VulnSea

oracle has 522 CVEs on record between 2012 and 2026. Disclosure cadence is accelerating: 489 in the last 90 days against 8 in the 90 before. The busiest recent month was September 2026 with 263. The median CVSS is 7.8 (high), with 119 rated critical. 2% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1283 days (10 cases). The dominant weakness classes are CWE-284 (302) and CWE-306 (88). Most affected products: hyperion_financial_management (83), webcenter_portal (35), hyperion_data_relationship_management (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.8
Publish → KEV
1283 d median(10)
Last 90 days
489 prev 8

Products

  • hyperion_financial_management 83
  • webcenter_portal 35
  • hyperion_data_relationship_management 21
  • webcenter_enterprise_capture 21
  • e-business_suite 20
  • peoplesoft_enterprise_campus_software_campus_community 20
522
Total CVEs
119
Critical
10
CISA KEV
10
Exploited

oracle vulnerabilities

CVEs affecting oracle, newest first. Open any entry for full detail, references, and exploit status.

522 CVEsRSS

CVE-2026-61111Medium· 6.5
2mo ago

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core)

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with l…

▾ Sunlitoracle · application_object_libraryEPSS 0.15%via NVD
CVE-2026-61110High· 8.8
2mo ago

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch)

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …

▾ Twilightoracle · applications_dbaEPSS 0.43%via NVD
CVE-2026-61107High· 7.2
2mo ago

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker …

▾ Twilightoracle · applications_dbaEPSS 0.49%via NVD
CVE-2026-60776Medium· 6.7
2mo ago

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader)

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged …

▾ Sunlitoracle · application_object_libraryEPSS 0.18%via NVD
CVE-2026-60761Medium· 6.5
2mo ago

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker w…

▾ Sunlitoracle · applications_dbaEPSS 0.15%via NVD
CVE-2026-60684Medium· 4.6
2mo ago

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments)

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attac…

▾ Sunlitoracle · applications_frameworkEPSS 0.21%via NVD
CVE-2026-60676High· 8.8
2mo ago

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean)

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · applications_frameworkEPSS 0.43%via NVD
CVE-2026-60675High· 8.8
2mo ago

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean)

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · applications_frameworkEPSS 0.43%via NVD
CVE-2026-60661High· 7.8
2mo ago

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems)

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure …

▾ Twilightoracle · solarisEPSS 0.13%via NVD
CVE-2026-60659High· 7.1
2mo ago

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems)

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure wh…

▾ Twilightoracle · solarisEPSS 0.14%via NVD
CVE-2026-60653High· 8.1
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low priv…

▾ Twilightoracle · webcenter_contentEPSS 0.36%via NVD
CVE-2026-60652High· 8.0
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low priv…

▾ Twilightoracle · webcenter_contentEPSS 0.35%via NVD
CVE-2026-60651High· 8.8
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthen…

▾ Twilightoracle · webcenter_contentEPSS 0.42%via NVD
CVE-2026-60647High· 7.1
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low priv…

▾ Twilightoracle · webcenter_contentEPSS 0.38%via NVD
CVE-2026-60642High· 7.6
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated …

▾ Twilightoracle · webcenter_contentEPSS 0.15%via NVD
CVE-2026-60641High· 7.6
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated …

▾ Twilightoracle · webcenter_contentEPSS 0.30%via NVD
CVE-2026-60629High· 7.5
2mo ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthentic…

▾ Twilightoracle · jdeveloperEPSS 0.28%via NVD
CVE-2026-60622High· 7.5
2mo ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated att…

▾ Twilightoracle · jdeveloperEPSS 0.41%via NVD
CVE-2026-60617Medium· 6.5
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker wit…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.27%via NVD
CVE-2026-60616Medium· 6.5
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker wit…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.28%via NVD
CVE-2026-60615High· 8.2
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.35%via NVD
CVE-2026-60614High· 7.1
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker w…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.28%via NVD
CVE-2026-60613Medium· 6.6
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows high privileged atta…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.40%via NVD
CVE-2026-60611Medium· 5.3
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.34%via NVD
CVE-2026-60610Medium· 5.9
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker wit…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.35%via NVD
CVE-2026-60609Medium· 6.5
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker w…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.39%via NVD
CVE-2026-60605High· 7.5
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows un…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.41%via NVD
CVE-2026-60604High· 7.5
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.33%via NVD
CVE-2026-60603High· 8.8
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attac…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.43%via NVD
CVE-2026-60599High· 8.1
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacke…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.36%via NVD
oracle vulnerabilities (CVEs) — page 14 · VulnSea