Vendor
Oracle, page 2
As of , 46 Oracle vulnerabilities are on CISA's list of exploited vulnerabilities, 13 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2026-21962.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 26 | CVE-2020-14750Remote Code Execution | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 27 | CVE-2020-14871Unspecified | Oracle Solaris and Zettabyte File System (ZFS) | Patch this weekMetasploit module; EPSS 0.80 | 0.80 | ||
| 28 | CVE-2020-14882Remote Code Execution | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 29 | CVE-2020-14883Unspecified | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.98 | 0.98 | ||
| 30 | CVE-2019-3010Privilege Escalation | Oracle Solaris | Patch this weekMetasploit module | 0.13 | ||
| 31 | CVE-2019-2616BI Publisher Unauthorized Access | Oracle BI Publisher (Formerly XML Publisher) | Patch this weekEPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 32 | CVE-2024-21182Unspecified | Oracle WebLogic Server | Patch this weekEPSS 0.74 | 0.74 | ||
| 33 | CVE-2025-61757Missing Authentication for Critical Function | Oracle Fusion Middleware | Patch this weekEPSS 0.89 | 0.89 | ||
| 34 | CVE-2020-14644Remote Code Execution | Oracle WebLogic Server | Patch this weekEPSS 0.95 | 0.95 | ||
| 35 | CVE-2022-21445Deserialization of Untrusted Data | Oracle ADF Faces | Patch this weekEPSS 0.62 | 0.62 | ||
| 36 | CVE-2017-3506OS Command Injection | Oracle WebLogic Server | Patch this weekEPSS 0.96 | 0.96 | ||
| 37 | CVE-2020-2551Unspecified | Oracle Fusion Middleware | Patch this weekEPSS 0.93 | 0.93 | ||
| 38 | CVE-2016-3427Unspecified | Oracle Java SE and JRockit | Patch this weekEPSS 0.92 | 0.92 | ||
| 39 | CVE-2020-14864Business Intelligence Enterprise Edition Path Transversal | Oracle Intelligence Enterprise Edition | Patch this weekEPSS 0.97 | 0.97 | ||
| 40 | CVE-2012-1710Unspecified | Oracle Fusion Middleware | Patch this weekRansomware use | 0.08 | ||
| 41 | CVE-2008-3431Insufficient Input Validation | Oracle VirtualBox | Patch soonVerified Exploit-DB entry | 0.07 | ||
| 42 | CVE-2015-2590and Java SE Embedded Remote Code Execution | Oracle Java SE | Patch soon | 0.25 | ||
| 43 | CVE-2015-4902Integrity Check | Oracle Java SE | Patch soon | 0.14 | ||
| 44 | CVE-2012-0518Unspecified | Oracle Fusion Middleware | Patch soon | 0.05 | ||
| 45 | CVE-2024-20953Deserialization | Oracle Agile Product Lifecycle Management (PLM) | Patch soon | 0.04 | ||
| 46 | CVE-2024-21287Incorrect Authorization | Oracle Agile Product Lifecycle Management (PLM) | Patch soon | 0.02 |