When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,567 vulnerabilities with CWE-287
CVE-2026-10697
HIGH
MFA Bypass in MOVEit Transfer
CVSS 7.5
CVE-2026-15611
CRITICAL
Logto - Unverified Email-Based SSO Account Linking
CVSS 9.1
CVE-2026-15348
MEDIUM
Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter
CVSS 6.3
CVE-2026-14291
HIGH
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
CVSS 7.5
CVE-2026-60367
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-62144
CRITICAL
Checkpoint Quantum Security Management - Authentication Bypass
CVSS 9.1
CVE-2026-16232
CRITICAL
KEV
Authentication Bypass in the SmartConsole Login Process Using an Application Token
CVSS 9.1
CVE-2026-62547
HIGH
Oracle Workflow 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via SMTP
CVSS 8.1
CVE-2026-62534
HIGH
Oracle Applications Framework 12.2.11-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 8.8
CVE-2026-62498
HIGH
Oracle Flow Manufacturing 12.2.7-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62496
HIGH
Oracle Yard Management 12.2.6-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62493
HIGH
Oracle Purchasing 12.2.11-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-62478
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62476
HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62464
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-62447
HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-61322
HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61320
HIGH
Oracle Payables 12.2.8-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61311
HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61243
HIGH
PeopleSoft Enterprise FIN Common Objects Argentina 9.1 - Authenticated Remote Code Execution via Staffing Component
CVSS 8.8
CVE-2026-61233
CRITICAL
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via Integration Component
CVSS 9.8
CVE-2026-61225
HIGH
Oracle Communications Converged Application Server 8.2 and 8.3 - Unauthenticated Remote Takeover via TCP/IP
CVSS 8.1
CVE-2026-61188
HIGH
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Authenticated Remote Takeover via Installation Component
CVSS 7.5
CVE-2026-61183
CRITICAL
Oracle Agile Product Lifecycle Management for Process 6.2.4 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61180
HIGH
Oracle Agile PLM for Process 6.2.4: Auth RCE via Product Quality Management Component
CVSS 8.8
Details
Vulnerabilities
4,567
Exploit Likelihood
High