Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-4254
IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h…
Security Guardium Big Data Intelligence
Mitigation only
HIGH 7.2
CVE-2020-4636
IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.
Resilient Security Orchestration Automation And Response
Mitigation only
CRITICAL 9.8
CVE-2020-4499
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the …
Security Access Manager
9.0.7.2 / 10.0.0.1+
MEDIUM 6.1
CVE-2019-4552
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could ex…
Security Access Manager
9.0.7.2 / 10.0.0.1+
MEDIUM 5.4
CVE-2020-4395
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another u…
Security Access Manager Appliance
Patch available
MEDIUM 6.8
CVE-2020-4689
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by imp…
Security Guardium
Patch available
MEDIUM 5.4
CVE-2020-4741
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Java…
Infosphere Information Server
Patch available
MEDIUM 5.2
CVE-2020-4740
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…
Infosphere Information Server
Patch available
HIGH 8.2
CVE-2020-4388
IBM Cognos Analytics 11.0 and 11.1 could be vulnerable to a denial of service attack by failing to catch exceptions in a servlet also exposing debug …
Cognos Analytics
11.0.13+
HIGH 7.8
CVE-2020-4302
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a …
Cognos Analytics
11.0.13+
MEDIUM 5.4
CVE-2020-4680
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…
Security Guardium
Patch available
MEDIUM 5.4
CVE-2020-4681
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…
Security Guardium
Patch available
HIGH 8.1
CVE-2020-4779
A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attac…
Curam Social Program Management
Mitigation only
HIGH 7.5
CVE-2020-4778
IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 c…
Curam Social Program Management
Mitigation only
MEDIUM 6.5
CVE-2020-4781
An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could resul…
Curam Social Program Management
Mitigation only
MEDIUM 5.3
CVE-2020-4780
OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Management 7.0.9 and 7.0,10. The pur…
Curam Social Program Management
Mitigation only
HIGH 8.1
CVE-2020-4772
An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit…
Curam Social Program Management
Mitigation only
HIGH 7.5
CVE-2020-4776
A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse direc…
Curam Social Program Management
Mitigation only
MEDIUM 6.5
CVE-2020-4773
A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a u…
Curam Social Program Management
Mitigation only
MEDIUM 5.4
CVE-2020-4774
An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By se…
Curam Social Program Management
Mitigation only
MEDIUM 5.4
CVE-2020-4775
A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to in…
Curam Social Program Management
Mitigation only
MEDIUM 5.3
CVE-2020-4660
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…
Security Access Manager
Mitigation only
MEDIUM 5.3
CVE-2020-4661
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…
Security Access Manager
Mitigation only
MEDIUM 5.3
CVE-2020-4699
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks…
Security Access Manager
Mitigation only
HIGH 8.8
CVE-2020-4280EPSS 73%
IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-sup…
Qradar Security Information And Event Manager
after 7.4.1
HIGH 7.8
CVE-2020-4799
IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds write vulnerability. IBM X-Force…
Informix Dynamic Server
Patch available
HIGH 7.5
CVE-2019-4545
IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
Qradar Security Information And Event Manager
after 7.4.1
MEDIUM 5.5
CVE-2020-4528
IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain hi…
Datapower Gateway
after 2018.4.1.12
MEDIUM 6.1
CVE-2019-4725
IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
Security Access Manager
9.0.7.0+
CRITICAL 9.8
CVE-2020-4493
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP comman…
Maximo Asset Management
7.6.0.10 / 7.6.1.2+