Oracle / Commerce Platform
44 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-70955 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | HIGH | 7.5 | Aug 18, 2026 |
| CVE-2026-70954 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | CRITICAL | 9.8 | Aug 18, 2026 |
| CVE-2026-70953 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | CRITICAL | 9.8 | Aug 18, 2026 |
| CVE-2026-61137 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | HIGH | 8.1 | Jul 21, 2026 |
| CVE-2026-61136 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | HIGH | 7.3 | Jul 21, 2026 |
| CVE-2026-61135 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | HIGH | 7.4 | Jul 21, 2026 |
| CVE-2026-61134 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | MEDIUM | 6.8 | Jul 21, 2026 |
| CVE-2026-61133 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | HIGH | 7.5 | Jul 21, 2026 |
| CVE-2026-61132 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | HIGH | 7.6 | Jul 21, 2026 |
| CVE-2026-61131 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | CRITICAL | 9.8 | Jul 21, 2026 |
| CVE-2026-61130 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 1… | CRITICAL | 9.1 | Jul 21, 2026 |
| CVE-2026-61129 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exp… | CRITICAL | 9.8 | Jul 21, 2026 |
| CVE-2025-21576 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Supported versions that are affected are 1… | MEDIUM | 5.4 | Apr 15, 2025 |
| CVE-2024-21100 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.… | MEDIUM | 4.0 | Apr 16, 2024 |
| CVE-2022-21559 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11… | MEDIUM | 5.5 | Jul 19, 2022 |
| CVE-2022-22965 KEV | spring-framework: RCE via Data Binding on JDK 9+ | CRITICAL | 9.8 | Apr 1, 2022 |
| CVE-2020-36518 | jackson-databind: denial of service via a large depth of nested objects | HIGH | 7.5 | Mar 11, 2022 |
| CVE-2022-21387 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11… | MEDIUM | 5.3 | Jan 19, 2022 |
| CVE-2021-40690 | Bypass of the secureValidation property | HIGH | 7.5 | Sep 19, 2021 |
| CVE-2021-2463 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11… | CRITICAL | 9.8 | Jul 20, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2020-36179 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36180 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36182 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36183 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool | HIGH | 8.1 | Jan 6, 2021 |
Showing 1 to 25 of 44 CVEs