VulnSea

oracle has 522 CVEs on record between 2012 and 2026. Disclosure cadence is accelerating: 489 in the last 90 days against 8 in the 90 before. The busiest recent month was September 2026 with 263. The median CVSS is 7.8 (high), with 119 rated critical. 2% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1283 days (10 cases). The dominant weakness classes are CWE-284 (302) and CWE-306 (88). Most affected products: hyperion_financial_management (83), webcenter_portal (35), hyperion_data_relationship_management (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.8
Publish → KEV
1283 d median(10)
Last 90 days
489 prev 8

Products

  • hyperion_financial_management 83
  • webcenter_portal 35
  • hyperion_data_relationship_management 21
  • webcenter_enterprise_capture 21
  • e-business_suite 20
  • peoplesoft_enterprise_campus_software_campus_community 20
522
Total CVEs
119
Critical
10
CISA KEV
10
Exploited

oracle vulnerabilities

CVEs affecting oracle, newest first. Open any entry for full detail, references, and exploit status.

522 CVEsRSS

CVE-2026-47014High· 8.1
2mo ago

Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security)

Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with networ…

▾ Twilightoracle · product_workbenchEPSS 0.36%via NVD
CVE-2026-47013Medium· 5.3
2mo ago

Vulnerability in Oracle Java SE (component: JavaFX)

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compro…

▾ Sunlitoracle · jdkEPSS 0.41%via NVD
CVE-2026-47010Low· 3.7
2mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19,…

▾ Sunlitoracle · graalvmEPSS 0.25%via NVD
CVE-2026-47009Medium· 6.5
2mo ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with netw…

▾ Sunlitoracle · agile_product_lifecycle_managementEPSS 0.39%via NVD
CVE-2026-47007High· 7.3
2mo ago

Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment)

Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily ex…

▾ Twilightoracle · communications_pricing_design_centerEPSS 0.15%via NVD
CVE-2026-46992High· 8.8
2mo ago

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management)

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allow…

▾ Twilightoracle · enterprise_manager_base_platformEPSS 0.43%via NVD
CVE-2026-46983Critical· 9.8
2mo ago

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal)

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with n…

▾ Midnightoracle · retail_integration_busEPSS 0.51%via NVD
CVE-2026-46982Critical· 9.8
2mo ago

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal)

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with…

▾ Midnightoracle · retail_integration_busEPSS 0.51%via NVD
CVE-2026-46968Medium· 5.9
2mo ago

Vulnerability in Oracle Java SE (component: JSSE)

Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enter…

▾ Sunlitoracle · jreEPSS 0.29%via NVD
CVE-2026-46859Critical· 9.8
3mo ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP …

▾ Midnightoracle · agile_product_lifecycle_managementEPSS 0.51%via NVD
CVE-2026-46979Medium· 6.5
3mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privile…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.41%via NVD
CVE-2026-46851High· 8.1
3mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker wit…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.44%via NVD
CVE-2026-46817Critical· 9.8CISA KEVPoC
4mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ Hadaloracle · e-business_suiteEPSS 0.81%via NVD
CVE-2026-34282High· 7.5
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.…

▾ Twilightoracle · jreEPSS 0.89%via NVD
CVE-2026-22016High· 7.5PoC
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, …

▾ Midnightoracle · jreEPSS 0.70%via NVD
CVE-2026-35244Medium· 5.2
5mo ago

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management)

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.24.0.000. Easily exploitable vulnerability allows high privileg…

▾ Sunlitoracle · hyperion_infrastructure_technologyEPSS 0.28%via NVD
CVE-2026-21999Medium· 5.3
5mo ago

Vulnerability in the XML Database component of Oracle Database Server

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromi…

▾ Sunlitoracle · xml_databaseEPSS 0.24%via NVD
CVE-2026-21962Critical· 10.0CISA KEVPoC
8mo ago

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versio…

▾ Hadaloracle · http_serverEPSS 71%via NVD
CVE-2026-21945High· 7.5
8mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.…

▾ Twilightoracle · graalvmEPSS 0.97%via NVD
CVE-2026-21932High· 7.4
8mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11…

▾ Twilightoracle · graalvmEPSS 0.51%via NVD
CVE-2025-61884High· 7.5CISA KEVPoC
11mo ago

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …

▾ Abyssaloracle · configuratorEPSS 96%via NVD
CVE-2025-61882Critical· 9.8CISA KEV0dayPoC
11mo ago

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration)

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated…

▾ Hadaloracle · concurrent_processingEPSS 100%via NVD
CVE-2025-30758Medium· 5.3
1y ago

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface)

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows unauthenticated attacker with network access …

▾ Sunlitoracle · siebel_crmEPSS 0.30%via NVD
CVE-2025-30714Medium· 4.8
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via…

▾ Sunlitoracle · mysql_connector/pythonEPSS 0.40%via NVD
CVE-2025-30706High· 7.5
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via mult…

▾ Twilightoracle · mysql_connector/jEPSS 0.61%via NVD
CVE-2024-21202Medium· 6.1
1y ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated…

▾ Sunlitoracle · peoplesoft_enterprise_peopletoolsEPSS 0.20%via NVD
CVE-2023-22039Medium· 5.4
3y ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP …

▾ Sunlitoracle · agile_product_lifecycle_managementEPSS 0.36%via NVD
CVE-2022-21467Medium· 6.5
4y ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Attachments)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP …

▾ Sunlitoracle · agile_product_lifecycle_managementEPSS 0.92%via NVD
CVE-2021-35606Medium· 5.7
4y ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Notification Framework)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Notification Framework). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.52%via NVD
CVE-2021-2351High· 8.3
5y ago

Vulnerability in the Advanced Networking Option component of Oracle Database Server

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network acc…

▾ Twilightoracle · advanced_networking_optionEPSS 2.4%via NVD
oracle vulnerabilities (CVEs) — page 17 · VulnSea