Skip to main content

Vendor/product archive

oracle / application_express CVEs

Beta · best-effort

46 CVEs tagged to oracle / application_express4 Critical, 5 High, 37 Medium, 0 Low, 0 Unrated.

CVE-2025-50067

Published Jul 15, 2025

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerabil…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-21557

Published Jan 21, 2025

Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-21261

Published Oct 15, 2024

Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privilege…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21983

Published Jul 18, 2023

Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Admi…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21975

Published Jul 18, 2023

Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Ex…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-21974

Published Jul 18, 2023

Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Applicatio…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24729

Published Mar 16, 2022

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows a…

CVSS 6.5 · Medium

CVE-2022-24728

Published Mar 16, 2022

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKE…

CVSS 5.4 · Medium

CVE-2021-41165

Published Nov 17, 2021

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEd…

CVSS 8.2 · High

CVE-2021-41164

Published Nov 17, 2021

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins us…

CVSS 8.2 · High

CVE-2021-32809

Published Aug 12, 2021

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/c…

CVSS 4.6 · Medium

CVE-2021-2460

Published Jul 21, 2021

Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploita…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32723

Published Jun 28, 2021

Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (use…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26272

Published Jan 26, 2021

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (…

CVSS 6.5 · Medium

CVE-2021-26271

Published Jan 26, 2021

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advance…

CVSS 6.5 · Medium

CVE-2020-27193

Published Nov 12, 2020

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and p…

CVSS 6.1 · Medium

CVE-2020-14900

Published Oct 21, 2020

Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vul…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14899

Published Oct 21, 2020

Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vuln…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14898

Published Oct 21, 2020

Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vuln…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14763

Published Oct 21, 2020

Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnera…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2