Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2020-4549
IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a vi…
I2 Analysts Notebook
Mitigation only
HIGH 7.8
CVE-2020-4550
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…
I2 Analysts Notebook
Mitigation only
HIGH 7.8
CVE-2020-4551
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…
I2 Analysts Notebook
Mitigation only
HIGH 7.8
CVE-2020-4552
IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a vi…
I2 Analysts Notebook
Mitigation only
HIGH 7.8
CVE-2020-4553
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…
I2 Analysts Notebook
Mitigation only
HIGH 7.8
CVE-2020-4554
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persu…
I2 Analysts Notebook
Mitigation only
MEDIUM 6.3
CVE-2020-4328
IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could al…
Financial Transaction Manager For Multiplatform
Mitigation only
MEDIUM 5.3
CVE-2019-4366
IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser da…
Cognos Analytics
Mitigation only
HIGH 7.5
CVE-2020-4185
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitiv…
Security Guardium
Patch available
MEDIUM 5.3
CVE-2020-4186
IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the syste…
Security Guardium
Patch available
CRITICAL 9.8
CVE-2020-4567
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account c…
Security Key Lifecycle Manager
Patch available
HIGH 8.2
CVE-2020-4463EPSS 32%
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote att…
Maximo Asset Management
Patch available
HIGH 7.5
CVE-2020-4574
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromi…
Security Key Lifecycle Manager
Patch available
MEDIUM 6.5
CVE-2020-4569
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an input, but the input can be m…
Security Key Lifecycle Manager
Patch available
MEDIUM 5.4
CVE-2020-4644
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim …
Planning Analytics Local
after 2.0.9.1
MEDIUM 5.4
CVE-2020-4645
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…
Planning Analytics Local
after 2.0.9.1
MEDIUM 5.3
CVE-2020-4572
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message …
Security Key Lifecycle Manager
Patch available
MEDIUM 5.3
CVE-2020-4573
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force I…
Security Key Lifecycle Manager
Patch available
HIGH 7.5
CVE-2020-4375
IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak c…
Mq Appliance
8.0.0.15 / 9.1.0.6+
MEDIUM 6.5
CVE-2020-4465
IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within…
Mq Appliance
8.0.0.15 / 9.1.0.6+
MEDIUM 5.4
CVE-2020-4317
IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnera…
Intelligent Operations Center
Patch available
MEDIUM 5.4
CVE-2020-4318
IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnera…
Intelligent Operations Center
Patch available
MEDIUM 5.5
CVE-2019-4731
IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Forc…
Mq Appliance
Patch available
MEDIUM 5.4
CVE-2020-4447
IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…
Filenet Content Manager
Patch available
CRITICAL 9.8
CVE-2020-4385
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …
Verify Gateway
Patch available
HIGH 7.8
CVE-2020-4372
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009
Verify Gateway
Patch available
HIGH 7.5
CVE-2020-4400
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credent…
Verify Gateway
Patch available
MEDIUM 6.5
CVE-2020-4399
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial of service against the server…
Verify Gateway
Patch available
MEDIUM 5.9
CVE-2020-4397
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle…
Verify Gateway
Patch available
MEDIUM 5.5
CVE-2020-4369
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.
Verify Gateway
Patch available