Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-17083 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. I No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-17111 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta… I No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-17276 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high… I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-16956 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements… Db2 Mirror For I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-17218 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-16860 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element. I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-18847 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i. I No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-17617 IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif… Application Gateway Operator after 26.6.0 Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-8400 IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I… Websphere Application Server No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-10025 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne… Qradar Security Information And Event Manager No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-12943 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)… Hardware Management Console 10.3.1064.1 / 11.1.1112.1+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12118 IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d… Webmethods Integration No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-15435 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-14522 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30 CRITICAL 9.3 CVE-2026-11707 IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the … Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-14529 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-14974 IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14976 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e… Websphere Application Server 26.0.0.9+ Fix from $2,3002026-07-28 CRITICAL 9.3 CVE-2026-14973 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. Aspera after 1.0.19 Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14446 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. Websphere Application Server 8.5.5.30 / 9.0.5.28+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14512 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-16184 IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14501 IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to th… Agentics 1.1.3+ Fix from $2,3002026-07-17 CRITICAL 9.3 CVE-2026-15091 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur… Engineering Ai Hub 1.3.0+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-13473 IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer o… Storage Protect 8.2.1.2+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9074 IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset… Api Connect 10.0.8.10 / 12.1.1.0+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-3144 IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application befor… Api Connect 12.1.1.0+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-11541 IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application S… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-13773 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.… Websphere Extreme Scale after 8.6.1.6 Fix from $2,3002026-06-30 CRITICAL 9.9 CVE-2026-13772 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and in… Websphere Extreme Scale after 8.6.1.6 Fix from $2,3002026-06-30