Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.4
CVE-2026-14525
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa…
Websphere Application Server
No fix yet
CRITICAL 9.8
CVE-2026-14529
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14976
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…
Websphere Application Server
26.0.0.9+
CRITICAL 9.8
CVE-2026-14446
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Websphere Application Server
8.5.5.30 / 9.0.5.28+
MEDIUM 6.5
CVE-2026-1264
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…
Sterling B2b Integrator
6.1.2.8 / 6.2.0.5_2+
CRITICAL 9.8
CVE-2025-3319
IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result …
Spectrum Protect Server
after 8.1.26
MEDIUM 6.3
CVE-2024-56469
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 throu…
Devops Deploy
7.1.2.23 / 7.2.3.16+
CRITICAL 9.1
CVE-2025-0159
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…
Storage Virtualize
8.5.0.14 / 8.6.0.6+
MEDIUM 6.5
CVE-2024-54176
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2…
Devops Deploy
7.0.5.26 / 7.1.2.22+
HIGH 8.8
CVE-2024-45075
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad…
Webmethods Integration
Mitigation only
MEDIUM 6.5
CVE-2024-35151
IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.
Openpages Grc Platform
Mitigation only
HIGH 7.5
CVE-2024-35124
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default…
Openbmc
Mitigation only
CRITICAL 9.1
CVE-2024-35143
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,…
Planning Analytics Workspace
2.0.97 / 2.1.4+
HIGH 7.5
CVE-2024-31916
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses aut…
Openbmc
Mitigation only
MEDIUM 6.3
CVE-2024-22326
IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP con…
Ds8900f Firmware
Mitigation only
HIGH 7.5
CVE-2023-43045
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authenticat…
Sterling Partner Engagement Manager
Patch available
CRITICAL 9.1
CVE-2023-27290EPSS 9%
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require…
Observability With Instana
after 241-2
MEDIUM 6.8
CVE-2022-22309
The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the s…
Power System S922 Firmware
860.b0 / 940.60+
HIGH 7.5
CVE-2021-20474
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity o…
Guardium Data Encryption
Patch available
CRITICAL 9.1
CVE-2020-4670
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not p…
Planning Analytics Cloud
Patch available
CRITICAL 9.8
CVE-2020-4958
IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …
Security Identity Governance And Intelligence
Mitigation only
MEDIUM 5.3
CVE-2020-5022
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai…
Spectrum Protect Plus
10.1.7+
HIGH 7.5
CVE-2018-1501
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-F…
Security Guardium
Patch available
MEDIUM 6.5
CVE-2020-4471
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a…
Spectrum Protect Plus
after 10.1.5
MEDIUM 5.3
CVE-2019-4551
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access…
Security Directory Server
6.4.0.20+
CRITICAL 9.1
CVE-2019-4244
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper i…
Smartcloud Analytics Log Analysis
after 1.3.5
MEDIUM 5.3
CVE-2019-4337
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in I…
Robotic Process Automation With Automation Anywhere
11.0.0.4+
HIGH 7.5
CVE-2018-1745
IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Fo…
Security Key Lifecycle Manager
after 3.0.0.1
MEDIUM 5.3
CVE-2018-1757
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentica…
Security Identity Governance And Intelligence
Patch available
HIGH 7.5
CVE-2017-1523
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X…
Infosphere Master Data Management
Mitigation only