Synced 16 Jun 2026 15:24 UTC Account
← Oracle WebLogic

Oracle WebLogic vulnerabilities: known CVEs & security history

Oracle · Infrastructure · 309 tracked CVEs · 16 actively exploited · updated June 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all Oracle WebLogic release lines — 309 in total, with 16 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Oracle WebLogic's current status and the safe version to run.

309
known CVEs
16
actively exploited (KEV)
74
critical severity
3
ransomware-linked

Known Oracle WebLogic CVEs

Actively-exploited and most-severe first. Showing the top 80 of 309. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2022-22965⚡ exploited critical 9.8 100% 2022
CVE-2020-14750⚡ exploited critical 9.8 99% 2020
CVE-2020-14882⚡ exploited critical 9.8 100% 2020
CVE-2020-14644⚡ exploited critical 9.8 95% 2020
CVE-2020-2883⚡ exploited critical 9.8 95% 2020
CVE-2020-2551⚡ exploited critical 9.8 93% 2020
CVE-2019-2725⚡ exploited critical 9.8 100% 2019
CVE-2018-2628⚡ exploited critical 9.8 99% 2018
CVE-2017-5638⚡ exploited critical 9.8 100% 2017
CVE-2015-4852⚡ exploited critical 9.8 96% 2015
CVE-2024-21182⚡ exploited high 7.5 48% 2024
CVE-2023-21839⚡ exploited high 7.5 100% 2023
CVE-2017-10271⚡ exploited high 7.5 100% 2017
CVE-2017-3506⚡ exploited high 7.4 96% 2017
CVE-2020-14883⚡ exploited high 7.2 98% 2020
CVE-2020-11023⚡ exploited medium 6.9 84% 2020
CVE-2017-10137 critical 10 4% 2017
CVE-2017-10352 critical 9.9 6% 2017
CVE-2025-21535 critical 9.8 1% 2025
CVE-2024-21216 critical 9.8 1% 2024
CVE-2024-21181 critical 9.8 1% 2024
CVE-2023-22089 critical 9.8 1% 2023
CVE-2023-22072 critical 9.8 1% 2023
CVE-2023-22069 critical 9.8 1% 2023
CVE-2022-21306 critical 9.8 4% 2022
CVE-2022-23305 critical 9.8 67% 2022
CVE-2021-35617 critical 9.8 2% 2021
CVE-2021-2397 critical 9.8 2% 2021
CVE-2021-2394 critical 9.8 77% 2021
CVE-2021-2382 critical 9.8 2% 2021
CVE-2021-2136 critical 9.8 2% 2021
CVE-2021-2135 critical 9.8 8% 2021
CVE-2021-2108 critical 9.8 4% 2021
CVE-2021-2075 critical 9.8 4% 2021
CVE-2021-2064 critical 9.8 4% 2021
CVE-2021-2047 critical 9.8 4% 2021
CVE-2021-1994 critical 9.8 5% 2021
CVE-2020-14859 critical 9.8 4% 2020
CVE-2020-14841 critical 9.8 52% 2020
CVE-2020-14825 critical 9.8 31% 2020
CVE-2020-14687 critical 9.8 2% 2020
CVE-2020-14645 critical 9.8 46% 2020
CVE-2020-14625 critical 9.8 10% 2020
CVE-2020-2884 critical 9.8 2% 2020
CVE-2020-2801 critical 9.8 3% 2020
CVE-2020-9548 critical 9.8 18% 2020
CVE-2020-9547 critical 9.8 19% 2020
CVE-2020-9546 critical 9.8 5% 2020
CVE-2020-2546 critical 9.8 5% 2020
CVE-2019-20330 critical 9.8 9% 2020
CVE-2019-17571 critical 9.8 69% 2019
CVE-2019-17195 critical 9.8 11% 2019
CVE-2019-17531 critical 9.8 5% 2019
CVE-2019-17267 critical 9.8 5% 2019
CVE-2019-16943 critical 9.8 5% 2019
CVE-2019-16942 critical 9.8 6% 2019
CVE-2019-16335 critical 9.8 5% 2019
CVE-2019-14540 critical 9.8 11% 2019
CVE-2019-2856 critical 9.8 2% 2019
CVE-2019-2729 critical 9.8 89% 2019
CVE-2019-2658 critical 9.8 2% 2019
CVE-2019-2646 critical 9.8 2% 2019
CVE-2019-2645 critical 9.8 2% 2019
CVE-2018-3252 critical 9.8 28% 2018
CVE-2018-3245 critical 9.8 94% 2018
CVE-2018-3201 critical 9.8 3% 2018
CVE-2018-3197 critical 9.8 3% 2018
CVE-2018-3191 critical 9.8 62% 2018
CVE-2018-2894 critical 9.8 50% 2018
CVE-2018-2893 critical 9.8 71% 2018
CVE-2018-1000613 critical 9.8 5% 2018
CVE-2017-5645 critical 9.8 89% 2017
CVE-2017-3248 critical 9.8 97% 2017
CVE-2016-5535 critical 9.8 5% 2016
CVE-2016-5531 critical 9.8 5% 2016
CVE-2016-3551 critical 9.8 5% 2016
CVE-2016-3586 critical 9.8 20% 2016
CVE-2016-3510 critical 9.8 91% 2016
CVE-2016-3499 critical 9.8 9% 2016
CVE-2016-0638 critical 9.8 63% 2016

229 older / lower-severity CVEs not shown — see Oracle WebLogic's full record.

Is my Oracle WebLogic version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your Oracle WebLogic version → · Monitor Oracle WebLogic for new CVEs →

Oracle WebLogic vulnerabilities — frequently asked

How many known vulnerabilities does Oracle WebLogic have?

IsItPatched tracks 309 CVEs for Oracle WebLogic, 16 of which are actively exploited (CISA KEV). 74 are critical-severity and 99 high-severity. These span every release line — what matters is whether the version you run is affected.

Does Oracle WebLogic have any actively-exploited vulnerabilities?

Yes — 16 Oracle WebLogic CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (3 linked to ransomware). Patch these as a priority.

What is the most severe Oracle WebLogic vulnerability?

Among tracked issues, CVE-2022-22965 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Code injection weakness.

Is Oracle WebLogic safe to use?

It depends on the version. The latest supported Oracle WebLogic release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Oracle WebLogic security status · Oracle WebLogic end-of-life · actively-exploited CVEs. Always verify against Oracle's advisories — see our disclaimer.