Oracle vendor intelligence
Oracle Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Oracle products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 56
- Known exploited vulnerabilities affecting Oracle products
- In CISA KEV
- 45
- Records also listed in the official catalog
- Beyond CISA KEV
- 11
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 11
- Oracle KEVs with sensor-observed exploitation activity
The catalog gap matters for Oracle exposure
Eleven of the 56 exploited Oracle vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-fifth of this vendor portfolio.
- 80%
- Covered by CISA
- 20%
- Beyond CISA
- 25
- Product families
Attested Oracle vulnerabilities
56 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-21287
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The... |
Oracle Agile PLM Framework | Confirmed | In CISA | 21 Nov 2024 |
|
CVE-2020-2883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... |
WebLogic Server | Confirmed | In CISA | 07 Jan 2025 |
|
CVE-2024-20953
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily... |
Agile PLM Framework | Confirmed | In CISA | 24 Feb 2025 |
|
CVE-2020-9314
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the... |
iPlanet Web Server | High | Beyond CISA | 10 May 2020 |
|
CVE-2019-2618
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... |
WebLogic Server | High | Beyond CISA | 23 Apr 2019 |
|
CVE-2019-2588
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... |
BI Publisher (formerly XML Publisher) | High | Beyond CISA | 23 Apr 2019 |
No Oracle vulnerabilities match this search or filter.
Showing 6 of 6 on this page (56 Oracle known exploited vulnerabilities).
Recurring weakness patterns
Access control, missing authentication for critical function, and deserialization account for 21 mapped occurrences across this Oracle KEV portfolio.
CWE-284
Improper Access Control
CWE-306
Missing Authentication for Critical Function
CWE-502
Deserialization of Untrusted Data
CWE-287
Improper Authentication
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-693
Protection Mechanism Failure
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CWE-269
Improper Privilege Management