Cyber Resilience

← All vendors

Oracle

CPE vendor key: oracle · 2,866 CVEs published in the last 24 months.

CVEs (365 d)
2,524
▼ -217 vs prior 30d
Avg CVSS (365 d)
7.48
over 2,524 CVEs
Avg EPSS pct (365 d)
0.23
higher = more likely exploited
KEV hit rate (365 d)
0.2%
5 of 2,524 added to CISA KEV
LLM-credited CVEs
0
none detected

Monthly CVE volume — last 24 months

20242025202601108
Each point is one calendar month. Bars in the severity card to the right slice the same volume by CVSS band.

Severity mix

CritHighMedLow
Stacked by CVSS band (Critical / High / Medium / Low) using the best available metric per CVE.

Top affected products (24 mo)

e-business_suite
155
mysql_server
145
coherence
105
webcenter_content
88
vm_virtualbox
74
mysql
60
mysql_cluster
57
weblogic_server
55
jre
51
jdk
51
Distinct CVEs that include each product in their CPE configuration.

Top CWEs (24 mo)

CWE-284
1,481
CWE-306
393
CWE-269
199
CWE-400
180
CWE-200
164
CWE-287
100
CWE-863
66
CWE-352
53
CWE-601
53
CWE-770
27
Distinct CVEs assigned each weakness.

Recent CISA KEV adds (last 12 months)

AddedCVEProductKEV name
2026-07-15CVE-2026-46817E-Business SuiteOracle E-Business Suite Improper Privilege Management Vulnerability
2026-06-12CVE-2026-35273 PeopleSoft Enterprise PeopleToolsOracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
2026-06-01CVE-2024-21182WebLogic ServerOracle WebLogic Server Unspecified Vulnerability
2025-11-21CVE-2025-61757Fusion MiddlewareOracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
2025-10-20CVE-2025-61884E-Business SuiteOracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
2025-10-06CVE-2025-61882E-Business SuiteOracle E-Business Suite Unspecified Vulnerability
Filtered to KEV entries whose CISA vendor or product name matches this vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps that CPE-map to Microsoft).

Generated 23 August 2026 00:24 UTC .