Vulnerability index

Browse CVEs

385 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-11714 IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-13449 IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML … Business Automation Manager 9.5.0+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-11546 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-… Websphere Application Server 26.0.0.8+ Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-11708 IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-11712 IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-10109 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling. Db2 after 12.1.4 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-9072 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i… I after 7.6 Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-9006 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-8646 IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request … Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-12628 IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker… Storage Protect 8.2.1.1+ Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-8644 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.0 CVE-2026-9311 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.0 CVE-2026-9319 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-8175 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $2,3002026-05-27 CRITICAL 9.1 CVE-2026-7876 IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage … Aspera High Speed Transfer Server For Cloud Pak For Integration 1.5.20+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2024-40684 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.… Operations Analytics Log Analysis Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-3660 IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul… Engineering Lifecycle Management Mitigation only Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-8855 IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-9170 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation. HTTP Server Mitigation only Fix from $2,3002026-05-26 CRITICAL 9.1 CVE-2026-8856 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-8633 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se… Websphere Application Server after 9.0.5.27 Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2025-36220 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote atta… Cloud Pak For Data System Cyclops 11.3.0.2+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-2311 IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali… I Mitigation only Fix from $2,3002026-04-30 CRITICAL 9.8 CVE-2026-5935 IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma… Total Storage Service Console Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-4101 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2025-14917 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected secu… Websphere Application Server 26.0.0.4+ Fix from $2,3002026-03-25 CRITICAL 9.1 CVE-2026-3856 IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for … Db2 Recovery Expert Patch available Fix from $2,3002026-03-17 CRITICAL 9.8 CVE-2025-14923 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected secu… Websphere Application Server 26.0.0.3+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-33089 IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard … Concert 2.2.0+ Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2025-36418 IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra… Applinx Mitigation only Fix from $2,3002026-01-20