Vulnerability index

Browse CVEs

114 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2026-16908 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vul… I No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-13105 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. I Access Client Solutions No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-17266 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to … I after 7.6 Fix from $4,0002026-08-12 HIGH 7.1 CVE-2026-17094 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal… I Fix unknown Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-15435 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-14519 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a … App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-15280 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i… Websphere Application Server 26.0.0.9+ Fix from $1,9502026-07-28 CRITICAL 9.3 CVE-2026-14973 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. Aspera after 1.0.19 Fix from $2,3002026-07-28 HIGH 7.5 CVE-2026-11595 IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integra… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-9035 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $1,6002026-05-27 HIGH 7.5 CVE-2026-3366 IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote … Infosphere Optim Test Data Fabrication Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-2606 IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to … Webmethods Api Gateway Mitigation only Fix from $1,6002026-03-03 HIGH 7.6 CVE-2025-14914 IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal se… Websphere Application Server after 26.0.0.1 Fix from $1,9502026-02-02 CRITICAL 9.1 CVE-2025-36236 IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse … Vios Mitigation only Fix from $2,3002025-11-13 CRITICAL 9.8 CVE-2025-3356 IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could … Tivoli Monitoring Mitigation only Fix from $2,3002025-10-30 HIGH 7.5 CVE-2025-3355 IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could … Tivoli Monitoring Mitigation only Fix from $1,9502025-10-30 HIGH 7.5 CVE-2025-36114 IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall… Soar Qradar Plugin App after 5.6.0 Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-33004 IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction. Planning Analytics Local Mitigation only Fix from $1,6002025-06-01 HIGH 7.5 CVE-2024-51453 IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a speci… Sterling Secure Proxy after 6.2.0.1 Fix from $1,9502025-05-28 MEDIUM 5.3 CVE-2024-55913 IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craf… Concert 1.1.0+ Fix from $1,6002025-05-02 MEDIUM 6.5 CVE-2025-0823 IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An atta… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $1,6002025-02-28 MEDIUM 6.5 CVE-2024-54169 IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request … Entirex Mitigation only Fix from $1,6002025-02-27 MEDIUM 6.5 CVE-2024-49780 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges … Openpages With Watson 8.3.0.3 / 9.0.0.5+ Fix from $1,6002025-02-20 MEDIUM 6.5 CVE-2024-56477 IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a … Power Hardware Management Console Mitigation only Fix from $1,6002025-02-14 MEDIUM 6.5 CVE-2025-0799 IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file … App Connect Enterprise after 13.0.2.1 Fix from $1,6002025-02-06 MEDIUM 5.3 CVE-2023-38012 IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories… Cloud Pak System Mitigation only Fix from $1,6002025-01-25 HIGH 7.5 CVE-2024-45652 IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL… Maximo Asset Management Mitigation only Fix from $1,9502025-01-19 HIGH 7.5 CVE-2024-52363 IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte… Infosphere Information Server Mitigation only Fix from $1,9502025-01-17 MEDIUM 6.5 CVE-2024-41765 IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker … Engineering Lifecycle Optimization Publishing Mitigation only Fix from $1,6002025-01-04 HIGH 7.5 CVE-2024-41784 IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An att… Sterling Secure Proxy Mitigation only Fix from $1,9502024-11-15