Oracle Database Server vulnerabilities

502 known vulnerabilities affecting oracle/database_server.

Total CVEs
502
CISA KEV
0
Public exploits
25
Exploited in wild
0
Severity breakdown
CRITICAL112HIGH71MEDIUM250LOW69

Vulnerabilities

Page 1 of 26
CVE-2026-21939HIGHCVSS 7.0≥ 23.4, ≤ 23.262026-01-20
CVE-2026-21939 [HIGH] CVE-2026-21939: Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affecte Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a person other than the attacker. Successful att
nvd
CVE-2025-53047MEDIUMCVSS 5.8≥ 19.3, ≤ 19.28≥ 21.3, ≤ 21.19+1 more2025-10-21
CVE-2025-53047 [MEDIUM] CWE-200 CVE-2025-53047: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions t Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks
nvd
CVE-2025-53051LOWCVSS 2.7≥ 23.4, ≤ 23.92025-10-21
CVE-2025-53051 [LOW] CWE-125 CVE-2025-53051: Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS Functional Index. Successful attacks of this vulnerability can result in unau
nvd
CVE-2025-61749LOWCVSS 2.7≥ 23.4, ≤ 23.92025-10-21
CVE-2025-61749 [LOW] CWE-284 CVE-2025-61749: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can result in unauthorized update, inse
nvd
CVE-2025-30751HIGHCVSS 8.8≥ 19.3, ≤ 19.27≥ 23.4, ≤ 23.82025-07-15
CVE-2025-30751 [HIGH] CWE-863 CVE-2025-30751: Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that a Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Oracle Database. Successful attacks of this vulnerabil
nvd
CVE-2025-50070MEDIUMCVSS 5.3≥ 23.4, ≤ 23.82025-07-15
CVE-2025-50070 [MEDIUM] CWE-284 CVE-2025-50070: Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Authenticated OS User privilege with logon to the infrastructure where JDBC executes to compromise JDBC. Successful attacks require human interaction from a person
nvd
CVE-2025-50066LOWCVSS 2.7≥ 19.3, ≤ 19.27≥ 21.3, ≤ 21.18+1 more2025-07-15
CVE-2025-50066 [LOW] CWE-269 CVE-2025-50066: Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Support Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise Oracle Database Materia
nvd
CVE-2025-30750LOWCVSS 2.4≥ 19.3, ≤ 19.27≥ 21.3, ≤ 21.18+1 more2025-07-15
CVE-2025-30750 [LOW] CWE-863 CVE-2025-30750: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks require human interaction
nvd
CVE-2024-21233MEDIUMCVSS 4.3≥ 19.3, ≤ 19.24≥ 21.3, ≤ 21.15+2 more2024-10-15
CVE-2024-21233 [MEDIUM] CWE-203 CVE-2024-21233: Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions t Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Core. Successful attacks of this
nvd
CVE-2024-21251LOWCVSS 3.1≥ 19.3, ≤ 19.24≥ 21.3, ≤ 21.15+1 more2024-10-15
CVE-2024-21251 [LOW] CWE-203 CVE-2024-21251: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerab
nvd
CVE-2024-21184HIGHCVSS 7.2≥ 19.3, ≤ 19.232024-07-16
CVE-2024-21184 [HIGH] CWE-250 CVE-2024-21184: Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security. Successful attacks of this
nvd
CVE-2024-21126MEDIUMCVSS 5.8≥ 19.3, ≤ 19.23≥ 21.3, ≤ 21.142024-07-16
CVE-2024-21126 [MEDIUM] CWE-400 CVE-2024-21126: Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supp Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 and 21.3-21.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. While the vulnerability is in Oracle Databa
nvd
CVE-2024-21174LOWCVSS 3.1≥ 19.3, ≤ 19.23≥ 21.3, ≤ 21.14+1 more2024-07-16
CVE-2024-21174 [LOW] CWE-770 CVE-2024-21174: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability
nvd
CVE-2024-21123LOWCVSS 2.3≥ 19.3, ≤ 19.232024-07-16
CVE-2024-21123 [LOW] CWE-276 CVE-2024-21123: Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions t Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database Core executes to compromise Oracle Database Core. Successful attacks of this v
nvd
CVE-2024-21066MEDIUMCVSS 4.2≥ 19.3, ≤ 19.22≥ 21.3, ≤ 21.132024-04-16
CVE-2024-21066 [MEDIUM] CWE-79 CVE-2024-21066: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affecte Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS executes to compromise RDBMS. Successful attacks require human interaction
nvd
CVE-2024-21058MEDIUMCVSS 4.9≥ 19.3, ≤ 19.22≥ 21.3, ≤ 21.132024-04-16
CVE-2024-21058 [MEDIUM] CVE-2024-21058: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2024-20995LOWCVSS 2.4≥ 19.3, ≤ 19.22≥ 21.3, ≤ 21.132024-04-16
CVE-2024-20995 [LOW] CWE-404 CVE-2024-20995: Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versio Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle Database Sharding. Successful attacks require human interacti
nvd
CVE-2024-20903MEDIUMCVSS 6.5≥ 19.3, ≤ 19.21≥ 21.3, ≤ 21.122024-02-17
CVE-2024-20903 [MEDIUM] CVE-2024-20903: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.21 and 21.3-21.12. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result i
nvd
CVE-2023-22096MEDIUMCVSS 4.3≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22096 [MEDIUM] CVE-2023-22096: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result i
nvd
CVE-2023-22071MEDIUMCVSS 5.9≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22071 [MEDIUM] CVE-2023-22071: Vulnerability in the PL/SQL component of Oracle Database Server. Supported versions that are affect Vulnerability in the PL/SQL component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute on sys.utl_http privilege with network access via Oracle Net to compromise PL/SQL. Successful attacks require human interaction fr
nvd
1 / 26Next →