Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-20393
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error …
Qradar User Behavior Analytics
4.1.1+
MEDIUM 6.1
CVE-2021-20392
IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…
Qradar User Behavior Analytics
4.1.0+
MEDIUM 5.9
CVE-2021-20564
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caus…
Cloud Pak For Security
Mitigation only
MEDIUM 5.3
CVE-2021-20429
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force…
Qradar User Behavior Analytics
4.1.1+
MEDIUM 5.3
CVE-2021-20565
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relies on the existence or values …
Cloud Pak For Security
Mitigation only
MEDIUM 5.4
CVE-2021-20535
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attack…
Jazz Reporting Service
Mitigation only
MEDIUM 5.4
CVE-2020-4535
IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…
Openpages Grc Platform
8.1.0.2+
CRITICAL 9.1
CVE-2021-20538
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce…
Cloud Pak For Security
Mitigation only
MEDIUM 6.1
CVE-2021-20577
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…
Cloud Pak For Security
Patch available
MEDIUM 5.4
CVE-2021-20559
IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…
Control Desk
Patch available
MEDIUM 6.5
CVE-2020-4901
IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial…
Robotic Process Automation With Automation Anywhere
11.0.0.10+
HIGH 7.0
CVE-2020-28198
The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploit…
Tivoli Storage Manager
No fix yet
CRITICAL 9.8
CVE-2020-4979
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between…
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
HIGH 8.1
CVE-2020-5013
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
HIGH 7.8
CVE-2020-4932
IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticatio…
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
HIGH 7.8
CVE-2021-20401
IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticatio…
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
MEDIUM 6.5
CVE-2020-4883
IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further attacks against the system. IBM X…
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
MEDIUM 6.1
CVE-2021-20397
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
MEDIUM 5.4
CVE-2020-4929
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
MEDIUM 5.4
CVE-2020-4987
The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. Th…
Flashsystem 900 Firmware
1.5.2.9 / 1.6.1.3+
MEDIUM 6.7
CVE-2021-20515
IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could o…
Informix Dynamic Server
Patch available
HIGH 7.8
CVE-2021-29667
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitr…
Spectrum Scale
after 5.1.0.2
MEDIUM 6.0
CVE-2020-4981
IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 1…
Spectrum Scale
after 5.1.0.3
MEDIUM 5.4
CVE-2021-20448
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …
Content Navigator
Patch available
MEDIUM 5.4
CVE-2021-20549
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …
Content Navigator
Mitigation only
MEDIUM 5.4
CVE-2021-20550
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …
Content Navigator
Mitigation only
MEDIUM 5.4
CVE-2021-29666
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…
Spectrum Scale
after 5.1.0.2
HIGH 7.8
CVE-2021-29672
IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processi…
Spectrum Protect Client
after 8.1.11.0
HIGH 7.5
CVE-2021-29694
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sen…
Spectrum Protect Plus
after 10.1.7
MEDIUM 6.2
CVE-2021-20536
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local us…
Spectrum Protect Plus
Mitigation only