« Back to list

Oracle

Oracle Solaris: vulnerabilities and CVEs

Oracle Solaris has 565 published vulnerabilities, 16 of them in the last 12 months. 18 are rated critical and 6 are listed by CISA as actively exploited.

CVEs565
Last 12 months16
Critical18
Actively exploited6

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2019-3010High (8.8)13%⚠ Active exploitationOct 16, 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2015-4495High (8.8)69%⚠ Active exploitationAug 8, 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via…
CVE-2008-2992High (7.8)98%⚠ Active exploitationNov 4, 2008
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string…
CVE-2020-14871Critical (10)80%⚠ Active exploitationOct 21, 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated…
CVE-2016-3718Medium (5.5)77%⚠ Active exploitationMay 5, 2016
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
CVE-2016-3715Medium (5.5)75%⚠ Active exploitationMay 5, 2016
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-16606Critical (9.3)1.1%—Jul 22, 2026
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas…
CVE-2026-61202High (7.5)0.13%—Jul 21, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 11.3 and 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to…
CVE-2026-61052Medium (5.5)0.15%—Jul 21, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2026-60834High (7.1)0.24%—Jul 21, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access…
CVE-2026-60833High (7)0.13%—Jul 21, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the…
CVE-2026-60661High (7.8)0.13%—Jul 21, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the…
CVE-2026-60659High (7.1)0.14%—Jul 21, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2026-46978Critical (10)0.43%—Jun 17, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker…
CVE-2026-46914High (7.1)0.16%—Jun 17, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2026-34281Medium (6.5)0.15%—Apr 21, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2026-21942Medium (5)0.14%—Jan 20, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to…
CVE-2026-21935Medium (5.8)0.22%—Jan 20, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the…
CVE-2026-21928Medium (5.3)0.33%—Jan 20, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
CVE-2026-21927Medium (5.8)0.22%—Jan 20, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the…
CVE-2025-53070Medium (5.5)0.15%—Oct 21, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the…
CVE-2025-53068Medium (6.5)0.15%—Oct 21, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2025-30700Low (3.5)0.49%—Apr 15, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker…
CVE-2025-30690High (7.2)0.21%—Apr 15, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the…
CVE-2025-21551Medium (6)0.19%—Jan 21, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the…
CVE-2024-21151Low (3.3)0.20%—Jul 16, 2024
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2024-21105Low (2)0.26%—Apr 16, 2024
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the…
CVE-2024-21059High (7.8)0.17%—Apr 16, 2024
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the…
CVE-2024-20999High (8.2)0.27%—Apr 16, 2024
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Zones). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the…
CVE-2024-20946Medium (5.5)0.18%—Jan 16, 2024
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2024-20920Low (3.8)0.19%—Jan 16, 2024
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2023-22129Medium (5.5)0.18%—Oct 17, 2023
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the…
CVE-2023-22128Low (3.1)0.34%—Oct 17, 2023
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows unauthenticated attacker with network…
CVE-2023-22023High (7.8)0.19%—Jul 18, 2023
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with…
CVE-2023-22003Low (3.3)0.22%—Apr 18, 2023
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the…
CVE-2023-21985High (7.7)0.23%—Apr 18, 2023
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the…

Other products by Oracle