CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,504 vulnerabilities with CWE-200
CVE-2026-61240 HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Unauthenticated Data Access/Modification via Physical Access
CVSS 8.2
CVE-2026-61233 CRITICAL
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61216 MEDIUM
Oracle Payroll < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61214 LOW
Oracle Hrms (uk) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 2.2
CVE-2026-61185 HIGH
Oracle Agile PLM for Process 6.2.4: Unauthenticated Unauthorized Data Access via Network
CVSS 7.4
CVE-2026-61175 CRITICAL
Oracle Product Lifecycle Analytics - Denial of Service
CVSS 9.3
CVE-2026-61165 HIGH
Oracle Commerce Guided Search Platform Services - Denial of Service
CVSS 7.1
CVE-2026-61159 HIGH
Oracle Commerce Guided Search / Experience Manager 11.4.0 - Unauthenticated Sensitive Data Exposure via HTTP
CVSS 7.5
CVE-2026-61133 HIGH
Oracle Commerce Platform 11.4.0 - Unauthenticated Unauthorized Data Access via LDAP
CVSS 7.5
CVE-2026-61125 HIGH
Oracle Configure to Order 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via Supply to Order Workbench
CVSS 7.7
CVE-2026-61123 MEDIUM
Oracle Hrms (us) < 12.2.15 - Denial of Service
CVSS 4.2
CVE-2026-61117 MEDIUM
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Data Access via Internal Operations Component
CVSS 6.3
CVE-2026-61116 HIGH
Oracle Application Object Library 12.2.3-12.2.15 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61112 MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via Product Diagnostic Tools
CVSS 6.5
CVE-2026-61104 LOW
PeopleSoft Enterprise CS Student Records 9.2.38 - Unauthenticated Information Disclosure via Research Tracking Component
CVSS 3.7
CVE-2026-61103 MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Data Access/Modification via Network
CVSS 5.9
CVE-2026-61082 MEDIUM
MySQL Connectors 9.7.0-9.7.1 - Unauthenticated Unauthorized Data Access via Connector/J
CVSS 6.5
CVE-2026-61081 LOW
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Authenticated Info Disclosure via Performance Schema
CVSS 2.7
CVE-2026-61050 MEDIUM
Oracle Production Scheduling 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP
CVSS 5.3
CVE-2026-61015 LOW
Oracle Time and Labor 12.2.3-12.2.15 - Unauthenticated Information Disclosure via HTTP
CVSS 3.7
CVE-2026-61014 HIGH
Oracle Inventory Management 12.2.3-12.2.15 - Authenticated Data Access via HTTP Request
CVSS 7.7
CVE-2026-60950 LOW
Oracle HRMS (Ireland) 12.2.3-12.2.15 - Authenticated Information Disclosure via HTTP
CVSS 2.2
CVE-2026-60939 LOW
Oracle Project Contracts 12.2.3-12.2.15 - Authenticated Information Disclosure via HTTP
CVSS 3.1
CVE-2026-60930 LOW
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Information Disclosure via HTTP
CVSS 3.1
CVE-2026-60923 HIGH
Oracle Capacity 12.2.3-12.2.15 - Authenticated Unauthorized Critical Data Access via HTTP
CVSS 7.7
Details
Vulnerabilities 10,504
Exploit Likelihood High