Apex
Vendor:
First CVE: Oct 18, 2006 · Active for 19 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Apex over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2006
19 years ago
Most Recent CVE
Jan 20, 2026
185 days ago
CVE Severity & Scoring
Apex8 CVEs
63%
38%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (12.5%)
Unknown7 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High0 (0.0%)
Unknown7 (87.5%)
User Interaction
None0 (0.0%)
Unknown7 (87.5%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (87.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5352HIGH Multiple unspecified vulnerabilities in Oracle Application Express 1.5 up to 1.6.1 have unknown impact and remote attack vectors, aka Vuln# (1) APEX04, (2) APEX20, and (3) APEX21. | Oct 18, 2006 | 10.0 | 25 | NO | NO |
CVE-2006-5351HIGH Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2) | Oct 18, 2006 | 9.0 | 23 | NO | NO |
CVE-2007-3860HIGH Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vecto | Jul 18, 2007 | 7.5 | 20 | NO | NO |
CVE-2026-21931MEDIUM Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App). Supported versions that are affected are 23.2.0, 23.2.1, 24.1.0, 24 | Jan 20, 2026 | 5.4 | 19 | NO | NO |
CVE-2007-3854MEDIUM Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Adv | Jul 18, 2007 | 5.5 | 17 | NO | NO |
CVE-2006-7138MEDIUM SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute ar | Mar 7, 2007 | 6.0 | 17 | NO | NO |
CVE-2006-7158MEDIUM Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via t | Mar 7, 2007 | 4.3 | 14 | NO | NO |
CVE-2006-5599MEDIUM Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FL | Oct 28, 2006 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Apex
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 24.2.1 | 1 | 5.4 | 0.2% | 0 | 0 |
| 24.1.0 | 1 | 5.4 | 0.2% | 0 | 0 |
| 23.2.1 | 1 | 5.4 | 0.2% | 0 | 0 |
| 23.2.0 | 1 | 5.4 | 0.2% | 0 | 0 |
| 2.2.0.00.32 | 1 | 7.5 | 1.9% | 0 | 0 |
| 2.2 | 2 | 4.9 | 1.9% | 0 | 0 |
| 2.0 | 2 | 7.3 | 2.3% | 0 | 0 |
| 1.6.1 | 2 | 7.8 | 2.7% | 0 | 0 |
| 1.5.0 | 3 | 8.2 | 2.5% | 0 | 0 |