VulnSea

peoplesoft_enterprise_peopletools vulnerabilities

CVEs whose affected-version data names the peoplesoft_enterprise_peopletools package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

24 CVEsRSS

CVE-2026-87264High· 7.7
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker wit…

▾ TwilightOracle Corporation · PeopleSoft Enterprise PeopleToolsEPSS 0.30%via NVD
CVE-2026-83019High· 8.1
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network acces…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.42%via NVD
CVE-2026-83018High· 7.8
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the …

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.16%via NVD
CVE-2026-83017High· 8.8
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker wi…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.43%via NVD
CVE-2026-83016High· 7.2
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to t…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.14%via NVD
CVE-2026-83015High· 7.0
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with lo…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.13%via NVD
CVE-2026-83014High· 8.1
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with netw…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.38%via NVD
CVE-2026-82993High· 8.5
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker wit…

▾ TwilightOracle Corporation · PeopleSoft Enterprise PeopleToolsEPSS 0.29%via NVD
CVE-2026-73960High· 7.5
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ TwilightOracle Corporation · PeopleSoft Enterprise PeopleToolsEPSS 0.46%via NVD
CVE-2026-73955High· 7.3
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network …

▾ TwilightOracle Corporation · PeopleSoft Enterprise PeopleToolsEPSS 0.32%via NVD
CVE-2026-73954High· 8.1
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker …

▾ TwilightOracle Corporation · PeopleSoft Enterprise PeopleToolsEPSS 0.37%via NVD
CVE-2026-47026High· 7.4
2mo ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated atta…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.37%via NVD
CVE-2026-47015High· 7.1
2mo ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.24%via NVD
CVE-2024-21202Medium· 6.1
1y ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated…

▾ Sunlitoracle · peoplesoft_enterprise_peopletoolsEPSS 0.20%via NVD
CVE-2022-23437Medium· 6.5
4y ago

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resourc…

▾ Sunlitapache · xerces-jEPSS 12%via NVD
CVE-2021-41164High· 8.2
4y ago

CKEditor4 is an open source WYSIWYG HTML editor

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malf…

▾ Twilightckeditor · ckeditorEPSS 1.3%via NVD
CVE-2021-41184Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0.…

▾ Twilightjqueryui · jquery_uiEPSS 41%via NVD
CVE-2021-41183Medium· 6.5
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI …

▾ Sunlitjqueryui · jquery_uiEPSS 8.5%via NVD
CVE-2021-41182Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.…

▾ Twilightjqueryui · jquery_uiEPSS 39%via NVD
CVE-2021-40690High· 7.5
5y ago

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allo…

▾ Twilightapache · santuario_xml_security_for_javaEPSS 7.4%via NVD
CVE-2020-27193Medium· 6.1
5y ago

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

▾ Sunlitckeditor · ckeditorEPSS 2.0%via NVD
CVE-2020-9281Medium· 6.1
6y ago

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

▾ Sunlitckeditor · ckeditorEPSS 4.3%via NVD
CVE-2019-10086High· 7.3
7y ago

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using…

▾ Twilightapache · commons_beanutilsEPSS 28%via NVD
CVE-2019-2725Critical· 9.8CISA KEVPoC
7y ago

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services)

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Hadaloracle · agile_plmEPSS 100%via NVD
peoplesoft_enterprise_peopletools vulnerabilities (CVEs) · VulnSea