- EPSS 0.1%
- Veröffentlicht 15.07.2025 19:27:36
- Zuletzt bearbeitet 24.07.2025 21:27:21
Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comp...
CVE-2025-21557
- EPSS 0.04%
- Veröffentlicht 21.01.2025 21:15:22
- Zuletzt bearbeitet 23.06.2025 18:08:52
Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application ...
CVE-2007-3854
- EPSS 7.88%
- Veröffentlicht 18.07.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial compone...
CVE-2007-3860
- EPSS 1.69%
- Veröffentlicht 18.07.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01. NOTE: a reliable researcher states that this is SQL i...
- EPSS 0.68%
- Veröffentlicht 07.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matchin...
CVE-2006-7158
- EPSS 0.39%
- Veröffentlicht 07.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via the NOTIFICATION_MSG parameter. NOTE: it is likely that this issue ove...
CVE-2006-5599
- EPSS 1.24%
- Veröffentlicht 28.10.2006 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP package. NOTE: it is likely that this issue overlaps one...
- EPSS 0.72%
- Veröffentlicht 18.10.2006 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2) APEX02, (3) APEX03, (4) APEX05, (5) APEX06, (6) APEX07, (7) APEX08, (8...
- EPSS 0.79%
- Veröffentlicht 18.10.2006 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Oracle Application Express 1.5 up to 1.6.1 have unknown impact and remote attack vectors, aka Vuln# (1) APEX04, (2) APEX20, and (3) APEX21.