Known Vulnerabilities for Application Server by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Application Server" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66751 json | Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-66398 json | phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated admi... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-66337 json | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a hea... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-66009 json | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that... | Not Provided | 2026-07-24 | 2026-07-28 |
| CVE-2026-66008 json | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class na... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-65700 json | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated r... | Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-65693 json | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrator... | Not Provided | 2026-07-24 | 2026-07-28 |
| CVE-2026-65689 json | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database d... | Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-65688 json | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font proce... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-65687 json | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG proces... | Not Provided | 2026-07-23 | 2026-07-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Application Server | 9.2.0.7 | |||
| Application | Oracle | Application Server | 9.2.0.6 | |||
| Application | Oracle | Application Server | 9.0.4.3 | |||
| Application | Oracle | Application Server | 9.0.4.2 | |||
| Application | Oracle | Application Server | 9.0.4.1 | |||
| Application | Oracle | Application Server | 9.0.4.0 | |||
| Application | Oracle | Application Server | 9.0.4 | |||
| Application | Oracle | Application Server | 9.0.3.1 | |||
| Application | Oracle | Application Server | 9.0.3 | |||
| Application | Oracle | Application Server | 9.0.2.3 | |||
| Application | Oracle | Application Server | 9.0.2.2 | |||
| Application | Oracle | Application Server | 9.0.2.1 | |||
| Application | Oracle | Application Server | 9.0.2.0.1 | |||
| Application | Oracle | Application Server | 9.0.2.0.0 | |||
| Application | Oracle | Application Server | 9.0.2 | |||
| Application | Oracle | Application Server | 9.0.2 | |||
| Application | Oracle | Application Server | 9.0 | |||
| Application | Oracle | Application Server | 8.1.7 | |||
| Application | Oracle | Application Server | 7.0.4.4 | |||
| Application | Oracle | Application Server | 4.0.8.2 |