Known vulnerabilities in Oracle HTTP Server

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_http_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 93
Public exploits: 13
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle HTTP Server Oracle HTTP Server is affected by 93 known vulnerabilities: 2 critical, 22 high, 49 medium, 20 low Critical High Medium Low

Vulnerabilities (93)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126739 - Improper input validation
CVE-2026-34291
CWE-20 High
No
No
- 22.04.2026 SB20260422150
#VU121716 - Heap-based Buffer Overflow
CVE-2026-21962
CWE-122 Critical
Available
Exploited
- 20.01.2026 SB20260120114
SB20260120125
#VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CVE-2025-58098
CWE-97 Low
Available
No
- 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 47 more
#VU119148 - Server-Side Request Forgery (SSRF)
CVE-2025-59775
CWE-918 Medium
No
No
- 04.12.2025 SB2025120441
SB2026010820
SB20260114117
and 11 more
#VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-65082
CWE-74 Low
No
No
- 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 33 more
#VU115751 - Resource exhaustion
CVE-2025-59375
CWE-400 Medium
No
No
- 17.09.2025 SB2025091783
SB2025091789
SB2025091790
and 108 more
#VU113672 - Unchecked Return Value
CVE-2025-54571
CWE-252 Medium
No
No
- 06.08.2025 SB2025080617
SB20250816115
SB20250816119
and 40 more
#VU112734 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2024-42516
CWE-113 Low
No
No
- 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 36 more
#VU112733 - Server-Side Request Forgery (SSRF)
CVE-2024-43204
CWE-918 Low
No
No
- 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 28 more
#VU112732 - Server-Side Request Forgery (SSRF)
CVE-2024-43394
CWE-918 Medium
No
No
- 10.07.2025 SB2025071040
SB2025071710
SB2025072111
and 8 more
#VU112731 - Improper Encoding or Escaping of Output
CVE-2024-47252
CWE-116 High
No
No
- 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 35 more
#VU112730 - Security Features
CVE-2025-23048
CWE-254 Medium
Available
No
- 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 30 more
#VU111223 - Type confusion
CVE-2025-49796
CWE-843 Medium
No
No
- 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 84 more
#VU105723 - Stack-based buffer overflow
CVE-2024-8176
CWE-121 High
No
No
- 14.03.2025 SB2025031426
SB2025031429
SB2025031430
and 105 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
- 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU103646 - Integer overflow
CVE-2025-0725
CWE-190 High
No
No
- 05.02.2025 SB2025020531
SB2025020601
SB2025020658
and 25 more
#VU96997 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-40896
CWE-611 High
No
No
- 10.09.2024 SB2024091054
SB2024091056
SB2024091071
and 10 more
#VU93544 - Improper input validation
CVE-2024-38477
CWE-20 Medium
No
No
- 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 58 more
#VU93543 - Server-Side Request Forgery (SSRF)
CVE-2024-38476
CWE-918 High
No
No
- 01.07.2024 SB2024070155
SB20240702144
SB2024070402
and 61 more
#VU70994 - Memory corruption
CVE-2022-41342
CWE-119 Low
No
No
- 10.01.2023 SB2023011066
SB20260120110
SB20260120113
and 2 more


Showing elements 1 - 20 out of 93