CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,227 vulnerabilities with CWE-284
CVE-2026-61252
MEDIUM
Oracle Hrms (Hong Kong) < 12.2.15 - Improper Access Control
CVSS 5.4
CVE-2026-61250
MEDIUM
Oracle Payroll < 12.2.15 - Improper Access Control
CVSS 6.5
CVE-2026-61245
CRITICAL
PeopleSoft Enterprise FIN Manufacturing Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61244
CRITICAL
PeopleSoft Enterprise FIN Manufacturing Argentina 9.1 - Unauthenticated Data Creation/Modification/Access via HTTP
CVSS 9.1
CVE-2026-61243
HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 8.8
CVE-2026-61242
CRITICAL
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 9.9
CVE-2026-61240
HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Unauthenticated Data Access/Modification via Physical Access
CVSS 8.2
CVE-2026-61239
CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Common Objects Argentina - Denial of Service
CVSS 9.9
CVE-2026-61238
CRITICAL
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Unauthenticated Data Creation/Modification/Access via HTTP
CVSS 9.1
CVE-2026-61237
CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Common Objects Argentina - Denial of Service
CVSS 9.9
CVE-2026-61236
HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61235
CRITICAL
PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2 - Authenticated Remote System Takeover via HTTP
CVSS 9.1
CVE-2026-61234
HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Data Creation, Deletion, and Access via HTTP
CVSS 7.4
CVE-2026-61233
CRITICAL
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61232
HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61226
HIGH
Oracle Communications Converged Application Server 8.3 - Authenticated Remote Takeover via RTP Proxy
CVSS 7.5
CVE-2026-61224
HIGH
Oracle Communications Converged Application Server 8.3 - Authenticated Remote Takeover via TLS
CVSS 8.0
CVE-2026-61223
CRITICAL
Oracle Communications Converged Application Server 8.2-8.3 - Unauthenticated Remote Code Execution via TCP/IP
CVSS 9.0
CVE-2026-61221
MEDIUM
Oracle Item Master < 12.2.15 - Improper Access Control
CVSS 5.4
CVE-2026-61220
MEDIUM
Oracle Banking Origination - Improper Access Control
CVSS 6.1
CVE-2026-61218
HIGH
Oracle E-Business Suite 12.2.3-12.2.15 SES: Authenticated Data Modification & Unauthorized Access via Search Engine
CVSS 8.1
CVE-2026-61217
MEDIUM
Oracle Security Service - Improper Access Control
CVSS 6.4
CVE-2026-61216
MEDIUM
Oracle Payroll < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61211
CRITICAL
Oracle Database Server 19.3-19.31 and 23.4.0-23.26.2 - Authenticated Remote Takeover via RDBMS DBMS_CLOUD Component
CVSS 9.9
CVE-2026-61210
HIGH
PeopleSoft Enterprise SCM Manufacturing 9.2 - Unauth HTTPS Data Creation, Modification, Deletion & Access
CVSS 7.4
Details
Vulnerabilities
6,227