Flexcube Universal Banking

Vendor:

First CVE: Oct 25, 2016 · Active for 9 years

95
Total CVEs
More Total CVEs than 99% of tracked products
10.6
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Flexcube Universal Banking over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2016
9 years ago
Most Recent CVE
Jan 20, 2026
185 days ago

CVE Severity & Scoring

Flexcube Universal Banking95 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local4 (4.2%)
Network89 (93.7%)
Unknown0 (0.0%)
Physical2 (2.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low81 (85.3%)
High14 (14.7%)
Unknown0 (0.0%)
User Interaction
None58 (61.1%)
Unknown0 (0.0%)
Required37 (38.9%)
Privileges Required
Low61 (64.2%)
High0 (0.0%)
None34 (35.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on u
Aug 18, 20217.530NONO
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.530NONO
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.530NONO
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of
Jul 13, 20217.530NONO
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.529NONO
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could
Feb 24, 20218.228NONO
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 all
Oct 25, 20168.828NONO
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that
Jan 14, 20207.526NONO
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are
Jan 18, 20188.826NONO

Exploit Exposure

Signals from CVEs in this product scope (95 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (95 CVEs).

Media Mentions

Signals from CVEs in this product scope (95 CVEs).

Top CNAs Publishing CVEs For Flexcube Universal Banking

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.5.0106.42.2%00
14.586.819.3%00
14.4.017.53.9%00
14.1.096.01.7%00
14.0.0136.11.6%00
12.4.0266.42.3%00
12.427.511.8%00
12.3.0326.21.4%00
12.2.0466.01.5%00
12.1.0466.01.5%00
12.0.3495.91.5%00
12.0.2495.91.5%00
12.0.1525.81.5%00
12.0.036.11.3%00
11.83.315.9100.0%00
11.7.015.40.9%00
11.6.015.40.9%00
11.5.015.40.9%00
11.4.0515.71.5%00
11.3.0495.81.5%00