CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,845 vulnerabilities with CWE-306
CVE-2026-60204
CRITICAL
Oracle WebLogic Server 12.2.1.4/14.1.1-2/15.1.1 Unauth RCE via T3/IIOP
CVSS 9.8
CVE-2026-60203
HIGH
Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60202
CRITICAL
Oracle WebLogic Server 12.2.1.4.0/14.1.1-2.0.0/15.1.1.0.0 - Unauth RCE via T3/IIOP
CVSS 9.8
CVE-2026-60201
HIGH
Oracle WebLogic Server 12.2.1.4/14.1.1-2/15.1.1 Unauth RCE via T3/IIOP
CVSS 8.1
CVE-2026-60200
CRITICAL
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Unauthenticated Remote Code Execution via SOAP
CVSS 9.8
CVE-2026-60199
CRITICAL
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60198
CRITICAL
Oracle WebLogic Server 12.2.1.4/14.1.1-2/15.1.1 Unauth RCE via T3/IIOP
CVSS 9.8
CVE-2026-60197
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60169
HIGH
Oracle Hospitality Simphony 19.8-19.10 Unauthenticated RCE via POS Component
CVSS 8.1
CVE-2026-60153
HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 Authenticated RCE via Console
CVSS 7.2
CVE-2026-47056
CRITICAL
Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via REST Service
CVSS 10.0
CVE-2026-47040
CRITICAL
Oracle Net Services - Denial of Service
CVSS 9.1
CVE-2026-47038
LOW
Oracle DB 19.3-19.31/21.3-21.22/23.4-23.26.2: Auth'd Data Manipulation via Oracle Net in RDBMS
CVSS 2.7
CVE-2026-47036
CRITICAL
Siebel CRM Development 17.0-26.3 - Unauthenticated Remote Code Execution via Siebel Approval Manager
CVSS 9.8
CVE-2026-47019
HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via Item Catalog
CVSS 8.1
CVE-2026-47004
HIGH
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Authenticated Remote Takeover via Self Update Framework
CVSS 8.8
CVE-2026-46999
HIGH
Oracle Enterprise Manager Base Platform - Denial of Service
CVSS 7.0
CVE-2026-46997
MEDIUM
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Authenticated Data Modification via Metadata Plugin
CVSS 6.5
CVE-2026-46992
HIGH
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Authenticated Remote Takeover via Enterprise Config Management
CVSS 8.8
CVE-2026-50759
HIGH
exo 1.0.69 - Unauthenticated Privilege Escalation via GET /state and DELETE /instance/{instance_id} Endpoints
CVSS 7.5
CVE-2026-47671
MEDIUM
Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
CVSS 5.4
CVE-2026-47396
CRITICAL
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
CVSS 9.8
CVE-2026-47393
CRITICAL
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVSS 9.8
CVE-2026-47391
CRITICAL
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
CVSS 9.8
CVE-2026-47122
MEDIUM
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
CVSS 4.2
Details
Vulnerabilities
2,845
Exploit Likelihood
High