vciy

CVEs we hold for Bmc

Records whose assigning authority named Bmc as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-10540Weak password hash protection in Control-M/Entreprise ManagerBMC Control-M/Enterprise Manager
CVE-2026-10539Unauthenticated command injection in Control-M/Server communication commandBMC Control-M/Server
CVE-2026-10538Improper deserialization handling in Control-M ComponentsBMC Control-M/Server
CVE-2025-71260BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEBMC Software, Inc. FootPrints
CVE-2025-71259BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSSBMC Software, Inc. FootPrints
CVE-2025-71258BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWebBMC Software, Inc. FootPrints
CVE-2025-71257BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication BypassBMC Software, Inc. FootPrints
CVE-2025-55118BMC Control-M/Agent memory corruption in SSL/TLS communicationBMC Control-M/Agent
CVE-2025-55117BMC Control-M/Agent buffer overflow in SSL/TLS communicationBMC Control-M/Agent
CVE-2025-55116BMC Control-M/Agent buffer overflow local privilege escalationBMC Control-M/Agent
CVE-2025-55115BMC Control-M/Agent path traversal local privilege escalationBMC Control-M/Agent
CVE-2025-55114BMC Control-M/Agent improper IP address filtering orderBMC Control-M/Agent
CVE-2025-55113BMC Control-M/Agent unescaped NULL byte in access control list checksBMC Control-M/Agent
CVE-2025-55112BMC Control-M/Agent hardcoded Blowfish keysBMC Control-M/Agent
CVE-2025-55111BMC Control-M/Agent insecure default file permissionsBMC Control-M/Agent
CVE-2025-55110BMC Control-M/Agent hardcoded default keystore passwordBMC Control-M/Agent
CVE-2025-55109BMC Control-M/Agent default SSL/TLS configuration authenticated bypassBMC Control-M/Agent
CVE-2025-55108BMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code…BMC Control-M/Agent
CVE-2025-48709BMC Control-M/Server cleartext database credentials in process lists and logsBMC Control-M/Server
CVE-2024-58298Compuware iStrobe Web 20.13 Pre-Auth Remote Code Execution via File UploadBMC Software Compuware iStrobe Web
CVE-2024-1606HTML injection in BMC Control-MBMC Control-M
CVE-2024-1605DLL side-loading in BMC Control-MBMC Control-M
CVE-2024-1604Incorrect authorization in BMC Control-MBMC Control-M
CVE-2022-35865no title heldBMC Track-It!
CVE-2022-35864no title heldBMC Track-It!
CVE-2022-24047no title heldBMC Track-It!
CVE-2021-35002BMC Track-It! Unrestricted File Upload Remote Code Execution VulnerabilityBMC Track-It!
CVE-2021-35001BMC Track-It! GetData Missing Authorization Information Disclosure VulnerabilityBMC Track-It!
CVE-2017-12701no title heldBMC Medical Luna CPAP Machine

29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.