Concert Software

Vendor:

First CVE: Mar 6, 2025 · Active for 1 year

19
Total CVEs
More Total CVEs than 95% of tracked products
19.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Concert Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2025
16 months ago
Most Recent CVE
Oct 28, 2025
272 days ago

CVE Severity & Scoring

Concert Software19 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (84.2%)
High3 (15.8%)
Unknown0 (0.0%)
User Interaction
None16 (84.2%)
Unknown0 (0.0%)
Required3 (15.8%)
Privileges Required
Low4 (21.1%)
High0 (0.0%)
None15 (78.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being lim
Aug 18, 20259.831NONO
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Aug 18, 20257.526NONO
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Sep 8, 20257.525NONO
IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound comm
Aug 18, 20257.525NONO
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource
Aug 18, 20257.525NONO
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.
Aug 18, 20257.525NONO
IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Sep 1, 20257.524NONO
IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Mar 6, 20257.522NONO
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An
Sep 1, 20255.921NONO
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI t
Sep 1, 20256.121NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Concert Software

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.0.517.50.4%00