Every CVE whose affected-product data names Oracle Helidon, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (115)
CVE-2026-73930 — CVSS 9.9 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71164 — CVSS 9.8 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73905 — CVSS 9.8 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71074 — CVSS 9.8 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71152 — CVSS 9.8 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73921 — CVSS 9.8 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73912 — CVSS 9.8 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71167 — CVSS 9.4 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73920 — CVSS 9.4 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71166 — CVSS 9.4 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71065 — CVSS 9.3 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73922 — CVSS 9.1 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73924 — CVSS 9.1 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73917 — CVSS 9.1 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73916 — CVSS 9.1 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73865 — CVSS 9.1 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73866 — CVSS 9.1 (critical): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73939 — CVSS 8.6 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71155 — CVSS 8.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73929 — CVSS 8.3 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73931 — CVSS 8.3 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73925 — CVSS 8.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73937 — CVSS 8.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71159 — CVSS 8.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2022-21404 — CVSS 8.1 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions that are affected are…
CVE-2026-71110 — CVSS 8.1 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-83439 — CVSS 8.1 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). Supported versions…
CVE-2026-87289 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are…
CVE-2021-37136 — CVSS 7.5 (high): The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the…
CVE-2026-70908 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71153 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71158 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71160 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73878 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73879 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73882 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73883 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73884 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73887 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73890 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73902 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73903 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73907 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73908 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73915 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73927 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73934 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73935 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73936 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73938 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-83276 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affected…
CVE-2026-83280 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affected…
CVE-2026-83281 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are…
CVE-2026-83330 — CVSS 7.5 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are…
CVE-2026-60915 — CVSS 7.4 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73933 — CVSS 7.3 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73891 — CVSS 7.3 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73894 — CVSS 7.3 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73918 — CVSS 7.3 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73886 — CVSS 7.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73885 — CVSS 7.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73928 — CVSS 7.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73876 — CVSS 7.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73875 — CVSS 7.2 (high): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71029 — CVSS 6.8 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73904 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73896 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73897 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73893 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73867 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2021-43797 — CVSS 6.5 (medium): Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers…
CVE-2026-83460 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affected are 4.0.0-4.5.4…
CVE-2026-73892 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73914 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71162 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73868 — CVSS 6.5 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73870 — CVSS 6.1 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73898 — CVSS 6.1 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71154 — CVSS 6.1 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73869 — CVSS 6.1 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-70923 — CVSS 6.1 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-70716 — CVSS 5.9 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2021-21409 — CVSS 5.9 (medium): Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance…
CVE-2026-73909 — CVSS 5.9 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73874 — CVSS 5.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73911 — CVSS 5.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71165 — CVSS 5.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73913 — CVSS 5.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73919 — CVSS 5.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-83488 — CVSS 5.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versions that are…
CVE-2026-73881 — CVSS 5.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71156 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71157 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-70727 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-71161 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-83480 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are…
CVE-2026-73910 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73871 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73872 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73888 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73932 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73900 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73899 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73895 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-83458 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4…
CVE-2026-73889 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73906 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-83459 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versions that are affected…
CVE-2026-73877 — CVSS 5.3 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73901 — CVSS 4.8 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2021-29425 — CVSS 4.8 (medium): In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or…
CVE-2026-73880 — CVSS 4.4 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73873 — CVSS 4.2 (medium): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-73923 — CVSS 3.7 (low): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…
CVE-2026-60853 — CVSS 3.7 (low): Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected…