Vendor

Oracle, page 2

As of , 46 Oracle vulnerabilities are on CISA's list of exploited vulnerabilities, 13 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2026-21962.

#VulnerabilityProductOur groupListedDeadlineEPSS
26CVE-2020-14750Remote Code ExecutionOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.990.99
27CVE-2020-14871UnspecifiedOracle Solaris and Zettabyte File System (ZFS)Patch this weekMetasploit module; EPSS 0.800.80
28CVE-2020-14882Remote Code ExecutionOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.990.99
29CVE-2020-14883UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.980.98
30CVE-2019-3010Privilege EscalationOracle SolarisPatch this weekMetasploit module0.13
31CVE-2019-2616BI Publisher Unauthorized AccessOracle BI Publisher (Formerly XML Publisher)Patch this weekEPSS 0.92; verified Exploit-DB entry0.92
32CVE-2024-21182UnspecifiedOracle WebLogic ServerPatch this weekEPSS 0.740.74
33CVE-2025-61757Missing Authentication for Critical FunctionOracle Fusion MiddlewarePatch this weekEPSS 0.890.89
34CVE-2020-14644Remote Code ExecutionOracle WebLogic ServerPatch this weekEPSS 0.950.95
35CVE-2022-21445Deserialization of Untrusted DataOracle ADF FacesPatch this weekEPSS 0.620.62
36CVE-2017-3506OS Command InjectionOracle WebLogic ServerPatch this weekEPSS 0.960.96
37CVE-2020-2551UnspecifiedOracle Fusion MiddlewarePatch this weekEPSS 0.930.93
38CVE-2016-3427UnspecifiedOracle Java SE and JRockitPatch this weekEPSS 0.920.92
39CVE-2020-14864Business Intelligence Enterprise Edition Path TransversalOracle Intelligence Enterprise EditionPatch this weekEPSS 0.970.97
40CVE-2012-1710UnspecifiedOracle Fusion MiddlewarePatch this weekRansomware use0.08
41CVE-2008-3431Insufficient Input ValidationOracle VirtualBoxPatch soonVerified Exploit-DB entry0.07
42CVE-2015-2590and Java SE Embedded Remote Code ExecutionOracle Java SEPatch soon0.25
43CVE-2015-4902Integrity CheckOracle Java SEPatch soon0.14
44CVE-2012-0518UnspecifiedOracle Fusion MiddlewarePatch soon0.05
45CVE-2024-20953DeserializationOracle Agile Product Lifecycle Management (PLM)Patch soon0.04
46CVE-2024-21287Incorrect AuthorizationOracle Agile Product Lifecycle Management (PLM)Patch soon0.02