Jdk

Vendor:

First CVE: Jun 30, 2007 · Active for 19 years

791
Total CVEs
More Total CVEs than 100% of tracked products
41.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Jdk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2007
19 years ago
Most Recent CVE
Apr 21, 2026
94 days ago

CVE Severity & Scoring

Jdk791 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local22 (2.8%)
Network347 (43.9%)
Unknown421 (53.2%)
Physical1 (0.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low155 (19.6%)
High215 (27.2%)
Unknown421 (53.2%)
User Interaction
None239 (30.2%)
Unknown421 (53.2%)
Required131 (16.6%)
Privileges Required
Low11 (1.4%)
High0 (0.0%)
None359 (45.4%)
Unknown421 (53.2%)

Top CVEs

Signals from CVEs in this product scope (791 CVEs).

791 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run
Apr 1, 20229.898YESYES
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServe
Jan 10, 20139.898YESYES
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted app
Aug 28, 20129.898YESYES
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 a
Jun 16, 20129.898YESYES
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications
Oct 19, 20119.898YESYES
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai
Apr 21, 20169.895YESNO
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attacke
Mar 5, 201310.089NOYES
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and
Oct 16, 201210.087NOYES
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentialit
Jun 18, 20139.386NOYES
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vecto
Mar 8, 201310.085NOYES

Exploit Exposure

Signals from CVEs in this product scope (791 CVEs).

CISA KEV
9 CVEs
1.1% of CVEs· 96th percentile
Metasploit
14 CVEs
1.8% of CVEs· 96th percentile
Nuclei
1 CVE
0.1% of CVEs· 96th percentile
ExploitDB
23 CVEs
2.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (791 CVEs).

Media Mentions

Signals from CVEs in this product scope (791 CVEs).

Top CNAs Publishing CVEs For Jdk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.1195.84.0%00
8.028.74.6%00
7.027.54.3%00
2675.00.4%00
25.0.275.00.4%00
25.0.155.90.4%00
2535.70.5%00
24.0.156.70.6%00
2435.90.7%00
23.0.114.81.0%00
2353.90.9%00
22.0.194.41.1%00
21.0.946.50.4%00
21.0.835.70.5%00
21.0.747.40.6%00
21.0.635.90.7%00
21.0.514.81.0%00
21.0.444.01.0%00
21.0.354.91.1%00
21.0.243.71.1%00