CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,847 vulnerabilities with CWE-306
CVE-2026-46813
CRITICAL
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46807
CRITICAL
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via T3/IIOP
CVSS 9.8
CVE-2026-46803
CRITICAL
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-46801
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46800
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-46799
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46798
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-46789
CRITICAL
Oracle WebCenter Content 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.6
CVE-2026-46783
CRITICAL
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-46781
CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via RMI
CVSS 10.0
CVE-2026-46780
HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46778
CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via RMI
CVSS 10.0
CVE-2026-35304
CRITICAL
Oracle Coherence 12.2.1.4.0 14.1.1.0.0 14.1.2.0.0 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTPS
CVSS 9.8
CVE-2026-35303
HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Remote Code Execution via Console
CVSS 8.8
CVE-2026-35301
CRITICAL
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Remote Code Execution via Console
CVSS 10.0
CVE-2026-35299
HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Remote Code Execution via Console
CVSS 8.8
CVE-2026-35296
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35295
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution
CVSS 7.5
CVE-2026-35293
CRITICAL
Oracle WebCenter Sites 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35292
CRITICAL
Oracle WebLogic Server 14.1.2.0.0 and 15.1.1.0.0 - Unauthenticated Remote Code Execution via Console
CVSS 10.0
CVE-2026-35289
HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution via Deployment Package
CVSS 8.1
CVE-2026-35286
CRITICAL
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-35279
HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution in Performance Monitor
CVSS 8.1
CVE-2026-35278
CRITICAL
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution in Performance Monitor
CVSS 9.8
CVE-2026-35276
HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
Details
Vulnerabilities
2,847
Exploit Likelihood
High