Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2017-1438
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileg…
Db2
Patch available
MEDIUM 6.7
CVE-2017-1439
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileg…
Db2
Patch available
MEDIUM 5.9
CVE-2017-1519
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a p…
Db2
Patch available
MEDIUM 5.5
CVE-2017-1352
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user …
Maximo Asset Management
Mitigation only
HIGH 8.8
CVE-2014-9565
Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earli…
Ib6131 Firmware
after 3.4.0.0.0.0
MEDIUM 6.1
CVE-2017-1189
IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr…
Websphere Portal
Mitigation only
MEDIUM 5.4
CVE-2017-1098
IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…
Emptoris Supplier Lifecycle Management
Mitigation only
MEDIUM 5.4
CVE-2017-1502
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…
Content Navigator
Mitigation only
HIGH 8.8
CVE-2017-1097
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker…
Emptoris Strategic Supply Management
Mitigation only
HIGH 8.1
CVE-2017-1458
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could explo…
Qradar Network Security
Mitigation only
HIGH 7.5
CVE-2017-1491
IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a…
Qradar Network Security
Mitigation only
MEDIUM 6.5
CVE-2017-1129EPSS 30%
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to h…
Inotes
Patch available
MEDIUM 6.5
CVE-2017-1130EPSS 29%
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select di…
Inotes
Patch available
MEDIUM 6.1
CVE-2017-1457
IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …
Qradar Network Security
Mitigation only
MEDIUM 6.1
CVE-2017-1450
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…
Emptoris Sourcing
Mitigation only
MEDIUM 5.4
CVE-2017-1444
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…
Emptoris Sourcing
Mitigation only
MEDIUM 5.4
CVE-2017-1447
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…
Emptoris Sourcing
Mitigation only
MEDIUM 5.4
CVE-2017-1449
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim t…
Emptoris Sourcing
Mitigation only
HIGH 8.8
CVE-2017-1440
IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted…
Emptoris Services Procurement
Patch available
HIGH 8.8
CVE-2017-1442
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unautho…
Emptoris Services Procurement
Patch available
MEDIUM 6.1
CVE-2017-1443
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …
Emptoris Services Procurement
Patch available
MEDIUM 5.5
CVE-2017-1441
IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM …
Emptoris Services Procurement
Patch available
MEDIUM 5.4
CVE-2017-1445
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…
Emptoris Spend Analysis
Mitigation only
MEDIUM 5.4
CVE-2017-1446
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…
Emptoris Spend Analysis
Mitigation only
MEDIUM 6.3
CVE-2016-2980
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerabi…
Sametime
Patch available
MEDIUM 6.1
CVE-2017-1195
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. …
Curam Social Program Management
Patch available
MEDIUM 6.1
CVE-2017-1427
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…
Cognos Analytics
Patch available
MEDIUM 6.1
CVE-2017-1428
IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …
Cognos Analytics
Patch available
MEDIUM 5.4
CVE-2016-2967
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Sametime …
Sametime
Patch available
MEDIUM 5.4
CVE-2016-2975
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…
Sametime
Patch available