Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2021-29713
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…
Engineering Lifecycle Optimization
Patch available
MEDIUM 5.3
CVE-2021-20526
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at…
Planning Analytics
Patch available
MEDIUM 6.1
CVE-2021-29835
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Business Automation Workflow
Patch available
HIGH 8.1
CVE-2021-29873
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell es…
Spectrum Virtualize
8.4.0.0+
MEDIUM 6.1
CVE-2021-38896
IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…
Qradar Advisor
after 2.6.1
MEDIUM 5.4
CVE-2021-29912
IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
Security Risk Manager On Cp4s
Patch available
MEDIUM 5.4
CVE-2021-29878
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Business Automation Workflow
Patch available
HIGH 8.8
CVE-2021-29679
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled inp…
Cognos Analytics
Patch available
HIGH 8.8
CVE-2021-29745
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to whic…
Cognos Analytics
Patch available
HIGH 7.5
CVE-2021-38862
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…
Data Risk Manager
Mitigation only
MEDIUM 6.5
CVE-2021-38915
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
Data Risk Manager
Mitigation only
MEDIUM 6.5
CVE-2020-4654
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission contro…
Sterling File Gateway
5.2.6.5_4 / 6.0.3.5+
MEDIUM 5.5
CVE-2021-29906
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is config…
App Connect Enterprise Certified Container
Mitigation only
HIGH 8.8
CVE-2021-20489
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …
Sterling File Gateway
after 6.1.0.3
HIGH 7.5
CVE-2021-20584
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-…
Sterling B2b Integrator
after 6.1.0.2
MEDIUM 6.1
CVE-2021-20481
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
Sterling File Gateway
after 6.1.0.1
MEDIUM 6.1
CVE-2021-20561
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…
Sterling B2b Integrator
after 6.1.0.2
MEDIUM 5.4
CVE-2021-20571
IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …
Sterling B2b Integrator
after 6.1.0.3
MEDIUM 6.5
CVE-2021-20375
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to im…
Sterling B2b Integrator
after 6.1.0.1
MEDIUM 6.5
CVE-2021-20473
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to …
Sterling File Gateway
after 6.1.0.1
CRITICAL 9.8
CVE-2021-29908
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrativ…
Ts7700 Firmware
Mitigation only
CRITICAL 9.1
CVE-2021-38923
IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.
Powervm Hypervisor Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…
Sterling B2b Integrator
after 6.1.0.3
CRITICAL 9.8
CVE-2021-29903
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted S…
Sterling B2b Integrator
after 6.1.0.3
HIGH 8.8
CVE-2021-29837
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to exe…
Sterling B2b Integrator
after 6.1.0.3
HIGH 7.5
CVE-2021-38925
IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker…
Sterling B2b Integrator
after 6.1.0.3
MEDIUM 5.4
CVE-2021-29764
IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …
Sterling B2b Integrator
after 6.1.0.3
MEDIUM 5.4
CVE-2021-29836
IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed…
Sterling B2b Integrator
after 6.1.0.3
MEDIUM 5.4
CVE-2021-29855
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed …
Sterling B2b Integrator
after 6.1.0.3
CRITICAL 9.8
CVE-2021-20578
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m…
Cloud Pak For Security
Patch available