<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Oracle APEX</title>
  <link>https://cvedaily.com/pages/tags/oracle-apex.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/oracle-apex.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Oracle APEX</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:01 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-21931 – Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21931</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21931</strong></p>
  <p>Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App).  Supported versions that are affected are 23.2.0, 23.2.1, 24.1.0, 24.2.0 and  24.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle APEX Sample Applications.  Successful attacks require human interaction from a person o…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7138 – SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7138</guid>
    <pubDate>Wed, 07 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7138</strong></p>
  <p>SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter.  NOTE: it is likely that this issue is subsumed by CVE-2006-5351, but due to lack of details from Or…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7138">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
