VulnSea

oracle has 522 CVEs on record between 2012 and 2026. Disclosure cadence is accelerating: 489 in the last 90 days against 8 in the 90 before. The busiest recent month was September 2026 with 263. The median CVSS is 7.8 (high), with 119 rated critical. 2% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1283 days (10 cases). The dominant weakness classes are CWE-284 (302) and CWE-306 (88). Most affected products: hyperion_financial_management (83), webcenter_portal (35), hyperion_data_relationship_management (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.8
Publish → KEV
1283 d median(10)
Last 90 days
489 prev 8

Products

  • hyperion_financial_management 83
  • webcenter_portal 35
  • hyperion_data_relationship_management 21
  • webcenter_enterprise_capture 21
  • e-business_suite 20
  • peoplesoft_enterprise_campus_software_campus_community 20
522
Total CVEs
119
Critical
10
CISA KEV
10
Exploited

oracle vulnerabilities

CVEs affecting oracle, newest first. Open any entry for full detail, references, and exploit status.

522 CVEsRSS

CVE-2026-60415High· 8.1
1mo ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows un…

▾ Twilightoracle · weblogic_serverEPSS 0.42%via NVD
CVE-2026-60414High· 7.8
1mo ago

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core)

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · outside_in_technologyEPSS 0.19%via NVD
CVE-2026-60413High· 7.8
1mo ago

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core)

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · outside_in_technologyEPSS 0.19%via NVD
CVE-2026-60412High· 7.8
1mo ago

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core)

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · outside_in_technologyEPSS 0.32%via NVD
CVE-2026-60392High· 7.8
1mo ago

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK)

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated atta…

▾ Twilightoracle · outside_in_technologyEPSS 0.32%via NVD
CVE-2026-60163High· 8.4
2mo ago

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin)

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0…

▾ Twilightoracle · mysql_serverEPSS 0.19%via NVD
CVE-2026-60812Medium· 6.5
2mo ago

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…

▾ Sunlitoracle · e-business_suiteEPSS 0.39%via NVD
CVE-2026-60811Medium· 6.3
2mo ago

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…

▾ Sunlitoracle · e-business_suiteEPSS 0.26%via NVD
CVE-2026-60810High· 8.2
2mo ago

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthent…

▾ Twilightoracle · e-business_suiteEPSS 0.35%via NVD
CVE-2026-60800High· 7.1
2mo ago

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench)

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged a…

▾ Twilightoracle · e-business_suiteEPSS 0.30%via NVD
CVE-2026-60799High· 7.1
2mo ago

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench)

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged a…

▾ Twilightoracle · e-business_suiteEPSS 0.30%via NVD
CVE-2026-60772High· 7.1
2mo ago

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged att…

▾ Twilightoracle · e-business_suiteEPSS 0.28%via NVD
CVE-2026-60771High· 8.1
2mo ago

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows l…

▾ Twilightoracle · e-business_suiteEPSS 0.36%via NVD
CVE-2026-60764High· 8.1
2mo ago

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged att…

▾ Twilightoracle · e-business_suiteEPSS 0.36%via NVD
CVE-2026-60708High· 8.1
2mo ago

Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…

▾ Twilightoracle · e-business_suiteEPSS 0.36%via NVD
CVE-2026-60703High· 7.1
2mo ago

Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attack…

▾ Twilightoracle · interaction_blendingEPSS 0.16%via NVD
CVE-2026-60685Medium· 6.1
2mo ago

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with net…

▾ Sunlitoracle · e-business_suiteEPSS 0.13%via NVD
CVE-2026-60683High· 7.7
2mo ago

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow…

▾ Twilightoracle · e-business_suiteEPSS 0.35%via NVD
CVE-2026-60681High· 8.8
2mo ago

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow…

▾ Twilightoracle · e-business_suiteEPSS 0.43%via NVD
CVE-2026-60678High· 8.8
2mo ago

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · e-business_suiteEPSS 0.43%via NVD
CVE-2026-60674High· 8.2
2mo ago

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security)

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability al…

▾ Twilightoracle · business_intelligenceEPSS 0.35%via NVD
CVE-2026-60671High· 8.6
2mo ago

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security)

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability al…

▾ Twilightoracle · business_intelligenceEPSS 0.34%via NVD
CVE-2026-60670High· 8.1
2mo ago

Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer)

Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthe…

▾ Twilightoracle · applications_technology_stackEPSS 0.39%via NVD
CVE-2026-60575Medium· 6.3
2mo ago

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer)

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker …

▾ Sunlitoracle · workflowEPSS 0.26%via NVD
CVE-2026-60573Medium· 6.3
2mo ago

Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard)

Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker w…

▾ Sunlitoracle · e-business_suiteEPSS 0.26%via NVD
CVE-2026-60521Medium· 6.5
2mo ago

Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List)

Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netw…

▾ Sunlitoracle · advanced_pricingEPSS 0.27%via NVD
CVE-2026-60491Medium· 6.3
2mo ago

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration)

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileg…

▾ Sunlitoracle · advanced_inbound_telephonyEPSS 0.26%via NVD
CVE-2026-60343High· 8.8
2mo ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with…

▾ Twilightoracle · weblogic_serverEPSS 0.43%via NVD
CVE-2026-60335High· 7.2
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged …

▾ Twilightoracle · webcenter_contentEPSS 0.49%via NVD
CVE-2026-60334High· 8.8
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged a…

▾ Twilightoracle · webcenter_contentEPSS 0.43%via NVD
oracle vulnerabilities (CVEs) — page 12 · VulnSea