Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

I CRITICAL 9.8
CVE-2026-17083

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

No fix yet
Fix from $2,300 2026-08-12
I CRITICAL 9.8
CVE-2026-17111

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…

No fix yet
Fix from $2,300 2026-08-12
I CRITICAL 9.9
CVE-2026-17276

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high…

Fix: after 7.6
Fix from $2,300 2026-08-12
Db2 Mirror For I CRITICAL 9.8
CVE-2026-16956

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…

Fix: after 7.6
Fix from $2,300 2026-08-12
I CRITICAL 9.8
CVE-2026-17218

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

Fix: after 7.6
Fix from $2,300 2026-08-12
I CRITICAL 9.9
CVE-2026-16860

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

Fix: after 7.6
Fix from $2,300 2026-08-12
I CRITICAL 9.8
CVE-2026-18847

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.

No fix yet
Fix from $2,300 2026-08-12
Application Gateway Operator CRITICAL 9.8
CVE-2026-17617

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…

Fix: after 26.6.0
Fix from $2,300 2026-08-05
Websphere Application Server CRITICAL 9.8
CVE-2026-8400

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I…

No fix yet
Fix from $2,300 2026-08-05
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…

No fix yet
Fix from $2,300 2026-08-05
Hardware Management Console CRITICAL 9.8
CVE-2026-12943

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…

Fix: 10.3.1064.1 / 11.1.1112.1+
Fix from $2,300 2026-07-30
Webmethods Integration CRITICAL 9.8
CVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…

No fix yet
Fix from $2,300 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-15435

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11707

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-07-30
Websphere Application Server CRITICAL 9.8
CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-29
Websphere Application Server CRITICAL 9.8
CVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…

Fix: 26.0.0.9+
Fix from $2,300 2026-07-28
Aspera CRITICAL 9.3
CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Fix: after 1.0.19
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14446

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Fix: 8.5.5.30 / 9.0.5.28+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Agentics CRITICAL 9.8
CVE-2026-14501

IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to th…

Fix: 1.1.3+
Fix from $2,300 2026-07-17
Engineering Ai Hub CRITICAL 9.3
CVE-2026-15091

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…

Fix: 1.3.0+
Fix from $2,300 2026-07-17
Storage Protect CRITICAL 9.8
CVE-2026-13473

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer o…

Fix: 8.2.1.2+
Fix from $2,300 2026-07-17
Api Connect CRITICAL 9.8
CVE-2026-9074

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…

Fix: 10.0.8.10 / 12.1.1.0+
Fix from $2,300 2026-07-08
Api Connect CRITICAL 9.8
CVE-2026-3144

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application befor…

Fix: 12.1.1.0+
Fix from $2,300 2026-07-08
Websphere Application Server CRITICAL 9.8
CVE-2026-11541

IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application S…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Extreme Scale CRITICAL 10.0
CVE-2026-13773

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30
Websphere Extreme Scale CRITICAL 9.9
CVE-2026-13772

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and in…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30