CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,845 vulnerabilities with CWE-306
CVE-2026-60489
HIGH
JD Edwards EnterpriseOne CRM Foundation 9.2 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60463
CRITICAL
Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP
CVSS 9.8
CVE-2026-60462
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60461
CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60460
CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60458
CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60450
HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.1
CVE-2026-60446
CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via T3/IIOP
CVSS 9.8
CVE-2026-60442
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60441
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60435
CRITICAL
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 9.8
CVE-2026-60424
CRITICAL
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via LDAP
CVSS 9.0
CVE-2026-60417
HIGH
Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Takeover via LDAP
CVSS 8.1
CVE-2026-60398
HIGH
Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60396
HIGH
Oracle GoldenGate 21.3-21.21 and 23.4-23.26.1 - Authenticated Remote Code Execution via Distribution Server Executable
CVSS 7.2
CVE-2026-60389
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 10.0
CVE-2026-60388
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0/14.1.2.0.0 Unauthenticated RCE via T3/IIOP
CVSS 9.8
CVE-2026-60387
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60386
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 9.8
CVE-2026-60385
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60384
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60380
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 9.8
CVE-2026-60379
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0/14.1.2.0.0 Unauth RCE via SOAP Messaging Enabler
CVSS 10.0
CVE-2026-60378
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Messaging Enabler
CVSS 9.8
CVE-2026-60376
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
Details
Vulnerabilities
2,845
Exploit Likelihood
High