Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-31896
IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl…
Spss Statistics
Mitigation only
MEDIUM 6.8
CVE-2023-43029
IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment.
Storage Virtualize Plugin For Vsphere
Mitigation only
HIGH 7.8
CVE-2024-51459
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
Infosphere Information Server
11.7.1.136+
CRITICAL 10.0
CVE-2024-56346
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
Aix
Mitigation only
CRITICAL 9.6
CVE-2024-56347
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process c…
Aix
Mitigation only
HIGH 7.5
CVE-2024-45643
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential informat…
Security Qradar Edr
3.12.16+
CRITICAL 9.8
CVE-2025-2000
A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma…
Qiskit
1.4.2+
MEDIUM 6.5
CVE-2024-52362
IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 1…
App Connect Enterprise Certified Containers Operands
12.9.0+
MEDIUM 6.5
CVE-2024-22340
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51
could allow a remote attacker to obtain sensitive information during the creation of E…
Common Cryptographic Architecture
7.5.52+
MEDIUM 6.5
CVE-2024-49823
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Mo…
Common Cryptographic Architecture
7.5.52+
MEDIUM 5.3
CVE-2024-47109
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid…
Sterling File Gateway
6.1.2.7 / 6.2.0.4+
HIGH 7.1
CVE-2025-0162
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenti…
Aspera Shares
1.10.0+
MEDIUM 5.3
CVE-2023-43052
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input.…
Control Center
Mitigation only
MEDIUM 6.1
CVE-2023-35894
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could…
Sterling Control Center
Mitigation only
HIGH 7.5
CVE-2024-51476
IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Concert Software
Mitigation only
HIGH 7.5
CVE-2024-41771
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…
Engineering Requirements Management Doors Next
Mitigation only
MEDIUM 6.5
CVE-2024-43169
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integr…
Engineering Requirements Management Doors Next
Mitigation only
HIGH 7.5
CVE-2024-41770
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…
Engineering Requirements Management Doors Next
Mitigation only
MEDIUM 5.4
CVE-2024-54179
IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vuln…
Business Automation Workflow
after 24.0.1
MEDIUM 5.3
CVE-2024-55907
IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming …
Cognos Analytics Mobile
1.1.21+
MEDIUM 6.5
CVE-2024-41778
IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attack…
Controller
Mitigation only
CRITICAL 9.8
CVE-2025-0160
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…
Storage Virtualize
8.5.0.14 / 8.6.0.6+
CRITICAL 9.1
CVE-2025-0159
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…
Storage Virtualize
8.5.0.14 / 8.6.0.6+
MEDIUM 5.5
CVE-2024-54175
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD
could allow a local user to cause a denial of service due to an improper check for unusual or exception…
Mq
Mitigation only
MEDIUM 5.5
CVE-2025-0985
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD
stores potentially sensitive information in environment variables that could be obtained by a local use…
Mq
Mitigation only
HIGH 8.8
CVE-2025-0975
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape charac…
Mq Appliance
after 9.4.2
MEDIUM 6.5
CVE-2024-56340
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by…
Cognos Analytics
11.2.4 / 12.0.4+
MEDIUM 6.5
CVE-2025-0823
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An atta…
Cognos Analytics
11.2.4 / 12.0.4+
MEDIUM 6.5
CVE-2025-23225
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid he…
Mq Appliance
after 9.4.2
MEDIUM 5.5
CVE-2024-56812
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information coul…
Entirex
Mitigation only