Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-17083
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
I
No fix yet
CRITICAL 9.8
CVE-2026-17111
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…
I
No fix yet
CRITICAL 9.9
CVE-2026-17276
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high…
I
after 7.6
CRITICAL 9.8
CVE-2026-16956
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…
Db2 Mirror For I
after 7.6
CRITICAL 9.8
CVE-2026-17218
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
I
after 7.6
CRITICAL 9.9
CVE-2026-16860
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
I
after 7.6
CRITICAL 9.8
CVE-2026-18847
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
I
No fix yet
CRITICAL 9.8
CVE-2026-17617
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…
Application Gateway Operator
after 26.6.0
CRITICAL 9.8
CVE-2026-8400
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I…
Websphere Application Server
No fix yet
CRITICAL 9.8
CVE-2026-10025
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…
Qradar Security Information And Event Manager
No fix yet
CRITICAL 9.8
CVE-2026-12943
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…
Hardware Management Console
10.3.1064.1 / 11.1.1112.1+
CRITICAL 9.8
CVE-2026-12118
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…
Webmethods Integration
No fix yet
CRITICAL 9.8
CVE-2026-15435
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
CRITICAL 9.8
CVE-2026-14522
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
CRITICAL 9.3
CVE-2026-11707
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the …
Websphere Application Server
8.5.5.30 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14529
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14974
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14976
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…
Websphere Application Server
26.0.0.9+
CRITICAL 9.3
CVE-2026-14973
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
Aspera
after 1.0.19
CRITICAL 9.8
CVE-2026-14446
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Websphere Application Server
8.5.5.30 / 9.0.5.28+
CRITICAL 9.8
CVE-2026-14512
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-16184
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14501
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to th…
Agentics
1.1.3+
CRITICAL 9.3
CVE-2026-15091
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…
Engineering Ai Hub
1.3.0+
CRITICAL 9.8
CVE-2026-13473
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer o…
Storage Protect
8.2.1.2+
CRITICAL 9.8
CVE-2026-9074
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…
Api Connect
10.0.8.10 / 12.1.1.0+
CRITICAL 9.8
CVE-2026-3144
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application befor…
Api Connect
12.1.1.0+
CRITICAL 9.8
CVE-2026-11541
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application S…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 10.0
CVE-2026-13773
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…
Websphere Extreme Scale
after 8.6.1.6
CRITICAL 9.9
CVE-2026-13772
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and in…
Websphere Extreme Scale
after 8.6.1.6