CWE-200
High likelihoodExposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
10,504 vulnerabilities with CWE-200
CVE-2026-60554
HIGH
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-60553
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 8.7
CVE-2026-60552
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-60551
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60550
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60548
HIGH
Oracle SOA Suite 12.2.1.4.0/14.1.2.0.0: Authenticated Critical Data Access via Integration Business Insight
CVSS 7.7
CVE-2026-60449
HIGH
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0 Unauthenticated Unauthorized Data Access
CVSS 7.1
CVE-2026-60440
HIGH
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Data Exposure via Messaging Enabler
CVSS 7.7
CVE-2026-60431
HIGH
Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via mod_proxy
CVSS 8.6
CVE-2026-60408
MEDIUM
TimesTen In-Memory Database 26.1.1.1.0 - Authenticated Information Disclosure via Kubernetes Operator
CVSS 4.3
CVE-2026-60405
LOW
TimesTen In-Memory Database 26.1.1.1.0 - Authenticated Information Disclosure via Kubernetes Operator
CVSS 3.8
CVE-2026-60395
MEDIUM
Oracle GoldenGate 19.1-19.30, 21.3-21.21, 23.4-23.26.1 Authenticated Info Disclosure via Admin Server
CVSS 4.3
CVE-2026-60394
MEDIUM
Oracle GoldenGate 21.3-21.21 and 23.4-23.26.1 - Unauthenticated Information Disclosure via Admin Server Executable
CVSS 5.3
CVE-2026-60354
LOW
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Information Disclosure via HTTP
CVSS 3.7
CVE-2026-60352
LOW
Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Information Disclosure via ADF Faces
CVSS 3.7
CVE-2026-60350
MEDIUM
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Unauthorized Data Access via ADF Faces
CVSS 6.5
CVE-2026-60349
MEDIUM
Oracle JDeveloper - Denial of Service
CVSS 5.9
CVE-2026-60339
LOW
Oracle Project Manufacturing V16 - Authenticated Information Disclosure via PJM Command Center
CVSS 3.1
CVE-2026-60318
LOW
Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Information Disclosure via Patchset Assistant
CVSS 3.3
CVE-2026-60315
HIGH
Oracle Corporation MySQL Server - Denial of Service
CVSS 8.2
CVE-2026-60307
MEDIUM
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Authenticated Information Disclosure via HTTP
CVSS 4.3
CVE-2026-60293
HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1-2.0.0/15.1.1.0.0 - Unauthenticated Data Access via WLS Web Services
CVSS 8.6
CVE-2026-60283
MEDIUM
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Information Disclosure via HTTP
CVSS 5.3
CVE-2026-60266
MEDIUM
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Sensitive Data Exposure via TLS
CVSS 5.9
CVE-2026-60264
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP/2
CVSS 9.8
Details
Vulnerabilities
10,504
Exploit Likelihood
High