VYPR

Application Express

by Oracle Corporation

CVEs (66)

  • CVE-2020-26870MedOct 7, 2020
    risk 0.33cvss 6.1epss 0.05

    Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

  • CVE-2019-10219MedNov 8, 2019
    risk 0.33cvss 6.1epss 0.02

    A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

  • CVE-2024-21261MedOct 15, 2024
    risk 0.32cvss 4.9epss 0.00

    Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. While the…

  • CVE-2021-32809MedAug 12, 2021
    risk 0.30cvss 4.6epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML,…

  • CVE-2020-2977MedJul 15, 2020
    risk 0.30cvss 4.6epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise…

  • CVE-2020-2514MedApr 15, 2020
    risk 0.30cvss 4.6epss 0.01

    Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to…

  • CVE-2022-24728MedMar 16, 2022
    risk 0.28cvss 5.4epss 0.01

    CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing…

  • CVE-2020-7760MedOct 30, 2020
    risk 0.28cvss 5.3epss 0.05

    This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.j…

  • CVE-2009-0981Apr 15, 2009
    risk 0.03cvss —epss 0.05

    Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable…

  • CVE-2015-2655Jul 16, 2015
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.3.00.08 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

  • CVE-2015-2586Jul 16, 2015
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect availability via unknown vectors.

  • CVE-2015-2585Jul 16, 2015
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0 allows remote authenticated users to affect availability via unknown vectors.

  • CVE-2014-6483Oct 15, 2014
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2013-1519Apr 17, 2013
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2012-1708May 3, 2012
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Application Express component in Oracle Database Server 4.0 and 4.1 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2011-3525Oct 18, 2011
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2 and 4.0 allows remote authenticated users to affect confidentiality, integrity, and availability, related to APEX developer user.

  • CVE-2010-0892Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2.0.00.27 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2009-1993Oct 22, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Application Express component in Oracle Database 3.0.1 allows remote authenticated users to affect confidentiality and integrity, related to FLOWS_030000.WWV_EXECUTE_IMMEDIATE.

  • CVE-2008-4005Oct 14, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Application Express component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2008-1822Apr 16, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vectors, aka APEX02.