CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,845 vulnerabilities with CWE-306
CVE-2026-60250
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60247
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60246
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60244
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60242
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60241
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60240
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60236
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60235
HIGH
Oracle Coherence - Denial of Service
CVSS 8.6
CVE-2026-60234
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60232
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60230
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60229
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60228
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60219
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60218
HIGH
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Authenticated Remote Code Execution via TCP
CVSS 8.8
CVE-2026-60217
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 10.0
CVE-2026-60216
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60215
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60212
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60210
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60209
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60207
HIGH
Oracle WebLogic Server 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60206
CRITICAL
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Authenticated Remote Code Execution via SAML
CVSS 9.9
CVE-2026-60205
CRITICAL
Oracle WebLogic Server 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Core Component
CVSS 9.8
Details
Vulnerabilities
2,845
Exploit Likelihood
High