Database Server

Vendor:

First CVE: Aug 16, 1999 · Active for 26 years

521
Total CVEs
More Total CVEs than 100% of tracked products
19.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Database Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 1999
26 years ago
Most Recent CVE
May 28, 2026
57 days ago

CVE Severity & Scoring

Database Server521 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local18 (3.5%)
Network88 (16.9%)
Unknown414 (79.5%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low76 (14.6%)
High31 (6.0%)
Unknown414 (79.5%)
User Interaction
None72 (13.8%)
Unknown414 (79.5%)
Required35 (6.7%)
Privileges Required
Low38 (7.3%)
High39 (7.5%)
None30 (5.8%)
Unknown414 (79.5%)

Top CVEs

Signals from CVEs in this product scope (521 CVEs).

521 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availab
Oct 22, 200910.086NOYES
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attacke
Jan 19, 20117.580NOYES
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS
Oct 11, 20026.878NOYES
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager
May 8, 20127.577NOYES
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.
Oct 20, 20032.162NOYES
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for
Sep 21, 20126.452NOYES
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via
Oct 17, 20076.551NOYES
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as ide
Jan 18, 200610.050NOYES
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integ
Jan 13, 201010.045NOYES
Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.
Jan 17, 200810.045NOYES

Exploit Exposure

Signals from CVEs in this product scope (521 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
9 CVEs
1.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
5.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (521 CVEs).

Media Mentions

Signals from CVEs in this product scope (521 CVEs).

Top CNAs Publishing CVEs For Database Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
release_224.83.7%02
9i_application_server19.010.8%00
9.2.258.531.1%01
9.2.158.027.4%01
9.2.0.8dv486.53.7%07
9.2.0.8586.43.5%06
9.2.0.7448.44.2%00
9.2.0.6198.94.3%00
9.2.0.588.84.4%00
9.2.0.447.54.0%00
9.2.0.327.52.6%00
9.2.0.218.53.7%00
9.2.0.128.83.1%00
9.217.513.8%00
9.0.427.45.5%00
9.0.2.424.311.6%01
9.0.1.5608.54.2%01
9.0.1.447.84.1%00
9.0.133.80.9%01
9.017.513.8%00