CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,845 vulnerabilities with CWE-306
CVE-2026-60375
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3 or IIOP Protocol
CVSS 9.8
CVE-2026-60374
CRITICAL
Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60365
CRITICAL
Oracle Weblogic Server Proxy Plug-in 15.1.1.0.0 - Unauthenticated Arbitrary Data Creation, Deletion and Access via HTTP
CVSS 10.0
CVE-2026-60362
CRITICAL
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via LDAP
CVSS 9.8
CVE-2026-60361
CRITICAL
Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0 - Authenticated Remote Code Execution via LDAP with Scope Change
CVSS 9.9
CVE-2026-60360
CRITICAL
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via LDAP
CVSS 10.0
CVE-2026-60359
HIGH
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60356
HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via Authentication Engine
CVSS 8.6
CVE-2026-60355
CRITICAL
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 9.8
CVE-2026-60335
HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Content Server
CVSS 7.2
CVE-2026-60334
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60329
CRITICAL
Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Code Execution via T3/IIOP Protocol
CVSS 9.8
CVE-2026-60322
MEDIUM
Oracle Apps Manager 12.2.3-12.2.15: Unauthenticated Data Mod & Info Disclosure via Diagnostics
CVSS 6.5
CVE-2026-60313
HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Authenticated Remote Code Execution via RMI
CVSS 8.8
CVE-2026-60312
HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1-2.0.0/15.1.1.0.0 Unauth RCE via T3/IIOP
CVSS 8.1
CVE-2026-60308
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60306
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60302
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60300
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60299
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60298
CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60297
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60296
CRITICAL
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via TCP
CVSS 9.8
CVE-2026-60294
CRITICAL
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Unauthenticated Remote Code Execution via SOAP
CVSS 9.8
CVE-2026-60292
CRITICAL
Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
Details
Vulnerabilities
2,845
Exploit Likelihood
High