Documaker
Oracle · 23 CVEs
Execution of JavaScript code using malformed HTML in ckeditor
Aug 12, 2021
Arbitrary HTML injection vulnerability in ckeditor
Aug 12, 2021
Cross-site scripting in ckeditor via abuse of undo functionality
Aug 12, 2021
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affect…
Jul 20, 2021
spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux applica…
May 27, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.db…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.de…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.de…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.db…
Dec 17, 2020
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.db…
Dec 17, 2020
dom4j: XML External Entity vulnerability in default SAX parser
May 1, 2020
Prototype pollution in dojo
Mar 10, 2020
hibernate-validator: safeHTML validator allows XSS
Nov 8, 2019
libquartz: XXE attacks via job description
Jul 26, 2019
c3p0: loading XML configuration leads to denial of service
Apr 22, 2019
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1…
Jul 21, 2016
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-37695 | Execution of JavaScript code using malformed HTML in ckeditor | HIGH | 1.32% | Aug 12, 2021 |
| CVE-2021-32809 | Arbitrary HTML injection vulnerability in ckeditor | MEDIUM | 1.19% | Aug 12, 2021 |
| CVE-2021-32808 | Cross-site scripting in ckeditor via abuse of undo functionality | HIGH | 1.19% | Aug 12, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 2.43% | Jul 20, 2021 |
| CVE-2021-22118 | spring-web: (re)creating the temporary storage directory could result in a privilege escalation within WebFlux application | HIGH | 0.40% | May 27, 2021 |
| CVE-2020-36180 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 4.09% | Jan 6, 2021 |
| CVE-2020-36182 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 4.09% | Jan 6, 2021 |
| CVE-2020-36183 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool | HIGH | 4.97% | Jan 6, 2021 |
| CVE-2020-36184 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource | HIGH | 8.36% | Jan 6, 2021 |
| CVE-2020-36185 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource | HIGH | 4.24% | Jan 6, 2021 |
| CVE-2020-36186 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource | HIGH | 4.24% | Jan 6, 2021 |
| CVE-2020-36187 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource | HIGH | 4.24% | Jan 6, 2021 |
| CVE-2020-36188 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnection… | HIGH | 8.79% | Jan 6, 2021 |
| CVE-2020-36189 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerC… | HIGH | 3.99% | Jan 6, 2021 |
| CVE-2020-36181 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 4.09% | Jan 6, 2021 |
| CVE-2020-35490 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource | HIGH | 6.29% | Dec 17, 2020 |
| CVE-2020-35491 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource | HIGH | 7.75% | Dec 17, 2020 |
| CVE-2020-10683 | dom4j: XML External Entity vulnerability in default SAX parser | CRITICAL | 7.27% | May 1, 2020 |
| CVE-2020-5258 | Prototype pollution in dojo | HIGH | 4.02% | Mar 10, 2020 |
| CVE-2019-10219 | hibernate-validator: safeHTML validator allows XSS | MEDIUM | 2.16% | Nov 8, 2019 |
| CVE-2019-13990 | libquartz: XXE attacks via job description | CRITICAL | 16.20% | Jul 26, 2019 |
| CVE-2019-5427 | c3p0: loading XML configuration leads to denial of service | HIGH | 4.88% | Apr 22, 2019 |
| CVE-2016-0635 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Healt… | HIGH | 5.08% | Jul 21, 2016 |
Showing 1 to 23 of 23 CVEs