When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,570 vulnerabilities with CWE-287
CVE-2026-11717
CRITICAL
Mcp Toolbox For Databases (googleapis/mcp-toolbox) < 1.3.0 - Improper Authentication
CVE-2026-48991
MEDIUM
XianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and state validation
CVSS 5.5
CVE-2026-49502
HIGH
Dell PowerFlex - Improper Authentication
CVSS 7.4
CVE-2026-48117
MEDIUM
DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
CVSS 6.8
CVE-2026-32804
HIGH
Dell PowerFlex - Improper Authentication
CVSS 8.1
CVE-2026-48929
HIGH
Rocket.Chat - Improper Authentication
CVSS 7.5
CVE-2026-46973
HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46972
HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46962
HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46961
HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46952
HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46951
HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46942
HIGH
Oracle Process Manufacturing Process Planning 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46940
HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46937
HIGH
Oracle iSetup 12.2.3-12.2.15 - Authenticated Remote Code Execution in General Ledger Update Transform
CVSS 8.8
CVE-2026-46929
HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution in Cost Planning
CVSS 8.8
CVE-2026-46928
HIGH
Oracle Spares Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTPS
CVSS 8.8
CVE-2026-46921
HIGH
Siebel CRM Cloud Applications 17.0-26.5 - Authenticated Remote Code Execution in Siebel Cloud Manager
CVSS 8.8
CVE-2026-46919
CRITICAL
Oracle Siebel CRM Cloud Applications 17.0-26.5 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46916
HIGH
Oracle Process Manufacturing 12.2.3-12.2.15 - Authenticated RCE in Quality Management
CVSS 8.8
CVE-2026-46903
HIGH
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46890
CRITICAL
Oracle Siebel Apps - Marketing 17.0-26.5 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2026-46859
CRITICAL
Oracle Agile PLM 9.3.6 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35261
MEDIUM
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Data Manipulation and Information Disclosure via HTTP
CVSS 6.5
CVE-2026-48780
HIGH
Forem vulnerable to bypass of email address domain restrictions
CVSS 8.2
Details
Vulnerabilities
4,570
Exploit Likelihood
High