CWE-200
High likelihoodExposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
10,504 vulnerabilities with CWE-200
CVE-2026-60922
LOW
Oracle iSupplier Portal 12.2.3-12.2.15 - Authenticated Information Disclosure via HTTP
CVSS 3.1
CVE-2026-60919
LOW
Oracle iSupplier Portal 12.2.3-12.2.15 - Unauthenticated Information Disclosure via HTTP
CVSS 3.7
CVE-2026-60913
LOW
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Information Disclosure via Internal Operations Component
CVSS 1.9
CVE-2026-60899
MEDIUM
Oracle HCM Config Workbench 12.2.3-12.2.15: Authenticated Unauthorized Data Access via Rapid Implementation
CVSS 6.5
CVE-2026-60896
LOW
Oracle Work IN Process < 12.2.15 - Denial of Service
CVSS 3.6
CVE-2026-60891
LOW
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Information Disclosure via Local Access
CVSS 1.9
CVE-2026-60888
MEDIUM
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP
CVSS 5.3
CVE-2026-60886
HIGH
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP with User Interaction
CVSS 7.6
CVE-2026-60864
MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 6.4
CVE-2026-60844
HIGH
Oracle Customer Support 12.2.3-12.2.15 Auth Bypass via Update Service Request Leads to Data Modification/Access
CVSS 8.1
CVE-2026-60835
MEDIUM
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP
CVSS 6.5
CVE-2026-60812
MEDIUM
Oracle Supply Chain Trading Connector 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via Collaboration History
CVSS 6.5
CVE-2026-60705
HIGH
Oracle Corporation Siebel Crm Cloud Applications < 26.5 - Denial of Service
CVSS 7.0
CVE-2026-60687
MEDIUM
Oracle U.S. Federal Financials 12.2.3-12.2.15 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 6.8
CVE-2026-60673
MEDIUM
Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 - Unauthorized Data Access via XML Services
CVSS 6.5
CVE-2026-60647
HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.1
CVE-2026-60620
MEDIUM
Oracle Corporation JD Edwards EnterpriseOne Configurator - Denial of Service
CVSS 6.4
CVE-2026-60611
MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Information Disclosure via HTTP
CVSS 5.3
CVE-2026-60610
MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 5.9
CVE-2026-60609
MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Authenticated Unauthorized Data Access via Communication Component
CVSS 6.5
CVE-2026-60607
MEDIUM
PeopleSoft Enterprise CS Financial Aid 9.2.38 - Authenticated Unauthorized Data Access via FM Need Analysis Calculator
CVSS 5.5
CVE-2026-60558
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60557
MEDIUM
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP with User Interaction
CVSS 6.5
CVE-2026-60556
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60555
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
Details
Vulnerabilities
10,504
Exploit Likelihood
High