Vulnerabilities > Oracle

DATE CVE VULNERABILITY TITLE RISK
2022-12-26 CVE-2019-9579 An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products.
network
low complexity
illumos oracle
8.1
2022-12-26 CVE-2020-10650 Deserialization of Untrusted Data vulnerability in multiple products
A deserialization flaw was discovered in jackson-databind through 2.9.10.4.
network
high complexity
fasterxml oracle CWE-502
8.1
2022-12-26 CVE-2021-43395 Improper Locking vulnerability in multiple products
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923.
5.5
2022-11-03 CVE-2022-2696 Unspecified vulnerability in Oracle Restaurant Menu - Food Ordering System - Table Reservation
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation.
network
low complexity
oracle
6.5
2022-11-03 CVE-2022-3776 Unspecified vulnerability in Oracle Restaurant Menu - Food Ordering System - Table Reservation
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1.
network
low complexity
oracle
8.8
2022-10-18 CVE-2022-21587 Missing Authentication for Critical Function vulnerability in Oracle E-Business Suite
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
network
low complexity
oracle CWE-306
critical
9.8
2022-07-19 CVE-2022-21558 Unspecified vulnerability in Oracle Crystal Ball 11.1.2.0.000/11.1.2.4.900
Vulnerability in the Oracle Crystal Ball product of Oracle Construction and Engineering (component: Installation).
local
high complexity
oracle
7.8
2022-07-19 CVE-2022-34169 Incorrect Conversion between Numeric Types vulnerability in multiple products
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets.
7.5
2022-07-11 CVE-2020-29505 Insufficient Entropy vulnerability in multiple products
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability.
network
low complexity
dell oracle CWE-331
7.5
2022-07-11 CVE-2020-29506 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
network
low complexity
dell oracle
critical
9.8