Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.7

    MEDIUM
    CVE-2021-29708

    IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.... Read more

    Affected Products : spectrum_scale
    • EPSS Score: %0.05
    • Published: May. 25, 2021
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2021-29707

    IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.... Read more

    Affected Products : hardware_management_console
    • EPSS Score: %0.04
    • Published: Jul. 19, 2021
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-29706

    IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denial of service. IBM X-Force ID: 200663.... Read more

    Affected Products : aix
    • EPSS Score: %0.04
    • Published: Jun. 17, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29704

    IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more

    • EPSS Score: %0.09
    • Published: Aug. 23, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29703

    Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.... Read more

    Affected Products : linux_kernel aix hp-ux db2 solaris windows
    • EPSS Score: %0.64
    • Published: Jun. 24, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29702

    Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.... Read more

    Affected Products : linux_kernel aix db2 windows
    • EPSS Score: %0.76
    • Published: Jun. 16, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-29701

    IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the sys... Read more

    • EPSS Score: %0.12
    • Published: Jan. 11, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-29700

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks against the system. IBM X-Force ID: 200656.... Read more

    Affected Products : sterling_b2b_integrator
    • EPSS Score: %0.02
    • Published: Oct. 07, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-29699

    IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.... Read more

    • EPSS Score: %0.36
    • Published: Jul. 15, 2021
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2021-29697

    IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to obtain sensitive information through HTTP requests that could be used in further attacks against the system.... Read more

    Affected Products : cloud_pak_for_security
    • EPSS Score: %0.15
    • Published: Aug. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-29696

    IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.... Read more

    Affected Products : cloud_pak_for_security
    • EPSS Score: %0.49
    • Published: Aug. 02, 2021
    • Modified: Nov. 21, 2024
  • 8.5

    HIGH
    CVE-2021-29695

    IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request that would allow them to delete arbitrary files on the system. IBM X-Force ID: 200558.... Read more

    • EPSS Score: %0.65
    • Published: May. 25, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29694

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.... Read more

    Affected Products : linux_kernel spectrum_protect_plus
    • EPSS Score: %0.11
    • Published: Apr. 26, 2021
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2021-29693

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.... Read more

    Affected Products : aix vios
    • EPSS Score: %0.10
    • Published: Jun. 28, 2021
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2021-29692

    IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using ... Read more

    • EPSS Score: %0.18
    • Published: May. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29691

    IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: ... Read more

    • EPSS Score: %0.06
    • Published: May. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-29688

    IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200... Read more

    • EPSS Score: %0.30
    • Published: May. 20, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-29687

    IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018... Read more

    • EPSS Score: %0.19
    • Published: May. 20, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-29686

    IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015... Read more

    • EPSS Score: %0.17
    • Published: May. 20, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-29683

    IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.... Read more

    • EPSS Score: %0.09
    • Published: May. 20, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291558 Results