Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-31767EPSS 5%
IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reque…
Cics Tx
11.1+
CRITICAL 9.8
CVE-2021-38945
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X…
Cognos Analytics
11.1.7+
CRITICAL 9.8
CVE-2022-22317
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a…
Curam Social Program Management
Patch available
CRITICAL 9.8
CVE-2022-22318
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate a…
Curam Social Program Management
Patch available
CRITICAL 9.8
CVE-2022-22485
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrat…
Spectrum Protect Operations Center
after 8.1.14.000
CRITICAL 9.8
CVE-2019-4575
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could…
Financial Transaction Manager
after 3.2.9
CRITICAL 9.8
CVE-2022-31768
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…
Infosphere Information Server
Patch available
CRITICAL 9.1
CVE-2020-4926
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection…
Elastic Storage System
5.1.3.0 / 6.1.3.0+
CRITICAL 9.8
CVE-2022-22413
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen…
Robotic Process Automation
Mitigation only
CRITICAL 9.8
CVE-2021-38969
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM…
Spectrum Virtualize
Mitigation only
CRITICAL 9.8
CVE-2021-38869
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 20834…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
CRITICAL 9.8
CVE-2003-5001
A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete…
Iss Blackice Pc Protection
Mitigation only
CRITICAL 9.1
CVE-2022-22374
The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its …
Power 9 Ac922 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-39070
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to…
Security Verify Access
Mitigation only
CRITICAL 9.8
CVE-2020-4877
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…
Cognos Controller
Mitigation only
CRITICAL 9.8
CVE-2020-4879
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…
Cognos Controller
Mitigation only
CRITICAL 9.1
CVE-2021-39063
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged a…
Spectrum Protect Plus
10.1.9+
CRITICAL 9.8
CVE-2021-39052
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-For…
Spectrum Copy Data Management
after 2.2.13
CRITICAL 9.8
CVE-2021-39065
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper va…
Spectrum Copy Data Management
after 2.2.13
CRITICAL 9.1
CVE-2021-38917
IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system …
Powervm Hypervisor
Mitigation only
CRITICAL 9.1
CVE-2021-38948
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker cou…
Infosphere Information Server
Patch available
CRITICAL 9.8
CVE-2021-29908
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrativ…
Ts7700 Firmware
Mitigation only
CRITICAL 9.1
CVE-2021-38923
IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.
Powervm Hypervisor Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…
Sterling B2b Integrator
after 6.1.0.3
CRITICAL 9.8
CVE-2021-29903
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…
Sterling B2b Integrator
after 6.1.0.3
CRITICAL 9.8
CVE-2021-20578
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m…
Cloud Pak For Security
Patch available
CRITICAL 9.8
CVE-2020-4690
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…
Security Guardium
Patch available
CRITICAL 9.8
CVE-2021-29772
IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.
Api Connect
after 5.0.8.11
CRITICAL 9.1
CVE-2021-29715
IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open …
Api Connect
after 5.0.8.11
CRITICAL 9.8
CVE-2021-20509
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys…
Maximo Asset Management
7.6.1.2+