CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,842 vulnerabilities with CWE-306
CVE-2026-56163
CRITICAL
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-66139
MEDIUM
Openstack Zaqar - Missing Authentication for Critical Function
CVSS 4.8
CVE-2026-63765
HIGH
Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
CVSS 8.2
CVE-2026-47769
MEDIUM
APIFold Vulnerable to Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-64812
CRITICAL
Jetbrains IntelliJ Idea < 2026.2 - Missing Authentication for Critical Function
CVSS 10.0
CVE-2026-61246
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60439
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60373
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60372
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via Thirdparty Jars
CVSS 9.8
CVE-2026-60367
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60366
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-65012
MEDIUM
InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder
CVSS 5.3
CVE-2026-65014
MEDIUM
n8n before 2.28.0 Authentication Bypass via test-webhook
CVSS 5.3
CVE-2026-65319
HIGH
Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text
CVSS 7.5
CVE-2026-62547
HIGH
Oracle Workflow 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via SMTP
CVSS 8.1
CVE-2026-62534
HIGH
Oracle Applications Framework 12.2.11-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 8.8
CVE-2026-62498
HIGH
Oracle Flow Manufacturing 12.2.7-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62496
HIGH
Oracle Yard Management 12.2.6-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62493
HIGH
Oracle Purchasing 12.2.11-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-62478
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62476
HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62474
MEDIUM
Oracle Lease And Finance Management < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62464
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-62447
HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-61322
HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
Details
Vulnerabilities
2,842
Exploit Likelihood
High