Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Api Connect CRITICAL 9.8
CVE-2025-13915EPSS 9%

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acce…

Fix: after 10.0.8.5
Fix from $2,300 2025-12-26
Vios CRITICAL 9.8
CVE-2025-36251

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due …

Mitigation only
Fix from $2,300 2025-11-13
Vios CRITICAL 9.8
CVE-2025-36250

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute a…

Mitigation only
Fix from $2,300 2025-11-13
Vios CRITICAL 9.1
CVE-2025-36236

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse …

Mitigation only
Fix from $2,300 2025-11-13
Infosphere Information Server CRITICAL 9.1
CVE-2025-12531

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. …

Fix: after 11.7.1.6
Fix from $2,300 2025-11-03
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3356

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $2,300 2025-10-30
Maximo Application Suite CRITICAL 9.8
CVE-2025-36386

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain …

Fix: after 9.1.4
Fix from $2,300 2025-10-28
Security Verify Access CRITICAL 9.8
CVE-2025-36087

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain confi…

Fix: after 10.0.9
Fix from $2,300 2025-10-13
Security Verify Access CRITICAL 9.3
CVE-2025-36356

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authen…

Fix: 10.0.9.0 / 11.0.1.0+
Fix from $2,300 2025-10-06
Transformation Extender Advanced CRITICAL 9.8
CVE-2023-49886

IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserializa…

Mitigation only
Fix from $2,300 2025-10-06
Storage Fusion CRITICAL 9.8
CVE-2025-36222

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default confi…

Fix: 2.11.0+
Fix from $2,300 2025-09-11
Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data CRITICAL 9.8
CVE-2025-0165

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker …

Fix: 5.2.0.1+
Fix from $2,300 2025-08-30
Cognos Command Center CRITICAL 9.3
CVE-2025-2697

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…

Mitigation only
Fix from $2,300 2025-08-26
Jazz Foundation CRITICAL 9.1
CVE-2025-36157

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to upda…

Patch available
Fix from $2,300 2025-08-24
Concert CRITICAL 9.8
CVE-2025-27909

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as t…

Fix: 2.0.0+
Fix from $2,300 2025-08-18
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3320

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…

Mitigation only
Fix from $2,300 2025-08-06
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3354

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…

Mitigation only
Fix from $2,300 2025-08-06
Analytics Content Hub CRITICAL 9.8
CVE-2024-39752

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore …

Fix: 2.4+
Fix from $2,300 2025-07-10
Analytics Content Hub CRITICAL 9.8
CVE-2024-38327

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map wh…

Fix: 2.4+
Fix from $2,300 2025-07-10
Websphere Application Server CRITICAL 9.8
CVE-2025-36038EPSS 9%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence …

Fix: 8.5.5.28 / 9.0.5.25+
Fix from $2,300 2025-06-25
Spectrum Protect Server CRITICAL 9.8
CVE-2025-3319

IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result …

Fix: after 8.1.26
Fix from $2,300 2025-06-20
Qradar Security Information And Event Manager CRITICAL 9.1
CVE-2025-33117

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a mal…

Mitigation only
Fix from $2,300 2025-06-19
Mq Operator CRITICAL 9.8
CVE-2025-36041

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ O…

Fix: after 3.5.3
Fix from $2,300 2025-06-15
Security Verify Governance CRITICAL 9.8
CVE-2024-22330

IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to com…

Mitigation only
Fix from $2,300 2025-06-06
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3357

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of a…

Mitigation only
Fix from $2,300 2025-05-28
I CRITICAL 9.8
CVE-2025-2947

IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command …

Mitigation only
Fix from $2,300 2025-04-17
Aix CRITICAL 10.0
CVE-2024-56346

IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

Mitigation only
Fix from $2,300 2025-03-18
Aix CRITICAL 9.6
CVE-2024-56347

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process c…

Mitigation only
Fix from $2,300 2025-03-18
Qiskit CRITICAL 9.8
CVE-2025-2000

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma…

Fix: 1.4.2+
Fix from $2,300 2025-03-14
Storage Virtualize CRITICAL 9.8
CVE-2025-0160

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…

Fix: 8.5.0.14 / 8.6.0.6+
Fix from $2,300 2025-02-28