Application Express

Vendor:

First CVE: Apr 16, 2008 · Active for 18 years

47
Total CVEs
More Total CVEs than 97% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
2.1%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Application Express over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2008
18 years ago
Most Recent CVE
Jul 15, 2025
374 days ago

CVE Severity & Scoring

Application Express47 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network45 (95.7%)
Unknown2 (4.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (91.5%)
High2 (4.3%)
Unknown2 (4.3%)
User Interaction
None5 (10.6%)
Unknown2 (4.3%)
Required40 (85.1%)
Privileges Required
Low26 (55.3%)
High0 (0.0%)
None19 (40.4%)
Unknown2 (4.3%)

Top CVEs

Signals from CVEs in this product scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execut
Oct 26, 20216.142NONO
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may e
Oct 26, 20216.142NONO
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog fu
Mar 15, 20176.129NONO
Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerabili
Jul 15, 20259.028NONO
Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application
Jul 18, 20239.028NONO
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows ab
Mar 16, 20227.526NONO
Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Exp
Jul 18, 20239.025NONO
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may
Oct 26, 20216.125NONO

Exploit Exposure

Signals from CVEs in this product scope (47 CVEs).

CISA KEV
1 CVE
2.1% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (47 CVEs).

Media Mentions

Signals from CVEs in this product scope (47 CVEs).

Top CNAs Publishing CVEs For Application Express

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.127.82.1%00
24.2.519.00.3%00
24.2.419.00.3%00
24.125.20.3%00
23.225.20.3%00
21.1.416.12.2%00