Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-40609
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe dese…
Sdk
7.1.5.19 / 8.0.8.5+
CRITICAL 9.8
CVE-2023-30990
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-For…
I
Patch available
CRITICAL 9.8
CVE-2023-27866
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th…
Informix Jdbc Driver
4.50.10+
CRITICAL 9.6
CVE-2023-23482
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading …
Sterling Partner Engagement Manager
6.1.2.8 / 6.2.0.6+
CRITICAL 9.8
CVE-2023-32336
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X…
Infosphere Information Server
Mitigation only
CRITICAL 9.8
CVE-2022-47984
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…
Infosphere Information Server
Patch available
CRITICAL 9.8
CVE-2023-27284
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl…
Aspera Cargo
4.2.5+
CRITICAL 9.8
CVE-2023-27286
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overfl…
Aspera Cargo
4.2.5+
CRITICAL 9.8
CVE-2023-25684
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially cr…
Security Key Lifecycle Manager
Patch available
CRITICAL 9.1
CVE-2023-27290EPSS 9%
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require…
Observability With Instana
after 241-2
CRITICAL 9.8
CVE-2022-47986 KEVEPSS 100%
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa…
Aspera Faspex
after 4.4.1
CRITICAL 9.8
CVE-2022-41731
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement…
Watson Knowledge Catalog On Cloud Pak For Data
Mitigation only
CRITICAL 9.8
CVE-2023-23477
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft…
Websphere Application Server
Mitigation only
CRITICAL 9.1
CVE-2022-38389
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
Tivoli Workload Scheduler
Mitigation only
CRITICAL 9.1
CVE-2022-22486
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
Tivoli Workload Scheduler
Mitigation only
CRITICAL 9.8
CVE-2022-40615
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statem…
Sterling Partner Engagement Manager
Patch available
CRITICAL 9.8
CVE-2022-22338
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted S…
Sterling B2b Integrator
6.0.3.7 / 6.1.0.6+
CRITICAL 9.1
CVE-2022-38708
IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from us…
Cognos Analytics
after 11.2.3
CRITICAL 9.8
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …
Infosphere Information Server
Patch available
CRITICAL 9.8
CVE-2022-34331
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VE…
Powervm Hypervisor
Mitigation only
CRITICAL 9.1
CVE-2022-40747
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…
Infosphere Information Server
Patch available
CRITICAL 9.8
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system,…
Infosphere Information Server
Patch available
CRITICAL 9.1
CVE-2022-22489
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A rem…
Mq
Patch available
CRITICAL 9.8
CVE-2022-22455
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the m…
Security Verify Governance
Patch available
CRITICAL 9.8
CVE-2021-39085
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injec…
Sterling B2b Integrator
6.0.3.6 / 6.1.0.5+
CRITICAL 9.8
CVE-2022-35280
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier …
Robotic Process Automation For Cloud Pak
Mitigation only
CRITICAL 9.1
CVE-2022-31775
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML Exte…
Datapower Gateway
10.0.1.8 / 10.5.0.1+
CRITICAL 9.1
CVE-2022-35643
IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.
Powervm Virtual I\/o Server
Patch available
CRITICAL 9.8
CVE-2020-4150
IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…
Security Siteprotector System
Mitigation only
CRITICAL 9.8
CVE-2022-22487
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the st…
Spectrum Protect Server
after 8.1.14