CVE Tools

Java

1,164 CVEs tracked. 14 of them are in CISA KEV.

This hub aggregates every CVE we track for Java, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Java CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Java CVEs per month
MonthCVEs
2024-105
2024-110
2024-120
2025-011
2025-020
2025-030
2025-043
2025-050
2025-060
2025-077
2025-080
2025-090
2025-103
2025-110
2025-120
2026-015
2026-020
2026-030
2026-049
2026-050
2026-060
2026-0718
2026-080
2026-090

Severity

How the 1,164 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical32328%
  • High19917%
  • Medium49042%
  • Low15013%

Latest CVEs

The 15 most recently published vulnerabilities affecting Java.

  1. CVE-2026-62574Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java ...7.8
  2. CVE-2026-60526Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult to exploit vulnerability allows low privileged ...6.7
  3. CVE-2026-60166Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
  4. CVE-2026-60164Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
  5. CVE-2026-60147Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java...6.5
  6. CVE-2026-47063Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Jav...7.5
  7. CVE-2026-47057Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthentic...7.5
  8. CVE-2026-47059Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8...3.7
  9. CVE-2026-47058Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthent...7.4
  10. CVE-2026-47034Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
  11. CVE-2026-47035Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
  12. CVE-2026-47027Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JD...5.3
  13. CVE-2026-47030Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
  14. CVE-2026-47021Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8...5.3
  15. CVE-2026-47013Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network...5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store