Oracle vendor intelligence

Oracle Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Oracle products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEVs Full KEV feed
Total KEVs
56
Known exploited vulnerabilities affecting Oracle products
In CISA KEV
45
Records also listed in the official catalog
Beyond CISA KEV
11
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
11
Oracle KEVs with sensor-observed exploitation activity

The catalog gap matters for Oracle exposure

Eleven of the 56 exploited Oracle vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-fifth of this vendor portfolio.

80%
Covered by CISA
20%
Beyond CISA
25
Product families

Attested Oracle vulnerabilities

56 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2024-21287

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The...

Oracle Agile PLM Framework Confirmed In CISA 21 Nov 2024
CVE-2020-2883

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 07 Jan 2025
CVE-2024-20953

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily...

Agile PLM Framework Confirmed In CISA 24 Feb 2025
CVE-2020-9314

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the...

iPlanet Web Server High Beyond CISA 10 May 2020
CVE-2019-2618

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

WebLogic Server High Beyond CISA 23 Apr 2019
CVE-2019-2588

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

BI Publisher (formerly XML Publisher) High Beyond CISA 23 Apr 2019

Showing 6 of 6 on this page (56 Oracle known exploited vulnerabilities).

Recurring weakness patterns

Access control, missing authentication for critical function, and deserialization account for 21 mapped occurrences across this Oracle KEV portfolio.

Browse all KEVs →