Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2024-29032
Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. …
Qiskit Ibm Runtime
0.21.2+
MEDIUM 5.3
CVE-2023-45177
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM…
Mq
9.0.0.21 / 9.1.0.18+
MEDIUM 5.9
CVE-2023-35888
IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…
Security Verify Governance
Mitigation only
MEDIUM 6.1
CVE-2023-47699
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
Sterling Secure Proxy
Mitigation only
MEDIUM 5.3
CVE-2023-47147
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.
Sterling Secure Proxy
Patch available
MEDIUM 5.5
CVE-2021-38938
IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be r…
Host Access Transformation Services
after 9.7.0.3
MEDIUM 6.1
CVE-2023-47162
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
Sterling Secure Proxy
Patch available
MEDIUM 5.4
CVE-2023-46182
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
Sterling Secure Proxy
Mitigation only
HIGH 8.2
CVE-2024-27266
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could…
Maximo Application Suite
Patch available
MEDIUM 6.5
CVE-2024-27265
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…
Integration Bus
after 10.1.0.3
HIGH 7.8
CVE-2024-22346
Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malici…
I
Patch available
HIGH 7.5
CVE-2023-32335
IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to info…
Maximo Application Suite
Mitigation only
MEDIUM 6.4
CVE-2023-38723
IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…
Maximo Application Suite
Mitigation only
MEDIUM 5.5
CVE-2023-43043
IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.
Maximo Mobile For Eam
Mitigation only
MEDIUM 5.4
CVE-2023-28517
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…
Sterling Partner Engagement Manager
Mitigation only
MEDIUM 5.5
CVE-2022-43855
IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity a…
Spss Statistics
Mitigation only
CRITICAL 9.8
CVE-2023-46172
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions fo…
Ds8900f Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-46169
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X…
Ds8900f Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-46170
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily read files after enum…
Ds8900f Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-22399
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could all…
Aspera Faspex
Mitigation only
MEDIUM 6.5
CVE-2023-25681
LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface usin…
Spectrum Virtualize
Mitigation only
HIGH 7.5
CVE-2023-32331
IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its bro…
Sterling Connect\
Mitigation only
MEDIUM 6.1
CVE-2023-38360
IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…
Cics Tx
Mitigation only
MEDIUM 5.3
CVE-2023-38362
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID:…
Cics Tx
Mitigation only
HIGH 7.5
CVE-2022-43890
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…
Security Verify Privilege On Premises
after 11.5
HIGH 7.5
CVE-2023-27291
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which co…
Watson Cp4d Data Stores
Mitigation only
MEDIUM 5.9
CVE-2023-28512
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improp…
Watson Cp4d Data Stores
Mitigation only
MEDIUM 5.9
CVE-2023-47742
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information …
Cloud Pak For Security
after 1.10.18.0
MEDIUM 5.9
CVE-2024-22355
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should ha…
Cloud Pak For Security
after 1.10.18.0
MEDIUM 5.4
CVE-2023-43054
IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Java…
Engineering Test Management
Mitigation only