9.8 | 99 | YES | YES |
CVE-2020-1472CRITICAL An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc | Aug 17, 2020 | 10.0 | 99 | YES | YES |
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
Signals from CVEs in this vendor scope (10713 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oracle.
Media articles that mention a CVE ID that affects a product developed by Oracle — matched by CVE ID, not by vendor name.