Vulnerability index

Browse CVEs

59 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Restaurant Menu Food Ordering System Table Reservation MEDIUM 6.1
CVE-2023-32516

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation plugin <= 2.3.6 v…

Fix: after 2.3.6
Fix from $1,600 2023-08-24
E Business Suite MEDIUM 6.1
CVE-2023-22035

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.…

Fix: after 12.2.12
Fix from $1,600 2023-07-18
Jd Edwards Enterpriseone Tools MEDIUM 6.1
CVE-2022-21631

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Supported versions that are affected …

Fix: after 9.2.6.4
Fix from $1,600 2022-10-18
Peoplesoft Enterprise MEDIUM 6.1
CVE-2022-21639

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search Integration). Supported versions that …

Patch available
Fix from $1,600 2022-10-18
Database Server MEDIUM 6.1
CVE-2022-21606

Vulnerability in the Oracle Services for Microsoft Transaction Server component of Oracle Database Server. The supported version that is affected is …

Patch available
Fix from $1,600 2022-10-18
Glassfish Server MEDIUM 6.1
CVE-2021-3314

Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dan…

Fix: after 3.1.2.18
Fix from $1,600 2021-06-25
Application Express MEDIUM 5.4
CVE-2020-2972

Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploi…

Fix: after 19.2
Fix from $1,600 2020-07-15
Primavera Portfolio Management MEDIUM 6.1
CVE-2020-2562

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module). Supported versions t…

Fix: after 18.0.2.0
Fix from $1,600 2020-07-15
Application Express MEDIUM 5.4
CVE-2020-2513

Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploi…

Fix: after 19.2
Fix from $1,600 2020-07-15
Applications Framework HIGH 7.6
CVE-2020-14610

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). The supported version t…

Patch available
Fix from $1,950 2020-07-15
Fusion Middleware Mapviewer MEDIUM 6.1
CVE-2020-14607

Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Tile Server). Supported versions that are aff…

Patch available
Fix from $1,600 2020-07-15
Webcenter Sites MEDIUM 6.1
CVE-2020-14613

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced User Interface). Supported versions that are aff…

Patch available
Fix from $1,600 2020-07-15
Financial Services Analytical Applications Infrastructure MEDIUM 6.1
CVE-2020-14615

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: I…

Fix: after 8.1.0
Fix from $1,600 2020-07-15
Istore HIGH 8.2
CVE-2020-14596

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Address Book). Supported versions that are affected are 12.1.1-12.1…

Fix: after 12.1.3
Fix from $1,950 2020-07-15
Financial Services Analytical Applications Infrastructure MEDIUM 6.1
CVE-2020-14601

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: I…

Fix: after 8.1.0
Fix from $1,600 2020-07-15
Istore HIGH 8.2
CVE-2020-14582

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Registration). Supported versions that are affected are 12.1.1…

Fix: after 12.2.9
Fix from $1,950 2020-07-15
Bi Publisher HIGH 8.2
CVE-2020-14584

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected…

Patch available
Fix from $1,950 2020-07-15
Bi Publisher HIGH 8.2
CVE-2020-14585

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11…

Patch available
Fix from $1,950 2020-07-15
Peoplesoft Enterprise Peopletools MEDIUM 6.1
CVE-2020-14592

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affect…

Patch available
Fix from $1,600 2020-07-15
Weblogic Server MEDIUM 6.1
CVE-2020-14572

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6…

Patch available
Fix from $1,600 2020-07-15
Enterprise Communications Broker MEDIUM 6.1
CVE-2020-14563

Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions th…

Fix: after 3.2.0
Fix from $1,600 2020-07-15
Reports Developer MEDIUM 6.1
CVE-2019-2413EPSS 6%

Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affe…

Patch available
Fix from $1,600 2019-01-16
Secure Global Desktop MEDIUM 6.1
CVE-2018-19439EPSS 20%

XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4). helpwind…

No fix yet
Fix from $1,600 2018-12-13
Webcenter Interaction MEDIUM 6.1
CVE-2018-16953

The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cro…

Mitigation only
Fix from $1,600 2018-09-18
Webcenter Interaction MEDIUM 6.1
CVE-2018-16955

The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redi…

Mitigation only
Fix from $1,600 2018-09-18
One To One Fulfillment HIGH 7.1
CVE-2017-3557

Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are aff…

Mitigation only
Fix from $1,950 2017-04-24
Peoplesoft Enterprise Peopletools MEDIUM 6.1
CVE-2017-3300

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Multichannel Framework). Supported vers…

Patch available
Fix from $1,600 2017-01-27
Agile Product Lifecycle Management MEDIUM 6.1
CVE-2016-5512

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…

Patch available
Fix from $1,600 2016-10-25
Linux MEDIUM 5.5
CVE-2016-5265

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Unive…

Fix: after 47.0.1
Fix from $1,600 2016-08-05