Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-4336
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute for…
Robotic Process Automation With Automation Anywhere
11.0.0.5+
CRITICAL 9.8
CVE-2019-4279EPSS 80%
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence …
Websphere Application Server
after 9.0.0.11
CRITICAL 10.0
CVE-2019-4202
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitra…
Api Connect
after 5.0.8.6
CRITICAL 9.8
CVE-2019-4012
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL…
Bigfix Webui Profile Management
Mitigation only
CRITICAL 9.8
CVE-2019-4203
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially …
Api Connect
after 5.0.8.6
CRITICAL 9.1
CVE-2019-4178
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request t…
Cognos Analytics
after 11.0.13.0
CRITICAL 9.9
CVE-2019-4013EPSS 13%
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…
Bigfix Platform
after 9.5.11
CRITICAL 9.8
CVE-2018-1994
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which …
Infosphere Information Server On Cloud
Patch available
CRITICAL 9.8
CVE-2019-4155
IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (…
Api Connect
after 2018.4.1.3
CRITICAL 9.8
CVE-2019-4032
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send speciall…
Financial Transaction Manager
after 3.1.0.3
CRITICAL 9.8
CVE-2018-1944
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or crypto…
Security Identity Governance And Intelligence
after 5.2.4.1
CRITICAL 9.8
CVE-2019-4059
IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and …
Rational Clearcase
9.0.1.5+
CRITICAL 9.1
CVE-2018-1727
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A…
Infosphere Information Server
Mitigation only
CRITICAL 9.8
CVE-2019-4008
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to …
Api Connect
after 2018.4.1.1
CRITICAL 9.9
CVE-2018-1969
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the…
Security Identity Manager
after 6.0.0.20
CRITICAL 9.8
CVE-2018-1784
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
Api Connect
after 5.0.8.4
CRITICAL 9.8
CVE-2018-1818
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…
Security Guardium
after 10.5
CRITICAL 9.1
CVE-2018-1821EPSS 13%
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat…
Operational Decision Manager
8.6.0.3 / 8.7.1.2+
CRITICAL 9.8
CVE-2018-1904
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client …
Websphere Application Server
after 9.0.0.9
CRITICAL 9.8
CVE-2018-1851
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper des…
Websphere Application Server
18.0.0.3+
CRITICAL 9.8
CVE-2018-1822
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability t…
Flashsystem 900 Firmware
Patch available
CRITICAL 9.8
CVE-2018-18202
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support pass…
Qlogic 4 Gb Fibre Channel Expansion Card Firmware
No fix yet
CRITICAL 9.3
CVE-2018-1742
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its ow…
Security Key Lifecycle Manager
after 3.0.0.1
CRITICAL 9.9
CVE-2018-1789
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery atta…
Api Connect
after 2018.3.4
CRITICAL 9.8
CVE-2018-1567
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a…
Websphere Application Server
after 9.0.0.9
CRITICAL 10.0
CVE-2018-1722EPSS 9%
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are r…
Security Access Manager
Mitigation only
CRITICAL 9.9
CVE-2018-1712
IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input p…
Api Connect
after 5.0.8.3
CRITICAL 9.8
CVE-2013-3000
SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via u…
Infosphere Data Replication Dashboard
Mitigation only
CRITICAL 9.8
CVE-2018-1457
An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM …
Engineering Requirements Management Doors
after 9.7.2
CRITICAL 9.8
CVE-2017-1601
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by def…
Security Guardium Database Activity Monitor
Patch available