Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-13915EPSS 9%
IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acce…
Api Connect
after 10.0.8.5
CRITICAL 9.8
CVE-2025-36251
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due …
Vios
Mitigation only
CRITICAL 9.8
CVE-2025-36250
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute a…
Vios
Mitigation only
CRITICAL 9.1
CVE-2025-36236
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse …
Vios
Mitigation only
CRITICAL 9.1
CVE-2025-12531
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. …
Infosphere Information Server
after 11.7.1.6
CRITICAL 9.8
CVE-2025-3356
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …
Tivoli Monitoring
Mitigation only
CRITICAL 9.8
CVE-2025-36386
IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain …
Maximo Application Suite
after 9.1.4
CRITICAL 9.8
CVE-2025-36087
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain confi…
Security Verify Access
after 10.0.9
CRITICAL 9.3
CVE-2025-36356
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authen…
Security Verify Access
10.0.9.0 / 11.0.1.0+
CRITICAL 9.8
CVE-2023-49886
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserializa…
Transformation Extender Advanced
Mitigation only
CRITICAL 9.8
CVE-2025-36222
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default confi…
Storage Fusion
2.11.0+
CRITICAL 9.8
CVE-2025-0165
IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker …
Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data
5.2.0.1+
CRITICAL 9.3
CVE-2025-2697
IBM Cognos Command Center 10.2.4.1 and 10.2.5
could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…
Cognos Command Center
Mitigation only
CRITICAL 9.1
CVE-2025-36157
IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to upda…
Jazz Foundation
Patch available
CRITICAL 9.8
CVE-2025-27909
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as t…
Concert
2.0.0+
CRITICAL 9.8
CVE-2025-3320
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…
Tivoli Monitoring
Mitigation only
CRITICAL 9.8
CVE-2025-3354
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…
Tivoli Monitoring
Mitigation only
CRITICAL 9.8
CVE-2024-39752
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore …
Analytics Content Hub
2.4+
CRITICAL 9.8
CVE-2024-38327
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map wh…
Analytics Content Hub
2.4+
CRITICAL 9.8
CVE-2025-36038EPSS 9%
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence …
Websphere Application Server
8.5.5.28 / 9.0.5.25+
CRITICAL 9.8
CVE-2025-3319
IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result …
Spectrum Protect Server
after 8.1.26
CRITICAL 9.1
CVE-2025-33117
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a mal…
Qradar Security Information And Event Manager
Mitigation only
CRITICAL 9.8
CVE-2025-36041
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ O…
Mq Operator
after 3.5.3
CRITICAL 9.8
CVE-2024-22330
IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to com…
Security Verify Governance
Mitigation only
CRITICAL 9.8
CVE-2025-3357
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of a…
Tivoli Monitoring
Mitigation only
CRITICAL 9.8
CVE-2025-2947
IBM i 7.6
contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command …
I
Mitigation only
CRITICAL 10.0
CVE-2024-56346
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
Aix
Mitigation only
CRITICAL 9.6
CVE-2024-56347
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process c…
Aix
Mitigation only
CRITICAL 9.8
CVE-2025-2000
A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma…
Qiskit
1.4.2+
CRITICAL 9.8
CVE-2025-0160
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…
Storage Virtualize
8.5.0.14 / 8.6.0.6+