Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.8
CVE-2024-47104
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the…
I
Mitigation only
HIGH 7.5
CVE-2024-49819
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext i…
Security Guardium Key Lifecycle Manager
Mitigation only
MEDIUM 6.5
CVE-2024-52901
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
Infosphere Information Server
Mitigation only
MEDIUM 6.5
CVE-2023-23472
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that co…
Infosphere Information Server
Mitigation only
MEDIUM 5.4
CVE-2024-47107
IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in…
Qradar Security Information And Event Manager
Mitigation only
HIGH 7.8
CVE-2024-47115
IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
Vios
Mitigation only
HIGH 7.5
CVE-2024-41777
IBM Cognos Controller 11.0.0 and 11.0.1
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…
Cognos Controller
Mitigation only
MEDIUM 6.5
CVE-2024-41776
IBM Cognos Controller 11.0.0 and 11.0.1
is vulnerable to cross-site request forgery which could allow an attacker to execute malicious an…
Cognos Controller
Mitigation only
HIGH 7.5
CVE-2024-41775
IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive i…
Cognos Controller
Mitigation only
CRITICAL 9.8
CVE-2024-25020
IBM Cognos Controller 11.0.0 and 11.0.1
is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Jou…
Cognos Controller
Mitigation only
CRITICAL 9.8
CVE-2024-40691
IBM Cognos Controller 11.0.0 and 11.0.1
could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web …
Cognos Controller
Mitigation only
CRITICAL 9.8
CVE-2024-25019
IBM Cognos Controller 11.0.0 and 11.0.1
could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry a…
Cognos Controller
Mitigation only
MEDIUM 5.3
CVE-2024-25035
IBM Cognos Controller 11.0.0 and 11.0.1
exposes server details that could allow an attacker to obtain information of the application environment …
Cognos Controller
No fix yet
MEDIUM 5.9
CVE-2021-29892
IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP …
Cognos Controller
Mitigation only
MEDIUM 5.5
CVE-2024-49351
IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
Workload Scheduler
Mitigation only
HIGH 8.8
CVE-2024-52899
IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on th…
Data Virtualization Manager For Z\/os
Mitigation only
MEDIUM 5.3
CVE-2023-26280
IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request due to improper access contro…
Jazz Foundation
Mitigation only
MEDIUM 6.5
CVE-2024-35160
IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticat…
Big Sql
Mitigation only
MEDIUM 5.3
CVE-2024-41761
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u…
Db2
Mitigation only
MEDIUM 5.9
CVE-2024-41781
IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060…
Powervm Hypervisor
Mitigation only
HIGH 8.1
CVE-2024-41779
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a ra…
Engineering Systems Design Rhapsody
Mitigation only
CRITICAL 9.8
CVE-2024-52360
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …
Concert
Mitigation only
HIGH 8.8
CVE-2024-52359
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to ad…
Concert
No fix yet
HIGH 8.2
CVE-2024-39726
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when pro…
Engineering Lifecycle Optimization Engineering Insights
Mitigation only
HIGH 7.5
CVE-2024-41784
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An att…
Sterling Secure Proxy
Mitigation only
MEDIUM 6.1
CVE-2024-41785
IBM Concert Software 1.0.0 through 1.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitr…
Concert
Mitigation only
MEDIUM 5.9
CVE-2024-43189
IBM Concert Software 1.0.0 through 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…
Concert
Mitigation only
MEDIUM 5.4
CVE-2024-45088
IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary Ja…
Maximo Asset Management
Mitigation only
MEDIUM 5.4
CVE-2024-35146
IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unaut…
Maximo Application Suite
Mitigation only
HIGH 8.8
CVE-2024-41744
IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra…
Cics Tx
Mitigation only