When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,568 vulnerabilities with CWE-287
CVE-2026-61180
HIGH
Oracle Agile PLM for Process 6.2.4: Auth RCE via Product Quality Management Component
CVSS 8.8
CVE-2026-61179
HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Remote Takeover via PQM Component
CVSS 8.8
CVE-2026-61178
CRITICAL
Oracle Agile PLM for Process 6.2.4 - Unauth RCE via Installation Component
CVSS 9.8
CVE-2026-61168
HIGH
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via Security Component
CVSS 8.8
CVE-2026-61163
HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Unauthenticated Remote Code Execution via Forge Component
CVSS 8.1
CVE-2026-61154
CRITICAL
Oracle Commerce Guided Search Platform Services 11.4.0 - Unauthenticated Remote Code Execution via Forge Component
CVSS 9.8
CVE-2026-61149
HIGH
Oracle Commerce Guided Search and Experience Manager 11.4.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61137
HIGH
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via Dynamo Application Framework
CVSS 8.1
CVE-2026-61131
CRITICAL
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via Dynamo Application Framework
CVSS 9.8
CVE-2026-61129
CRITICAL
Oracle Commerce Platform 11.4.0 - Unauthenticated Remote Code Execution via ATG Portals
CVSS 9.8
CVE-2026-61127
HIGH
Oracle Communications Service Catalog/Design 8.0.0.7.0-8.3.0.2.0 Auth RCE via Solution Designer
CVSS 8.8
CVE-2026-61121
HIGH
Oracle HRMS (UK) 12.2.8-12.2.15 - Authenticated Remote Code Execution via UK Payroll Component
CVSS 8.8
CVE-2026-61110
HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Authenticated Remote Code Execution via ADPatch Component
CVSS 8.8
CVE-2026-61099
HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 8.8
CVE-2026-61098
HIGH
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-61074
HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via eProcurement Component
CVSS 8.1
CVE-2026-61067
HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Authenticated Remote Takeover via Physical Network Access
CVSS 8.0
CVE-2026-61065
CRITICAL
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 9.8
CVE-2026-61049
HIGH
Oracle Production Scheduling 12.2.3-12.2.15 Unauth RCE via Physical Network Access & User Interaction
CVSS 7.1
CVE-2026-61010
HIGH
Oracle Process Manufacturing Systems 12.2.3-12.2.15 - Authenticated Remote System Takeover via HTTP
CVSS 8.8
CVE-2026-60989
HIGH
Oracle Advanced Collections 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60952
HIGH
Oracle Transportation Execution 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60932
HIGH
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60931
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60927
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
Details
Vulnerabilities
4,568
Exploit Likelihood
High