Oracle / Rest Data Services
34 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-46843 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows u… | MEDIUM | 5.3 | May 28, 2026 |
| CVE-2026-46842 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows u… | MEDIUM | 5.3 | May 28, 2026 |
| CVE-2026-46841 | Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allow… | MEDIUM | 5.3 | May 28, 2026 |
| CVE-2026-46840 | Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulner… | CRITICAL | 10.0 | May 28, 2026 |
| CVE-2026-46839 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows l… | CRITICAL | 9.9 | May 28, 2026 |
| CVE-2026-46830 | Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allo… | MEDIUM | 5.3 | May 28, 2026 |
| CVE-2026-46829 | Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allo… | HIGH | 7.5 | May 28, 2026 |
| CVE-2026-46775 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows l… | CRITICAL | 9.9 | May 28, 2026 |
| CVE-2026-35277 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows l… | HIGH | 8.1 | May 28, 2026 |
| CVE-2026-35266 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows… | HIGH | 7.9 | May 28, 2026 |
| CVE-2025-30756 | Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unau… | MEDIUM | 6.1 | Jul 15, 2025 |
| CVE-2021-41184 | XSS in the `of` option of the `.position()` util | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41183 | XSS in `*Text` options of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41182 | XSS in the `altField` option of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-32014 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when rea… | MEDIUM | 5.5 | Jul 19, 2021 |
| CVE-2021-32013 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when… | MEDIUM | 5.5 | Jul 19, 2021 |
| CVE-2021-32012 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when… | MEDIUM | 5.5 | Jul 19, 2021 |
| CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints | MEDIUM | 5.3 | Jul 15, 2021 |
| CVE-2021-34428 | jetty: SessionListener can prevent a session from being invalidated breaking logout | LOW | 3.5 | Jun 22, 2021 |
| CVE-2021-28169 | jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory | MEDIUM | 5.3 | Jun 9, 2021 |
| CVE-2021-29425 | Possible limited path traversal vulnerabily in Apache Commons IO | MEDIUM | 4.8 | Apr 13, 2021 |
| CVE-2021-28165 | jetty: Resource exhaustion when receiving an invalid large TLS frame | HIGH | 7.5 | Apr 1, 2021 |
| CVE-2020-27223 | jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS | MEDIUM | 5.3 | Feb 26, 2021 |
| CVE-2020-27218 | jetty: buffer not correctly recycled in Gzip Request inflation | MEDIUM | 4.8 | Nov 28, 2020 |
| CVE-2020-14745 | Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General). Supported versions that are affected are 11.2.0.4, 12… | MEDIUM | 4.3 | Oct 21, 2020 |
Showing 1 to 25 of 34 CVEs