IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2022-22457 MED 5.3 ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007. 0.1% —
CVE-2022-22456 MED 4.2 ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos 0.3% —
CVE-2022-22454 HIGH 7.8 ibm infosphere_information_server_on_cloud IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. 0.4% —
CVE-2022-22453 HIGH 7.5 ibm security_verify_governance IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. 0.4% —
CVE-2022-22452 HIGH 7.5 ibm security_verify_governance IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918. 1.0% —
CVE-2022-22450 LOW 3.8 ibm security_verify_governance IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. 0.6% —
CVE-2022-22449 MED 5.3 ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM 0.7% —
CVE-2022-22442 MED 6.5 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427." 0.5% —
CVE-2022-22434 MED 4.6 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API request modified to create additional objects. IBM X-Force ID: 224159. 0.2% —
CVE-2022-22433 HIGH 7.5 ibm robotic_process_automation IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS 1.0% —
CVE-2022-22426 LOW 3.3 ibm spectrum_copy_data_management IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain 0.2% —
CVE-2022-22425 CRIT 9.8 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598." 1.2% —
CVE-2022-22424 MED 5.5 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597. 0.2% —
CVE-2022-22423 MED 5.5 ibm common_cryptographic_architecture IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596. 0.3% —
CVE-2022-22415 MED 6.5 ibm robotic_process_automation A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029. 0.8% —
CVE-2022-22414 MED 5.5 ibm robotic_process_automation IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026. 0.2% —
CVE-2022-22412 MED 4.6 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019. 0.3% —
CVE-2022-22411 MED 6.5 ibm spectrum_scale_data_access_services IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016. 0.6% —
CVE-2022-22409 MED 5.3 ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592. 0.8% —
CVE-2022-22405 MED 5.9 ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle 0.5% —
CVE-2022-22402 MED 5.4 ibm aspera_faspex IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IB 0.4% —
CVE-2022-22401 MED 5.9 ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567. 0.5% —
CVE-2022-22394 HIGH 8.8 ibm spectrum_protect The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized ad 2.2% —
CVE-2022-22390 HIGH 7.5 ibm db2 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973. 1.0% —
CVE-2022-22389 MED 6.5 ibm db2 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740. 1.5% —