Oracle Vm Virtualbox vulnerabilities
430 known vulnerabilities affecting oracle/vm_virtualbox.
Total CVEs
430
CISA KEV
1
actively exploited
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH201MEDIUM170LOW54
Vulnerabilities
Page 12 of 22
CVE-2021-2284P4HIGHCVSS 7.1fixed in 6.1.202021-04-22
CVE-2021-2284 [HIGH] CVE-2021-2284: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The su
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM
nvd
CVE-2021-2281P4HIGHCVSS 7.1fixed in 6.1.202021-04-22
CVE-2021-2281 [HIGH] CVE-2021-2281: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The su
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM
nvd
CVE-2026-21986P4HIGHCVSS 7.1v7.1.14v7.2.42026-01-20
CVE-2026-21986 [HIGH] CVE-2026-21986: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppo
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1fixed in 6.1.322019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-3026P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.2.34≥ 6.0.0, < 6.0.142019-10-16
CVE-2019-3026 [MEDIUM] CVE-2019-3026: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.34 and prior to 6.0.14. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerabil
nvd
CVE-2019-2678P4MEDIUMCVSS 6.5fixed in 5.2.28≥ 6.0.0, < 6.0.62019-04-23
CVE-2019-2678 [MEDIUM] CVE-2019-2678: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2019-2574P4MEDIUMCVSS 6.5fixed in 5.2.28≥ 6.0.0, < 6.0.62019-04-23
CVE-2019-2574 [MEDIUM] CVE-2019-2574: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2020-2690P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.2.36≥ 6.0.0, < 6.0.16+1 more2020-01-15
CVE-2020-2690 [MEDIUM] CVE-2020-2690: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whil
nvd
CVE-2021-2128P4MEDIUMCVSS 6.5fixed in 6.1.182021-01-20
CVE-2021-2128 [MEDIUM] CVE-2021-2128: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The su
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM
nvd
CVE-2020-2691P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.2.36≥ 6.0.0, < 6.0.16+1 more2020-01-15
CVE-2020-2691 [MEDIUM] CVE-2020-2691: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whil
nvd
CVE-2020-2704P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.2.36≥ 6.0.0, < 6.0.16+1 more2020-01-15
CVE-2020-2704 [MEDIUM] CVE-2020-2704: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whil
nvd
CVE-2020-2681P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.2.36≥ 6.0.0, < 6.0.16+1 more2020-01-15
CVE-2020-2681 [MEDIUM] CVE-2020-2681: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whil
nvd
CVE-2020-2678P4MEDIUMCVSS 6.4≥ 5.2.0, < 5.2.36≥ 6.0.0, < 6.0.16+1 more2020-01-15
CVE-2020-2678 [MEDIUM] CVE-2020-2678: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Wh
nvd
CVE-2015-3196P4MEDIUMCVSS 4.3≥ 4.3.0, ≤ 4.3.35≥ 5.0.0, ≤ 5.0.132015-12-06
CVE-2015-3196 [MEDIUM] CWE-362 CVE-2015-3196: ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when use
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
nvd
CVE-2019-2555P4MEDIUMCVSS 6.5fixed in 5.2.24v6.0.02019-01-16
CVE-2019-2555 [MEDIUM] CVE-2019-2555: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2019-2450P4MEDIUMCVSS 6.5fixed in 5.2.24v6.0.02019-01-16
CVE-2019-2450 [MEDIUM] CVE-2019-2450: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2019-2556P4MEDIUMCVSS 6.5fixed in 5.2.24v6.0.02019-01-16
CVE-2019-2556 [MEDIUM] CVE-2019-2556: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2019-2451P4MEDIUMCVSS 6.5fixed in 5.2.24v6.0.02019-01-16
CVE-2019-2451 [MEDIUM] CVE-2019-2451: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2019-2554P4MEDIUMCVSS 6.5fixed in 5.2.24v6.0.02019-01-16
CVE-2019-2554 [MEDIUM] CVE-2019-2554: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2019-2863P4MEDIUMCVSS 6.5≥ 5.0.0, < 5.2.32≥ 6.0.0, < 6.0.102019-07-23
CVE-2019-2863 [MEDIUM] CVE-2019-2863: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulne
nvd