cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-21824,https://securityvulnerability.io/vulnerability/CVE-2023-21824,Oracle Communications BRM - Elastic Charging Engine Vulnerability,"A vulnerability exists in Oracle Communications BRM - Elastic Charging Engine that permits unauthorized access when a high-privilege attacker logs on to the affected infrastructure. This exploitation could lead to unauthorized access to critical data or potentially grant full access to all accessible data within the Elastic Charging Engine, impacting the confidentiality of sensitive information.",Oracle,Communications BRM - Elastic Charging Engine,4.4,MEDIUM,0.00044999999227002263,false,,false,false,false,,,false,false,,2023-01-18T00:15:00.000Z,0 CVE-2021-2405,https://securityvulnerability.io/vulnerability/CVE-2021-2405,Vulnerability in Oracle Engineering of Oracle E-Business Suite,"A vulnerability exists in the Oracle Engineering component of Oracle E-Business Suite, where low-privileged attackers with network access via HTTP can exploit it. This vulnerability allows for unauthorized creation, deletion, or modification of critical data, potentially leading to extensive access to all Oracle Engineering accessible data. Organizations using affected versions 12.2.3 through 12.2.10 should prioritize remediation to safeguard against data breaches and unauthorized access.",Oracle,Engineering,8.1,HIGH,0.0009399999980814755,false,,false,false,false,,,false,false,,2021-07-20T22:44:18.000Z,0 CVE-2021-2290,https://securityvulnerability.io/vulnerability/CVE-2021-2290,Data Manipulation Vulnerability in Oracle E-Business Suite Engineering,"A vulnerability affecting the Oracle Engineering component in the Oracle E-Business Suite allows an attacker with low privileges and network access to exploit the system via HTTP. This easily exploitable flaw can lead to unauthorized creation, deletion, or modification of critical data. Successful exploitation provides the attacker with significant access, enabling them to compromise the integrity and confidentiality of Oracle Engineering's accessible data.",Oracle,Engineering,8.1,HIGH,0.0009399999980814755,false,,false,false,false,,,false,false,,2021-04-22T21:54:00.000Z,0 CVE-2020-10775,https://securityvulnerability.io/vulnerability/CVE-2020-10775,Open Redirect Vulnerability in oVirt Engine by Red Hat,"An Open Redirect vulnerability exists in oVirt Engine versions 4.4 and earlier, allowing remote attackers to deceive users into visiting malicious websites. This could facilitate phishing attacks, as unsuspecting users will be redirected without clear visibility of the destination URL. When exploited, this vulnerability poses a significant risk to user confidentiality, as attackers can trick users into disclosing sensitive information.",Oracle,Ovirt-engine,5.3,MEDIUM,0.0021899999119341373,false,,false,false,false,,,false,false,,2020-08-24T16:13:00.000Z,0 CVE-2018-2632,https://securityvulnerability.io/vulnerability/CVE-2018-2632,,Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Engineering - Installer and Deployment. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel Engineering - Installer and Deployment accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).,Oracle,Siebel Engineering - Installer And Deployment,4.3,MEDIUM,0.0004900000058114529,false,,false,false,false,,,false,false,,2018-01-18T02:00:00.000Z,0 CVE-2017-10161,https://securityvulnerability.io/vulnerability/CVE-2017-10161,,"Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Services Security). Supported versions that are affected are 6.1.3.0 and 6.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Engineering Data Management accessible data. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",Oracle,Agile Engineering Data Management,4.8,MEDIUM,0.0006799999973736703,false,,false,false,false,,,false,false,,2017-10-19T17:00:00.000Z,0 CVE-2016-5518,https://securityvulnerability.io/vulnerability/CVE-2016-5518,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to webfileservices.",Oracle,Agile Engineering Data Management,8.1,HIGH,0.0030799999367445707,false,,false,false,false,,,false,false,,2016-10-25T14:00:00.000Z,0 CVE-2016-3468,https://securityvulnerability.io/vulnerability/CVE-2016-3468,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Install.",Oracle,Agile Engineering Data Management,9.8,CRITICAL,0.006949999835342169,false,,false,false,false,,,false,false,,2016-07-21T10:00:00.000Z,0 CVE-2016-3472,https://securityvulnerability.io/vulnerability/CVE-2016-3472,,"Unspecified vulnerability in the Siebel Engineering - Installer and Deployment component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Web Server.",Oracle,Siebel Engineering-installer And Deployment,5.7,MEDIUM,0.0011699999449774623,false,,false,false,false,,,false,false,,2016-07-21T10:00:00.000Z,0 CVE-2016-0635,https://securityvulnerability.io/vulnerability/CVE-2016-0635,,"Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle Documaker component in Oracle Insurance Applications before 12.5; the Oracle Insurance Calculation Engine component in Oracle Insurance Applications 9.7.1, 10.1.2, and 10.2.2; the Oracle Insurance Policy Administration J2EE and Oracle Insurance Rules Palette components in Oracle Insurance Applications 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, and 10.2.2; the Oracle Retail Integration Bus component in Oracle Retail Applications 15.0; the Oracle Retail Order Broker component in Oracle Retail Applications 5.1, 5.2, and 15.0; the Primavera Contract Management component in Oracle Primavera Products Suite 14.2; the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.2, 8.3, 8.4, 15.1, 15.2, and 16.1; the Oracle Financial Services Analytical Applications Infrastructure component in Oracle Financial Services Applications 8.0.0, 8.0.1, 8.0.2, and 8.0.3; the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce 3.1.1, 3.1.2, 11.0, 11.1, and 11.2; the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5; the Oracle Communications BRM - Elastic Charging Engine 11.2.0.0.0 and 11.3.0.0.0; the Oracle Enterprise Repository Enterprise Repository 12.1.3.0.0; the Oracle Financial Services Behavior Detection Platform 8.0.1 and 8.0.2; the Oracle Hyperion Essbase 12.2.1.1; the Oracle Tuxedo System and Applications Monitor (TSAM) 11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.1, 12.1.1.1.0, 12.1.3.0.0, and 12.2.2.0.0; the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Spring)) 7.0, 7.1 and 7.2; the Oracle Endeca Information Discovery Integrator 3.2; the Converged Commerce component of Oracle Retail Applications 16.0.1; the Oracle Identity Manager 11.1.2.3.0; Oracle Enterprise Manager for MySQL Database 12.1.0.4; Oracle Retail Invoice Matching 12.0, 13.0, 13.1, 13.2, 14.0, and 14.1; Oracle Communications Performance Intelligence Center (PIC) Software Prior to 10.2.1 and the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: AnswerFlow (Spring Framework)) version 8.5.1.0 - 8.5.1.7 and 8.6.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.",Oracle,"Documaker,Insurance Policy Administration J2ee,Insurance Calculation Engine,Insurance Rules Palette,Enterprise Manager Ops Center,Primavera P6 Enterprise Project Portfolio Management,Retail Order Broker Cloud Service,Primavera Contract Management,Health Sciences Information Manager,Healthcare Master Person Index,Retail Integration Bus",8.8,HIGH,0.0020600000862032175,false,,false,false,false,,,false,false,,2016-07-21T10:00:00.000Z,0 CVE-2016-3428,https://securityvulnerability.io/vulnerability/CVE-2016-3428,,Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface.,Oracle,Agile Engineering Data Management,3.1,LOW,0.0009899999713525176,false,,false,false,false,,,false,false,,2016-04-21T10:00:00.000Z,0 CVE-2016-0497,https://securityvulnerability.io/vulnerability/CVE-2016-0497,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows remote attackers to affect integrity via unknown vectors related to Web Client.",Oracle,Agile Engineering Data Management,,,0.0008299999753944576,false,,false,false,false,,,false,false,,2016-01-21T02:00:00.000Z,0 CVE-2016-0498,https://securityvulnerability.io/vulnerability/CVE-2016-0498,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install.",Oracle,Agile Engineering Data Management,,,0.0006000000284984708,false,,false,false,false,,,false,false,,2016-01-21T02:00:00.000Z,0 CVE-2009-0046,https://securityvulnerability.io/vulnerability/CVE-2009-0046,,"Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.",Oracle,Grid Engine,,,0.0030499999411404133,false,,false,false,false,,,false,false,,2009-01-07T18:00:00.000Z,0 CVE-2008-1756,https://securityvulnerability.io/vulnerability/CVE-2008-1756,,Unspecified vulnerability in the Qmaster daemon in Sun N1 Grid Engine 6.1 allows local users to cause a denial of service (daemon crash) via unspecified vectors.,Oracle,N1 Grid Engine,,,0.0004400000034365803,false,,false,false,false,,,false,false,,2008-04-11T20:28:00.000Z,0 CVE-2006-3941,https://securityvulnerability.io/vulnerability/CVE-2006-3941,,Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate.,Oracle,N1 Grid Engine,,,0.0032599999103695154,false,,false,false,false,,,false,false,,2006-07-31T23:04:00.000Z,0 CVE-2006-2930,https://securityvulnerability.io/vulnerability/CVE-2006-2930,,"Unspecified vulnerability in Sun Grid Engine 5.3 and Sun N1 Grid Engine 6.0, when configured in Certificate Security Protocol (CSP) Mode, allows local users to shut down the grid service or gain access, even if access is denied.",Oracle,"N1 Grid Engine,Grid Engine",,,0.0004400000034365803,false,,false,false,false,,,false,false,,2006-06-09T10:00:00.000Z,0 CVE-2006-1506,https://securityvulnerability.io/vulnerability/CVE-2006-1506,,Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.,Oracle,"N1 Grid Engine,Grid Engine",,,0.0004400000034365803,false,,false,false,false,,,false,false,,2006-03-30T01:00:00.000Z,0 CVE-2006-0408,https://securityvulnerability.io/vulnerability/CVE-2006-0408,,"rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.",Oracle,Grid Engine,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2006-01-25T02:00:00.000Z,0