Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2020-4516
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerab…
Business Automation Workflow
Patch available
MEDIUM 5.4
CVE-2020-4698
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This v…
Business Automation Workflow
Patch available
HIGH 7.8
CVE-2020-4545
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries …
Aspera Connect
after 3.9.9
MEDIUM 6.5
CVE-2020-4632
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticat…
Infosphere Metadata Asset Manager
Mitigation only
MEDIUM 5.4
CVE-2020-4702
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…
Infosphere Information Server
Mitigation only
HIGH 7.2
CVE-2020-4638
IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can es…
Api Connect
after 2018.4.1.12
MEDIUM 6.5
CVE-2020-4337
IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registratio…
Api Connect
after 2018.4.1.12
CRITICAL 9.8
CVE-2020-4693
IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the sy…
Spectrum Protect Operations Center
after 8.1.9.000
MEDIUM 5.4
CVE-2020-4445
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
Doors Next
Mitigation only
MEDIUM 5.4
CVE-2020-4522
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
Doors Next
Mitigation only
MEDIUM 5.4
CVE-2020-4546
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
Doors Next
Mitigation only
MEDIUM 5.4
CVE-2012-3341
IBM InfoSphere Guardium 7.0, 8.0, 8.01, and 8.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote…
Infosphere Guardium
Mitigation only
MEDIUM 5.3
CVE-2012-3338
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by improper restrictions on the crea…
Infosphere Guardium
Mitigation only
MEDIUM 5.3
CVE-2012-3337
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-cr…
Infosphere Guardium
Mitigation only
HIGH 8.8
CVE-2012-3336
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statement…
Infosphere Guardium
Mitigation only
MEDIUM 5.5
CVE-2020-4492
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the ke…
Spectrum Scale
after 5.0.4.3
HIGH 7.5
CVE-2020-4559
IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force …
Spectrum Protect
after 8.1.10.000
HIGH 7.2
CVE-2020-4603
IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new wea…
Security Guardium Insights
Patch available
MEDIUM 6.1
CVE-2020-4575
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Av…
Websphere Application Server
8.5.5.18 / 9.0.5.5+
MEDIUM 5.9
CVE-2020-4175
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…
Security Guardium Insights
Patch available
HIGH 7.5
CVE-2020-4169
IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…
Security Guardium Insights
Patch available
HIGH 7.5
CVE-2020-4174
IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive info…
Security Guardium Insights
Patch available
MEDIUM 6.5
CVE-2020-4167
IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized actions due to improper authenci…
Security Guardium Insights
Patch available
MEDIUM 5.3
CVE-2020-4166
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returne…
Security Guardium Insights
Patch available
MEDIUM 5.3
CVE-2020-4172
IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties …
Security Guardium Insights
Patch available
CRITICAL 9.8
CVE-2019-4694
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its o…
Guardium Data Encryption
1.7.0+
HIGH 8.8
CVE-2019-4713
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sendi…
Guardium Data Encryption
1.7.0+
HIGH 7.5
CVE-2019-4698
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for at…
Guardium Data Encryption
1.7.0+
MEDIUM 6.5
CVE-2019-4697
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-…
Guardium Data Encryption
1.7.0+
MEDIUM 5.4
CVE-2019-4691
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…
Guardium Data Encryption
1.7.0 / 4.0.0.3+