VYPR

Application Express

by Oracle Corporation

CVEs (66)

  • CVE-2025-21557MedJan 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks…

  • CVE-2021-2460MedJul 21, 2021
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network…

  • CVE-2021-2117MedJan 20, 2021
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access…

  • CVE-2021-2116MedJan 20, 2021
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network…

  • CVE-2020-14900MedOct 21, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access…

  • CVE-2020-14899MedOct 21, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via…

  • CVE-2020-14898MedOct 21, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via…

  • CVE-2020-14763MedOct 21, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via…

  • CVE-2020-14762MedOct 21, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise…

  • CVE-2020-2976MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle…

  • CVE-2020-2975MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle…

  • CVE-2020-2974MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle…

  • CVE-2020-2973MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle…

  • CVE-2020-2972MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle…

  • CVE-2020-2971MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle…

  • CVE-2020-2513MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle…

  • CVE-2019-2484MedJul 23, 2019
    risk 0.35cvss 5.4epss 0.01

    Vulnerability in the Application Express component of Oracle Database Server. Supported versions that are affected are 5.1 and 18.2. Easily exploitable vulnerability allows low privileged attacker having Valid Account privilege with network access via HTTP to compromise…

  • CVE-2016-7103MedMar 15, 2017
    risk 0.34cvss 6.1epss 0.23

    Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

  • CVE-2020-26870MedOct 7, 2020
    risk 0.33cvss 6.1epss 0.05

    Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

  • CVE-2019-10219MedNov 8, 2019
    risk 0.33cvss 6.1epss 0.02

    A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.