Known Vulnerabilities for Database Server by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Database Server" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77070 json | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggr... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-76224 json | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin q... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-75855 json | ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and dro... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-75854 json | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows ... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75853 json | ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL P... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75851 json | ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal ... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75846 json | ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQ... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75844 json | ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the ... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75839 json | ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerability i... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-74891 json | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attack... | Not Provided | 2026-08-17 | 2026-08-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Database Server | 9.2.2 | |||
| Application | Oracle | Database Server | 9.2.1 | |||
| Application | Oracle | Database Server | 9.2.0.8dv | |||
| Application | Oracle | Database Server | 9.2.0.8dv | |||
| Application | Oracle | Database Server | 9.2.0.8 | |||
| Application | Oracle | Database Server | 9.2.0.8 | |||
| Application | Oracle | Database Server | 9.2.0.7 | |||
| Application | Oracle | Database Server | 9.2.0.7 | |||
| Application | Oracle | Database Server | 9.2.0.6 | |||
| Application | Oracle | Database Server | 9.2.0.6 | |||
| Application | Oracle | Database Server | 9.2.0.5 | |||
| Application | Oracle | Database Server | 9.2.0.4 | |||
| Application | Oracle | Database Server | 9.2.0.3 | |||
| Application | Oracle | Database Server | 9.2.0.2 | |||
| Application | Oracle | Database Server | 9.2.0.1 | |||
| Application | Oracle | Database Server | 9.2 | |||
| Application | Oracle | Database Server | 9.0.4 | |||
| Application | Oracle | Database Server | 9.0.2.4 | |||
| Application | Oracle | Database Server | 9.0.2.4 | |||
| Application | Oracle | Database Server | 9.0.1.5 |