CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,844 vulnerabilities with CWE-306
CVE-2026-60596
LOW
PeopleSoft Enterprise FIN eSettlements 9.2 - Authenticated Information Disclosure via Local Access
CVSS 2.3
CVE-2026-60595
MEDIUM
PeopleSoft Enterprise FIN Pay/Bill Mgmt 9.2: Authenticated Unauthorized Data Access
CVSS 5.5
CVE-2026-60586
HIGH
MySQL Connectors 9.7.0-9.7.1 - Authenticated Unauthorized Data Access via Connector/J
CVSS 7.7
CVE-2026-60583
HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60580
HIGH
Oracle Enterprise Command Center Framework V16 - Unauthenticated Remote Code Execution via Physical Network Access
CVSS 8.8
CVE-2026-60574
MEDIUM
Oracle Content Manager < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60569
MEDIUM
MySQL Cluster 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 - Unauthenticated Unauthorized Data Access via NDB Operator
CVSS 5.1
CVE-2026-60557
MEDIUM
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP with User Interaction
CVSS 6.5
CVE-2026-60551
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60549
HIGH
Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via MFT Runtime Server
CVSS 8.8
CVE-2026-60545
HIGH
Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60544
HIGH
Oracle Soa Suite - Denial of Service
CVSS 8.2
CVE-2026-60543
HIGH
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via B2B Engine
CVSS 8.1
CVE-2026-60539
HIGH
Oracle SOA Suite 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution in Integration Business Insight
CVSS 8.8
CVE-2026-60538
CRITICAL
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Enterprise Scheduling System
CVSS 9.8
CVE-2026-60537
CRITICAL
Oracle Managed File Transfer 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 9.9
CVE-2026-60535
CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60531
CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-60499
HIGH
JD Edwards EnterpriseOne Solution Advisor 9.2 - Authenticated Remote Code Execution via Solution Advisor Component
CVSS 8.8
CVE-2026-60498
HIGH
JD Edwards EnterpriseOne Human Resources Management 9.2 - Authenticated Remote Takeover via JDENET
CVSS 7.5
CVE-2026-60497
HIGH
JD Edwards EnterpriseOne CRM Foundation 9.2 - Authenticated Remote Takeover via JDENET
CVSS 7.5
CVE-2026-60496
HIGH
JD Edwards EnterpriseOne Advanced Pricing - Procurement 9.2 - Authenticated Remote Code Execution via JDENET
CVSS 7.5
CVE-2026-60495
HIGH
Oracle JD Edwards EnterpriseOne Requirements Planning 9.2 - Authenticated Remote Code Execution via JDENET
CVSS 7.5
CVE-2026-60493
HIGH
JD Edwards EnterpriseOne Human Resources Management 9.2 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60489
HIGH
JD Edwards EnterpriseOne CRM Foundation 9.2 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
Details
Vulnerabilities
2,844
Exploit Likelihood
High