Workflow

Vendor:

First CVE: Feb 4, 2006 · Active for 20 years

12
Total CVEs
More Total CVEs than 90% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Workflow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2006
20 years ago
Most Recent CVE
Apr 21, 2026
93 days ago

CVE Severity & Scoring

Workflow12 CVEs
All CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (83.3%)
Unknown2 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High0 (0.0%)
Unknown2 (16.7%)
User Interaction
None7 (58.3%)
Unknown2 (16.7%)
Required3 (25.0%)
Privileges Required
Low2 (16.7%)
High3 (25.0%)
None5 (41.7%)
Unknown2 (16.7%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerabi
Jan 20, 20218.227NONO
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln#
Apr 20, 200610.026NONO
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily e
Apr 16, 20249.125NONO
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerabi
Jul 19, 20227.525NONO
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v
Jan 20, 20264.922NONO
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.14. Easily
Oct 21, 20256.121NONO
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identifi
Feb 4, 20067.521NONO
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v
Apr 21, 20265.520NONO
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9
Apr 15, 20205.319NONO
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.14. Easily e
Jan 21, 20255.417NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Workflow

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.1.334.61.1%00
11.5.9.528.84.3%00
11.5.128.84.3%00