Jre
Vendor:
First CVE: Dec 31, 2003 · Active for 22 years
799
Total CVEs
More Total CVEs than 100% of tracked products
44.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
1.8%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Jre over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Apr 21, 2026
96 days ago
CVE Severity & Scoring
Jre799 CVEs
16%
44%
36%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (2.6%)
Network340 (42.6%)
Unknown437 (54.7%)
Physical1 (0.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low149 (18.6%)
High213 (26.7%)
Unknown437 (54.7%)
User Interaction
None233 (29.2%)
Unknown437 (54.7%)
Required129 (16.1%)
Privileges Required
Low10 (1.3%)
High0 (0.0%)
None352 (44.1%)
Unknown437 (54.7%)
Top CVEs
Signals from CVEs in this product scope (799 CVEs).
799 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2465CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and Ope | Jun 18, 2013 | 9.8 | 98 | YES | YES |
CVE-2013-0422CRITICAL Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServe | Jan 10, 2013 | 9.8 | 98 | YES | YES |
CVE-2012-5076CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and | Oct 16, 2012 | 9.8 | 98 | YES | YES |
CVE-2012-4681CRITICAL Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted app | Aug 28, 2012 | 9.8 | 98 | YES | YES |
CVE-2012-1723CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 a | Jun 16, 2012 | 9.8 | 98 | YES | YES |
CVE-2012-0507CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows re | Jun 7, 2012 | 9.8 | 98 | YES | YES |
CVE-2011-3544CRITICAL Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications | Oct 19, 2011 | 9.8 | 98 | YES | YES |
CVE-2010-0840CRITICAL Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affe | Apr 1, 2010 | 9.8 | 98 | YES | YES |
CVE-2013-0431MEDIUM Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the | Jan 31, 2013 | 5.3 | 97 | YES | YES |
CVE-2016-3427CRITICAL Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai | Apr 21, 2016 | 9.8 | 95 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (799 CVEs).
CISA KEV
14 CVEs
1.8% of CVEs· 96th percentile
Metasploit
20 CVEs
2.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
30 CVEs
3.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (799 CVEs).
Media Mentions
Signals from CVEs in this product scope (799 CVEs).
Top CNAs Publishing CVEs For Jre
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.1 | 19 | 5.8 | 4.0% | 0 | 0 |
| 8.0 | 1 | 6.5 | 5.0% | 0 | 0 |
| 26 | 7 | 5.0 | 0.4% | 0 | 0 |
| 25.0.2 | 7 | 5.0 | 0.4% | 0 | 0 |
| 25.0.1 | 5 | 5.9 | 0.4% | 0 | 0 |
| 25 | 3 | 5.7 | 0.5% | 0 | 0 |
| 24.0.1 | 5 | 6.7 | 0.6% | 0 | 0 |
| 24 | 3 | 5.9 | 0.7% | 0 | 0 |
| 23.0.1 | 1 | 4.8 | 1.0% | 0 | 0 |
| 23 | 5 | 3.9 | 0.9% | 0 | 0 |
| 22.0.1 | 8 | 4.4 | 1.0% | 0 | 0 |
| 22 | 1 | 3.7 | 1.3% | 0 | 0 |
| 21.0.9 | 4 | 6.5 | 0.4% | 0 | 0 |
| 21.0.8 | 3 | 5.7 | 0.5% | 0 | 0 |
| 21.0.7 | 4 | 7.4 | 0.6% | 0 | 0 |
| 21.0.6 | 3 | 5.9 | 0.7% | 0 | 0 |
| 21.0.5 | 1 | 4.8 | 1.0% | 0 | 0 |
| 21.0.4 | 4 | 4.0 | 1.0% | 0 | 0 |
| 21.0.3 | 5 | 4.9 | 1.1% | 0 | 0 |
| 21.0.2 | 4 | 3.7 | 1.1% | 0 | 0 |