Oracle / Retail Xstore Point of Service
127 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-21954 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affe… | MEDIUM | 4.3 | Jul 21, 2026 |
| CVE-2026-21953 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affe… | LOW | 3.3 | Jul 21, 2026 |
| CVE-2022-22965 KEV | spring-framework: RCE via Data Binding on JDK 9+ | CRITICAL | 9.8 | Apr 1, 2022 |
| CVE-2022-22963 KEV | spring-cloud-function: Remote code execution by malicious Spring Expression | CRITICAL | 9.8 | Apr 1, 2022 |
| CVE-2021-43859 | Denial of Service by injecting highly recursive collections or maps in XStream | HIGH | 7.5 | Feb 1, 2022 |
| CVE-2021-44832 | Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration | MEDIUM | 6.6 | Dec 28, 2021 |
| CVE-2021-39150 | A Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39152 | A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39140 | XStream can cause a Denial of Service | MEDIUM | 6.5 | Aug 23, 2021 |
| CVE-2021-39149 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39148 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39147 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39146 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39145 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39141 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39151 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39139 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.8 | Aug 23, 2021 |
| CVE-2021-39154 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39144 KEV | XStream is vulnerable to a Remote Command Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2021-36374 | Apache Ant ZIP, and ZIP based, archive denial of service vulerability | MEDIUM | 5.5 | Jul 14, 2021 |
| CVE-2021-36373 | Apache Ant TAR archive denial of service vulnerability | MEDIUM | 5.5 | Jul 14, 2021 |
| CVE-2021-29505 | XStream is vulnerable to a Remote Command Execution attack | HIGH | 8.8 | May 28, 2021 |
| CVE-2021-29425 | Possible limited path traversal vulnerabily in Apache Commons IO | MEDIUM | 4.8 | Apr 13, 2021 |
| CVE-2021-21348 | XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos) | HIGH | 7.5 | Mar 22, 2021 |
Showing 1 to 25 of 127 CVEs