Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2020-4278
IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges…
Platform Lsf
Patch available
MEDIUM 5.4
CVE-2020-4196
IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…
Tivoli Netcool\/omnibus
Patch available
MEDIUM 5.4
CVE-2020-4198
IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…
Tivoli Netcool\/omnibus
Patch available
HIGH 8.6
CVE-2020-4283
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptographic key,…
Security Information Queue
Mitigation only
MEDIUM 5.3
CVE-2020-4292
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 uses a cross-domain policy file that includes domains that should not be …
Security Information Queue
Mitigation only
MEDIUM 6.3
CVE-2019-4669
IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 throug…
Business Process Manager
after 19.0.0.3
MEDIUM 6.3
CVE-2019-4597
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted S…
Sterling B2b Integrator
after 5.2.6.5
MEDIUM 6.3
CVE-2019-4598
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted S…
Sterling B2b Integrator
after 5.2.6.5
MEDIUM 5.4
CVE-2019-4596
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed …
Sterling B2b Integrator
after 5.2.6.5
MEDIUM 5.3
CVE-2019-4537
IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further attacks ag…
Websphere Service Registry And Repository
Patch available
HIGH 7.5
CVE-2019-4557
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens…
Qradar Advisor
2.5.1+
MEDIUM 5.3
CVE-2019-4672
IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that cou…
Qradar Advisor
2.5.1+
CRITICAL 9.8
CVE-2020-4210EPSS 15%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2020-4211EPSS 71%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2020-4212EPSS 15%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2020-4213EPSS 15%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
CRITICAL 9.8
CVE-2020-4222EPSS 15%
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …
Spectrum Protect
10.1.5+
MEDIUM 6.1
CVE-2019-4595
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirec…
Sterling B2b Integrator
after 5.2.6.5
MEDIUM 5.3
CVE-2019-4703
IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of …
Spectrum Protect Plus
after 10.1.5
HIGH 8.8
CVE-2019-4752
IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A …
Emptoris Spend Analysis
10.1.0.34 / 10.1.1.33+
MEDIUM 6.7
CVE-2020-4230
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated loc…
Db2
Mitigation only
CRITICAL 9.8
CVE-2019-4640
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the cod…
Security Secret Server
Mitigation only
HIGH 7.8
CVE-2020-4204
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by impro…
Db2
Mitigation only
HIGH 7.5
CVE-2020-4135
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send special…
Db2
Mitigation only
MEDIUM 6.5
CVE-2019-4457
IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obtain sensitive information that…
Jazz Foundation
after 6.0.6.1
MEDIUM 6.5
CVE-2020-4161
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to inco…
Db2
Mitigation only
MEDIUM 6.5
CVE-2020-4200
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafte…
Db2
Mitigation only
MEDIUM 5.4
CVE-2019-4429
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…
Control Desk
Patch available
MEDIUM 5.4
CVE-2012-0718
IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies.
Tivoli Endpoint Manager
Mitigation only
CRITICAL 9.8
CVE-2013-3323
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to …
Change And Configuration Management Database
Mitigation only