CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60606
CRITICAL
PeopleSoft Enterprise CC Common App Objects 9.2 - Unauthenticated Data Creation/Modification/Access via HTTP
CVSS 9.1
CVE-2026-60603
HIGH
PeopleSoft Enterprise CS Student Records 9.2.38 - Authenticated Remote Code Execution via Australian Features Component
CVSS 8.8
CVE-2026-60601
MEDIUM
PeopleSoft Enterprise FIN Common Objects 9.2 - Authenticated Data Modification via Security Component
CVSS 4.4
CVE-2026-60599
HIGH
PeopleSoft Enterprise CS Student Records 9.2.38 - Authenticated Data Manipulation via Research Tracking
CVSS 8.1
CVE-2026-60598
HIGH
PeopleSoft Enterprise CS Student Records 9.2.38 - Authenticated Remote Takeover via Research Tracking Component
CVSS 7.5
CVE-2026-60597
HIGH
PeopleSoft Enterprise FIN Cash Mgmt 9.2 - Unauthenticated Critical Data Creation/Modification/Deletion/Access via HTTP
CVSS 8.7
CVE-2026-60594
HIGH
PeopleSoft Enterprise CS Campus Community 9.2.38 - Authenticated RCE via Integration Component
CVSS 8.8
CVE-2026-60593
HIGH
PeopleSoft Enterprise FIN Staffing Front Office 9.2 - Unauthenticated Unauthorized Data Creation and Deletion via HTTP
CVSS 7.5
CVE-2026-60588
MEDIUM
Oracle Enterprise Asset Mgmt 12.2.3-12.2.15: Authenticated Data Modification & Info Disclosure via Work Definition
CVSS 5.4
CVE-2026-60587
MEDIUM
Oracle Project Foundation < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60585
MEDIUM
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Auth RCE via Replication Component
CVSS 6.6
CVE-2026-60584
HIGH
Oracle Transportation Management - Denial of Service
CVSS 7.6
CVE-2026-60583
HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60582
HIGH
Oracle Enterprise Command Center Framework - Denial of Service
CVSS 8.3
CVE-2026-60581
HIGH
Oracle Enterprise Command Center Framework V16 - Unauthenticated Remote Code Execution via Physical Network Access
CVSS 7.5
CVE-2026-60579
HIGH
Oracle Enterprise Command Center Framework V16 - Unauth Data Modification & Info Disclosure via Physical Access
CVSS 8.0
CVE-2026-60578
HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60577
HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60576
HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Remote Code Execution via HTTP
CVSS 7.2
CVE-2026-60575
MEDIUM
Oracle Workflow < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60573
MEDIUM
Oracle Partner Management < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60572
MEDIUM
Oracle E-Business Suite Integrated Soa Gateway < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60571
MEDIUM
Oracle Sdp Number Portability < 12.2.15 - Denial of Service
CVSS 5.4
CVE-2026-60570
HIGH
Oracle GoldenGate 23.4-23.26.1 - Authenticated Remote Code Execution via Libraries Component
CVSS 7.8
CVE-2026-60565
CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
Details
Vulnerabilities
6,232