Skip to main content

Vendor/product archive

oracle / apex CVEs

Beta · best-effort

8 CVEs tagged to oracle / apex2 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-21931

Published Jan 20, 2026

Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App). Supported versions that are affected are 23.2.0, 23.2.1, 24.1.0, 2…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-3854

Published Jul 18, 2007

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Ad…

CVSS 5.5 · Medium

CVE-2007-3860

Published Jul 18, 2007

Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7138

Published Mar 7, 2007

SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute a…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7158

Published Mar 7, 2007

Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5599

Published Oct 28, 2006

Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_F…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5351

Published Oct 18, 2006

Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2)…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5352

Published Oct 18, 2006

Multiple unspecified vulnerabilities in Oracle Application Express 1.5 up to 1.6.1 have unknown impact and remote attack vectors, aka Vuln# (1) APEX04, (2) APEX20, and (3) APEX21.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1