Vulnerabilities > Oracle > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-07-21 CVE-2021-2454 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
oracle
4.4
2021-07-21 CVE-2021-2455 Unspecified vulnerability in Oracle Peoplesoft Enterprise HCM Shared Components 9.2
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search).
network
low complexity
oracle
5.5
2021-07-21 CVE-2021-2457 Unspecified vulnerability in Oracle Identity Manager 11.1.2.3.0
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Request Management & Workflow).
network
low complexity
oracle
5.0
2021-07-21 CVE-2021-2458 Unspecified vulnerability in Oracle Identity Manager
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Identity Console).
network
oracle
4.9
2021-07-21 CVE-2021-2460 Unspecified vulnerability in Oracle Application Express
Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server.
network
oracle
4.9
2021-07-21 CVE-2021-2462 Unspecified vulnerability in Oracle Commerce Service Center
Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center).
network
oracle
5.8
2021-07-19 CVE-2021-35043 Cross-site Scripting vulnerability in multiple products
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected).
network
low complexity
antisamy-project oracle netapp CWE-79
6.1
2021-07-19 CVE-2021-32012 Resource Exhaustion vulnerability in multiple products
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
4.3
2021-07-19 CVE-2021-32013 Resource Exhaustion vulnerability in multiple products
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).
4.3
2021-07-19 CVE-2021-32014 Resource Exhaustion vulnerability in multiple products
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.
4.3