Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-4576
IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-cr…
Websphere Application Server
7.0.0.45 / 8.0.0.15+
HIGH 7.8
CVE-2020-4607
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper…
Security Verify Privilege Vault Remote On Premises
Patch available
MEDIUM 6.1
CVE-2020-4727
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a m…
Infosphere Information Server
Mitigation only
MEDIUM 5.3
CVE-2020-4531
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sens…
Business Automation Workflow
Mitigation only
HIGH 8.8
CVE-2020-4620EPSS 5%
IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e…
Data Risk Manager
2.0.6.4+
HIGH 8.8
CVE-2020-4621
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …
Data Risk Manager
2.0.6.4+
HIGH 7.5
CVE-2020-4622
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authen…
Data Risk Manager
2.0.6.4+
MEDIUM 6.5
CVE-2020-4619
IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.
Data Risk Manager
2.0.6.4+
HIGH 8.8
CVE-2020-4611
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 1849…
Data Risk Manager
2.0.6.4+
HIGH 8.1
CVE-2020-4617
IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…
Data Risk Manager
2.0.6.4+
HIGH 7.5
CVE-2020-4613
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…
Data Risk Manager
2.0.6.4+
HIGH 7.5
CVE-2020-4614
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. …
Data Risk Manager
2.0.6.4+
MEDIUM 6.5
CVE-2020-4612
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to obtain sensitive information using a specially crafted HTTP request. IBM X-Fo…
Data Risk Manager
2.0.6.4+
MEDIUM 5.4
CVE-2020-4615
IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…
Data Risk Manager
2.0.6.4+
MEDIUM 5.3
CVE-2020-4616
IBM Data Risk Manager (iDNA) 2.0.6 could disclose sensitive username information to an attacker using a specially crafted HTTP request. IBM X-Force I…
Data Risk Manager
2.0.6.4+
HIGH 7.5
CVE-2020-4643
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…
Websphere Application Server
after 9.0.5.5
MEDIUM 6.5
CVE-2020-4590
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a de…
Websphere Application Server
after 20.0.0.9
MEDIUM 6.1
CVE-2020-4731
IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…
Aspera Shares
after 1.9.14
HIGH 7.5
CVE-2020-4579
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2…
Datapower Gateway
after 2018.4.1.12
HIGH 7.5
CVE-2020-4580
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON…
Datapower Gateway
after 2018.4.1.12
HIGH 7.5
CVE-2020-4581
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encodin…
Datapower Gateway
after 2018.4.1.12
HIGH 8.2
CVE-2020-4409
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a vic…
Control Desk
7.6.1.2+
MEDIUM 5.3
CVE-2020-4708
IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Control-Allow-Origin header. IBM X…
Security Trusteer Pinpoint Detect
11.6.5.2+
MEDIUM 6.1
CVE-2020-8339
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior…
Bladecenter Advanced Management Module Firmware
3.68n+
HIGH 8.8
CVE-2020-4521EPSS 6%
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe …
Maximo Asset Management
7.6.0.10 / 7.6.1.2+
HIGH 8.0
CVE-2020-4703
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…
Spectrum Protect Plus
after 10.1.6
MEDIUM 6.5
CVE-2020-4711
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a special…
Spectrum Protect Plus
after 10.1.6
MEDIUM 5.4
CVE-2020-4530
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability …
Business Automation Workflow
8.0.1.0 / 8.5.7.0+
MEDIUM 6.3
CVE-2019-4671
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which coul…
Maximo Asset Management
7.6.0.10 / 7.6.1.2+
MEDIUM 5.4
CVE-2020-4578
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…
Websphere Application Server
after 9.0.5.5