Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-20418
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise use…
Security Guardium
Mitigation only
CRITICAL 9.8
CVE-2021-29781
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. B…
Partner Engagement Manager
Patch available
CRITICAL 9.1
CVE-2021-20399
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
CRITICAL 9.8
CVE-2020-4821
IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypa…
Infosphere Data Replication
Patch available
CRITICAL 9.1
CVE-2020-5003
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…
Financial Transaction Manager
Mitigation only
CRITICAL 10.0
CVE-2020-4561
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who c…
Cognos Analytics
Patch available
CRITICAL 9.1
CVE-2021-20487
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing t…
Power9 System Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-20426
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…
Security Guardium
Patch available
CRITICAL 9.1
CVE-2020-4669
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …
Planning Analytics Cloud
Patch available
CRITICAL 9.1
CVE-2020-4670
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not p…
Planning Analytics Cloud
Patch available
CRITICAL 9.1
CVE-2021-20538
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce…
Cloud Pak For Security
Mitigation only
CRITICAL 9.8
CVE-2020-4979
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between…
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
CRITICAL 9.8
CVE-2020-4682EPSS 8%
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…
Mq
Patch available
CRITICAL 9.8
CVE-2020-27583
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec…
Infosphere Information Server
No fix yet
CRITICAL 9.8
CVE-2020-4958
IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …
Security Identity Governance And Intelligence
Mitigation only
CRITICAL 9.1
CVE-2020-4899
IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of …
Api Connect
after 5.0.8.10
CRITICAL 9.8
CVE-2020-4988
Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or poss…
Loopback
Mitigation only
CRITICAL 9.8
CVE-2020-4747
IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au…
Connect\
Mitigation only
CRITICAL 9.0
CVE-2020-4627
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, c…
Cloud Pak For Security
Patch available
CRITICAL 9.8
CVE-2020-4854
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…
Spectrum Protect Plus
after 10.1.6
CRITICAL 9.8
CVE-2020-4499
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the …
Security Access Manager
9.0.7.2 / 10.0.0.1+
CRITICAL 9.8
CVE-2020-4493
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP comman…
Maximo Asset Management
7.6.0.10 / 7.6.1.2+
CRITICAL 9.8
CVE-2020-4693
IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the sy…
Spectrum Protect Operations Center
after 8.1.9.000
CRITICAL 9.8
CVE-2019-4694
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its o…
Guardium Data Encryption
1.7.0+
CRITICAL 9.8
CVE-2020-4589EPSS 8%
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafte…
Websphere Application Server
after 9.0.5.4
CRITICAL 9.8
CVE-2020-4459
IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentic…
Security Secret Server
10.8+
CRITICAL 9.1
CVE-2020-4377
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex…
Cognos Analytics
Mitigation only
CRITICAL 9.8
CVE-2020-4567
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account c…
Security Key Lifecycle Manager
Patch available
CRITICAL 9.8
CVE-2020-4385
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …
Verify Gateway
Patch available
CRITICAL 9.8
CVE-2020-4216
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…
Spectrum Protect Plus
after 10.1.5