Oracle / Application Express
47 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-50067 | Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily expl… | CRITICAL | 9.0 | Jul 15, 2025 |
| CVE-2025-21557 | Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allo… | MEDIUM | 5.4 | Jan 21, 2025 |
| CVE-2024-21261 | Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability al… | MEDIUM | 4.9 | Oct 15, 2024 |
| CVE-2023-21983 | Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Appli… | MEDIUM | 5.6 | Jul 18, 2023 |
| CVE-2023-21975 | Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected… | CRITICAL | 9.0 | Jul 18, 2023 |
| CVE-2023-21974 | Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affe… | CRITICAL | 9.0 | Jul 18, 2023 |
| CVE-2022-24729 | Regular expression Denial of Service in dialog plugin | HIGH | 7.5 | Mar 16, 2022 |
| CVE-2022-24728 | Cross-site Scripting in CKEditor4 | MEDIUM | 5.4 | Mar 16, 2022 |
| CVE-2021-41165 | HTML comments vulnerability allowing to execute JavaScript code | HIGH | 8.2 | Nov 17, 2021 |
| CVE-2021-41164 | Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML | HIGH | 8.2 | Nov 17, 2021 |
| CVE-2021-41184 | XSS in the `of` option of the `.position()` util | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41183 | XSS in `*Text` options of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41182 | XSS in the `altField` option of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-37695 | Execution of JavaScript code using malformed HTML in ckeditor | HIGH | 7.3 | Aug 12, 2021 |
| CVE-2021-32809 | Arbitrary HTML injection vulnerability in ckeditor | MEDIUM | 5.4 | Aug 12, 2021 |
| CVE-2021-32808 | Cross-site scripting in ckeditor via abuse of undo functionality | HIGH | 7.6 | Aug 12, 2021 |
| CVE-2021-2460 | Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00… | MEDIUM | 5.4 | Jul 20, 2021 |
| CVE-2021-32723 | Regular Expression Denial of Service (ReDoS) in Prism | HIGH | 7.4 | Jun 28, 2021 |
| CVE-2021-26272 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then pr… | MEDIUM | 6.5 | Jan 26, 2021 |
| CVE-2021-26271 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dia… | MEDIUM | 6.5 | Jan 26, 2021 |
| CVE-2020-27193 | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading… | MEDIUM | 6.1 | Nov 12, 2020 |
| CVE-2020-7760 | Regular Expression Denial of Service (ReDoS) | HIGH | 7.5 | Oct 30, 2020 |
| CVE-2020-14900 | Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Ea… | MEDIUM | 5.4 | Oct 21, 2020 |
| CVE-2020-14899 | Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Eas… | MEDIUM | 5.4 | Oct 21, 2020 |
| CVE-2020-14898 | Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Eas… | MEDIUM | 5.4 | Oct 21, 2020 |
Showing 1 to 25 of 47 CVEs