CVE Tools

Java Virtual Machine

25 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Java Virtual Machine, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Java Virtual Machine CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Java Virtual Machine CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-020
2025-030
2025-041
2025-050
2025-060
2025-071
2025-080
2025-090
2025-101
2025-110
2025-120
2026-011
2026-020
2026-030
2026-041
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical14%
  • High1040%
  • Medium1248%
  • Low28%

Latest CVEs

The 15 most recently published vulnerabilities affecting Java Virtual Machine.

  1. CVE-2026-35229Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.30 and 21.3-21.21. Easily exploitable vulnerability allows unauthenticated attac...7.5
  2. CVE-2026-21975Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 and 21.3-21.20. Easily exploitable vulnerability allows high privileged attac...4.5
  3. CVE-2025-61881Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Difficult to exploit vulnerability allows unauthen...5.9
  4. CVE-2025-50069Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. Easily exploitable vulnerability allows low privileged attack...7.7
  5. CVE-2025-30736Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Difficult to exploit vulnerability allows unauthen...7.4
  6. CVE-2025-21553Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low priv...4.2
  7. CVE-2024-21093Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged atta...5.3
  8. CVE-2022-39429Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Crea...4.3
  9. CVE-2022-39419Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create...4.3
  10. CVE-2021-35619Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Difficult to exploit vulnerability allows low privileged ...7.1
  11. CVE-2021-2438Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacke...4.3
  12. CVE-2020-14743Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low p...3.1
  13. CVE-2007-5375Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet conte...2.6
  14. CVE-2004-0723Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT...6.4
  15. CVE-2002-1289The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code vi...7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store