Known Vulnerabilities for Retail Point-of-service by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Retail Point-of-service" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-21954 json | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). ... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-21953 json | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). ... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2020-11987 json | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. B... | 8.2 - HIGH | 2021-02-24 | 2024-02-01 |
| CVE-2020-5398 json | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an ap... | 7.5 - HIGH | 2020-01-17 | 2023-11-07 |
| CVE-2020-5397 json | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Sp... | 5.3 - MEDIUM | 2020-01-17 | 2022-07-25 |
| CVE-2020-1945 json | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property jav... | 6.3 - MEDIUM | 2020-05-14 | 2023-11-07 |
| CVE-2019-17566 json | Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes... | 7.5 - HIGH | 2020-11-12 | 2024-01-07 |
| CVE-2019-13990 json | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via... | 9.8 - CRITICAL | 2019-07-26 | 2023-12-22 |
| CVE-2019-11358 json | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of ... | 6.1 - MEDIUM | 2019-04-20 | 2023-11-07 |
| CVE-2019-10086 json | Not Provided | 2019-08-20 | 2026-08-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Retail Point-of-service | 7.1.6 | |||
| Application | Oracle | Retail Point-of-service | 7.1.5 | |||
| Application | Oracle | Retail Point-of-service | 7.1.4 | |||
| Application | Oracle | Retail Point-of-service | 7.1.3 | |||
| Application | Oracle | Retail Point-of-service | 7.1.2 | |||
| Application | Oracle | Retail Point-of-service | 7.1.1 | |||
| Application | Oracle | Retail Point-of-service | 7.1.0 | |||
| Application | Oracle | Retail Point-of-service | 7.0.6 | |||
| Application | Oracle | Retail Point-of-service | 7.0.5 | |||
| Application | Oracle | Retail Point-of-service | 7.0.4 | |||
| Application | Oracle | Retail Point-of-service | 7.0.3 | |||
| Application | Oracle | Retail Point-of-service | 7.0.2 | |||
| Application | Oracle | Retail Point-of-service | 7.0.1 | |||
| Application | Oracle | Retail Point-of-service | 7.0.0 | |||
| Application | Oracle | Retail Point-of-service | 6.5.4 | |||
| Application | Oracle | Retail Point-of-service | 6.5.11 | |||
| Application | Oracle | Retail Point-of-service | 6.5.10 | |||
| Application | Oracle | Retail Point-of-service | 6.5.0 | |||
| Application | Oracle | Retail Point-of-service | 6.0.11 | |||
| Application | Oracle | Retail Point-of-service | 6.0.10 |