Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-23781
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl…
Control M\/managed File Transfer
after 9.0.22
HIGH 8.8
CVE-2026-23780
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenti…
Control M\/managed File Transfer
after 9.0.22
HIGH 7.5
CVE-2026-23782
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API ide…
Control M\/managed File Transfer
after 9.0.22
HIGH 8.8
CVE-2025-71260EPSS 34%
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTA…
Footprints
after 20.24.01.001
HIGH 7.1
CVE-2025-71258EPSS 17%
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component t…
Footprints
after 20.24.01.001
HIGH 7.1
CVE-2025-71259EPSS 13%
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API comp…
Footprints
after 20.24.01.001
CRITICAL 9.1
CVE-2025-71257EPSS 5%
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil…
Footprints
after 20.24.01.001
MEDIUM 5.3
CVE-2025-55117
A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configu…
Control M\/agent
after 9.0.22
HIGH 8.8
CVE-2025-55115
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vu…
Control M\/agent
9.0.20.100+
HIGH 8.8
CVE-2025-55116
A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent.
This …
Control M\/agent
9.0.20.100+
CRITICAL 10.0
CVE-2025-55113
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 t…
Control M\/agent
after 9.0.22
HIGH 7.4
CVE-2025-55112
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Bl…
Control M\/agent
after 9.0.20.200
MEDIUM 5.5
CVE-2025-55111
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earl…
Control M\/agent
9.0.21+
CRITICAL 9.0
CVE-2025-55109
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported ver…
Control M\/agent
after 9.0.22
HIGH 7.8
CVE-2025-48709
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could …
Control M\/server
Mitigation only
CRITICAL 9.8
CVE-2024-34399
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac…
Remedy Mid Tier
Mitigation only
HIGH 8.8
CVE-2021-35002
BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…
Track It\!
Mitigation only
MEDIUM 6.5
CVE-2021-35001
BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…
Track It\!
Mitigation only
HIGH 7.8
CVE-2024-1605
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissi…
Control M
9.0.20.238 / 9.0.21.201+
MEDIUM 5.4
CVE-2024-1606
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection…
Control M
9.0.20.238 / 9.0.21.201+
MEDIUM 6.8
CVE-2024-1604
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and ma…
Control M
9.0.20.238 / 9.0.21.201+
HIGH 7.8
CVE-2020-35593
BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.
Patrol Agent
after 20.08.00
CRITICAL 9.8
CVE-2017-9453
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
Server Automation
after 8.9.01
CRITICAL 9.8
CVE-2023-39122
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is als…
Control M
9.0.21+
CRITICAL 9.8
CVE-2023-34257
An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not req…
Patrol Agent
after 23.1.00
HIGH 7.5
CVE-2023-34258
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol accou…
Patrol
22.1.00+
CRITICAL 9.8
CVE-2023-26550
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
Control M
9.0.20.214+
MEDIUM 5.4
CVE-2022-26088
An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF …
Remedy It Service Management Suite
No fix yet
CRITICAL 9.8
CVE-2022-35865
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re…
Track It\!
Patch available
MEDIUM 6.5
CVE-2022-35864
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication …
Track It\!
Patch available