Latest CVE Feed
-
5.5
MEDIUMCVE-2024-47102
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.... Read more
- Published: Dec. 25, 2024
- Modified: Jul. 25, 2025
-
5.5
MEDIUMCVE-2024-52906
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.... Read more
- Published: Dec. 25, 2024
- Modified: Jul. 25, 2025
-
3.7
LOWCVE-2023-33855
Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack.... Read more
- Published: Mar. 26, 2024
- Modified: Jul. 25, 2025
-
6.4
MEDIUMCVE-2024-47107
IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
- Published: Dec. 07, 2024
- Modified: Jul. 25, 2025
-
7.5
HIGHCVE-2023-47150
IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602.... Read more
- Published: Mar. 26, 2024
- Modified: Jul. 25, 2025
-
6.8
MEDIUMCVE-2024-27269
IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.... Read more
- Published: May. 14, 2024
- Modified: Jul. 25, 2025
-
7.5
HIGHCVE-2024-31892
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements.... Read more
- Published: Dec. 14, 2024
- Modified: Jul. 25, 2025
-
7.8
HIGHCVE-2024-31891
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host oper... Read more
- Published: Dec. 14, 2024
- Modified: Jul. 25, 2025
-
9.1
CRITICALCVE-2024-38337
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.... Read more
- Published: Jan. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2024-41783
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.... Read more
- Published: Jan. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2023-47160
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or ... Read more
- Published: Feb. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: XML External Entity
-
8.0
HIGHCVE-2024-45084
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.... Read more
- Published: Feb. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-45081
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.... Read more
- Published: Feb. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2024-28780
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more
- Published: Feb. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2024-28777
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting t... Read more
- Published: Feb. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2024-28776
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin... Read more
- Published: Feb. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-50070
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Authenticated OS User privilege with logon to the infrastructure w... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-21162
Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requ... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-47111
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, ... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-47112
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure