Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2023-25680
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obf…
Robotic Process Automation
21.0.6+
HIGH 8.2
CVE-2020-4927
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary d…
Spectrum Scale
5.1.7.0+
MEDIUM 6.5
CVE-2022-46774
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …
Manage Application
Mitigation only
MEDIUM 6.5
CVE-2023-22876
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive in…
Sterling B2b Integrator
6.0.3.8 / 6.1.2.2+
HIGH 8.8
CVE-2023-26284
IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted adminis…
Mq Certified Container
9.3.0.4 / 9.3.2.0+
MEDIUM 6.1
CVE-2022-43874
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. This vulnerabil…
App Connect Enterprise Certified Container
Mitigation only
MEDIUM 6.1
CVE-2023-24975
IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an att…
Spectrum Symphony
Mitigation only
HIGH 7.5
CVE-2022-43902
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Forc…
Mq Appliance
9.2.0.8 / 9.2.5+
HIGH 8.8
CVE-2020-5002
IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. …
Financial Transaction Manager
3.2.11+
CRITICAL 9.1
CVE-2023-27290EPSS 9%
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require…
Observability With Instana
after 241-2
MEDIUM 5.4
CVE-2022-35645
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This…
Maximo Application Suite
Patch available
HIGH 7.5
CVE-2020-5026
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive infor…
Financial Transaction Manager
after 3.2.7
HIGH 7.5
CVE-2020-5001
IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a s…
Financial Transaction Manager
after 3.2.7
HIGH 7.5
CVE-2023-26281
IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. I…
HTTP Server
Patch available
HIGH 7.5
CVE-2022-40237
IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel synchronization logic. IBM X-Fo…
Mq For Hpe Nonstop
Patch available
MEDIUM 5.4
CVE-2023-22860
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…
Cloud Pak For Business Automation
Patch available
MEDIUM 5.5
CVE-2022-43923
IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.
Maximo Application Suite
Mitigation only
HIGH 8.8
CVE-2022-43873
An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privil…
Spectrum Virtualize
Mitigation only
MEDIUM 6.5
CVE-2022-43870
IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.
Spectrum Virtualize
Mitigation only
MEDIUM 5.4
CVE-2022-43578
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerab…
Sterling B2b Integrator
after 6.1.2.0
MEDIUM 5.4
CVE-2023-25928
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…
Infosphere Information Server
Patch available
HIGH 8.8
CVE-2022-40231
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unautho…
Sterling B2b Integrator
after 6.1.2.0
HIGH 7.5
CVE-2022-34351
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see …
Qradar Security Information And Event Manager
7.4.3+
HIGH 7.5
CVE-2023-24960
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte…
Infosphere Information Server
Patch available
MEDIUM 5.4
CVE-2022-43579
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerab…
Sterling B2b Integrator
after 6.1.2.0
HIGH 8.8
CVE-2022-40232
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should no…
Sterling B2b Integrator
after 6.1.1.1
HIGH 7.5
CVE-2022-41734
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message…
Maximo Application Suite
Patch available
HIGH 7.5
CVE-2022-43930
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log…
Db2
Patch available
HIGH 7.5
CVE-2022-43927
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a speciall…
Db2
Patch available
HIGH 7.5
CVE-2022-43929
IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-F…
Db2
Patch available