Oracle
Oracle Solaris: vulnerabilities and CVEs
Oracle Solaris has 565 published vulnerabilities, 16 of them in the last 12 months. 18 are rated critical and 6 are listed by CISA as actively exploited.
CVEs565
Last 12 months16
Critical18
Actively exploited6
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3010 | High (8.8) | 13% | ⚠ Active exploitation | Oct 16, 2019 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2015-4495 | High (8.8) | 69% | ⚠ Active exploitation | Aug 8, 2015 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via… |
| CVE-2008-2992 | High (7.8) | 98% | ⚠ Active exploitation | Nov 4, 2008 | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string… |
| CVE-2020-14871 | Critical (10) | 80% | ⚠ Active exploitation | Oct 21, 2020 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated… |
| CVE-2016-3718 | Medium (5.5) | 77% | ⚠ Active exploitation | May 5, 2016 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
| CVE-2016-3715 | Medium (5.5) | 75% | ⚠ Active exploitation | May 5, 2016 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16606 | Critical (9.3) | 1.1% | — | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas… |
| CVE-2026-61202 | High (7.5) | 0.13% | — | Jul 21, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 11.3 and 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to… |
| CVE-2026-61052 | Medium (5.5) | 0.15% | — | Jul 21, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2026-60834 | High (7.1) | 0.24% | — | Jul 21, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access… |
| CVE-2026-60833 | High (7) | 0.13% | — | Jul 21, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the… |
| CVE-2026-60661 | High (7.8) | 0.13% | — | Jul 21, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the… |
| CVE-2026-60659 | High (7.1) | 0.14% | — | Jul 21, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2026-46978 | Critical (10) | 0.43% | — | Jun 17, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker… |
| CVE-2026-46914 | High (7.1) | 0.16% | — | Jun 17, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2026-34281 | Medium (6.5) | 0.15% | — | Apr 21, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2026-21942 | Medium (5) | 0.14% | — | Jan 20, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to… |
| CVE-2026-21935 | Medium (5.8) | 0.22% | — | Jan 20, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the… |
| CVE-2026-21928 | Medium (5.3) | 0.33% | — | Jan 20, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via… |
| CVE-2026-21927 | Medium (5.8) | 0.22% | — | Jan 20, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the… |
| CVE-2025-53070 | Medium (5.5) | 0.15% | — | Oct 21, 2025 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the… |
| CVE-2025-53068 | Medium (6.5) | 0.15% | — | Oct 21, 2025 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2025-30700 | Low (3.5) | 0.49% | — | Apr 15, 2025 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker… |
| CVE-2025-30690 | High (7.2) | 0.21% | — | Apr 15, 2025 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the… |
| CVE-2025-21551 | Medium (6) | 0.19% | — | Jan 21, 2025 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the… |
| CVE-2024-21151 | Low (3.3) | 0.20% | — | Jul 16, 2024 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2024-21105 | Low (2) | 0.26% | — | Apr 16, 2024 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the… |
| CVE-2024-21059 | High (7.8) | 0.17% | — | Apr 16, 2024 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the… |
| CVE-2024-20999 | High (8.2) | 0.27% | — | Apr 16, 2024 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Zones). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the… |
| CVE-2024-20946 | Medium (5.5) | 0.18% | — | Jan 16, 2024 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2024-20920 | Low (3.8) | 0.19% | — | Jan 16, 2024 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2023-22129 | Medium (5.5) | 0.18% | — | Oct 17, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the… |
| CVE-2023-22128 | Low (3.1) | 0.34% | — | Oct 17, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows unauthenticated attacker with network… |
| CVE-2023-22023 | High (7.8) | 0.19% | — | Jul 18, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with… |
| CVE-2023-22003 | Low (3.3) | 0.22% | — | Apr 18, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the… |
| CVE-2023-21985 | High (7.7) | 0.23% | — | Apr 18, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the… |