Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-1475
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM…
Bigfix Platform
after 9.5.8
CRITICAL 9.1
CVE-2014-0931
Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java…
Rational Clearcase
after 8.0.1.3
CRITICAL 9.8
CVE-2014-6120
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.…
Rational Appscan Source
Mitigation only
CRITICAL 9.8
CVE-2018-1469
IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted H…
Api Connect
after 5.0.8.2
CRITICAL 9.8
CVE-2017-1789
IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 13…
Tivoli Monitoring
Mitigation only
CRITICAL 9.1
CVE-2018-1426
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC inst…
Db2
Mitigation only
CRITICAL 9.8
CVE-2018-1373
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force…
Security Guardium Big Data Intelligence
Patch available
CRITICAL 9.8
CVE-2018-1372
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier f…
Security Guardium Big Data Intelligence
Mitigation only
CRITICAL 9.1
CVE-2018-1383
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtai…
Aix
Mitigation only
CRITICAL 9.8
CVE-2011-4889
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43,…
Websphere Application Server
6.1.0.43 / 7.0.0.21+
CRITICAL 9.8
CVE-2012-2166
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded pas…
Xiv Storage System 2810 A14 Firmware
10.2.4.e-2 / 11.1.1+
CRITICAL 9.8
CVE-2017-1204
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain acces…
Tealeaf Customer Experience
Patch available
CRITICAL 9.8
CVE-2016-0332
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login atte…
Security Identity Manager Virtual Appliance
Patch available
CRITICAL 9.8
CVE-2017-1670
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, whi…
Security Key Lifecycle Manager
Patch available
CRITICAL 9.8
CVE-2017-1221
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for a…
Bigfix Platform
Mitigation only
CRITICAL 9.8
CVE-2017-1710
A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-…
Storwize V7000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-8937
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo…
Tivoli Storage Manager
Patch available
CRITICAL 9.8
CVE-2017-1376
A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges. IBM X-Force ID: 126873.
Operations Analytics Predictive Insights
Mitigation only
CRITICAL 9.1
CVE-2017-1383
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…
Infosphere Information Server
Mitigation only
CRITICAL 9.8
CVE-2016-8964
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-F…
Bigfix Inventory
9.2.8+
CRITICAL 9.9
CVE-2017-1253
IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted re…
Security Guardium
Mitigation only
CRITICAL 9.8
CVE-2017-1175
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co…
Maximo Asset Management
Mitigation only
CRITICAL 9.8
CVE-2017-1269
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow …
Security Guardium
Mitigation only
CRITICAL 9.8
CVE-2017-1197
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account crede…
Bigfix Security Compliance Analytics
Mitigation only
CRITICAL 9.8
CVE-2016-6093
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromi…
Security Key Lifecycle Manager
Patch available
CRITICAL 9.8
CVE-2016-6087
IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange v…
Domino
Patch available
CRITICAL 9.8
CVE-2017-1196
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for atta…
Bigfix Security Compliance Analytics
Mitigation only
CRITICAL 9.8
CVE-2017-1092EPSS 72%
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM …
Informix Open Admin Tool
Patch available
CRITICAL 9.1
CVE-2016-6111
IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when pr…
Curam Social Program Management
Patch available
CRITICAL 9.1
CVE-2016-9706
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injec…
Integration Bus
Patch available