Vulnerability index

Browse CVEs

58 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
I HIGH 7.5
CVE-2026-17199

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.5
CVE-2026-17271

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.

Fix: after 7.6
Fix from $4,900 2026-08-12
Datapower Gateway HIGH 7.5
CVE-2026-12733

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

Fix: 10.5.0.22 / 10.6.0.10+
Fix from $1,950 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-11897

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted requ…

Fix: 26.0.0.8+
Fix from $1,950 2026-07-30
Db2 MEDIUM 6.5
CVE-2024-54178

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denia…

Fix: 5.4+
Fix from $1,600 2026-06-22
Db2 MEDIUM 5.5
CVE-2026-6053

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partit…

Fix: after 12.1.4
Fix from $1,600 2026-05-27
Db2 HIGH 7.5
CVE-2026-1718

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transact…

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Db2 MEDIUM 6.5
CVE-2025-36122

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user …

Fix: after 12.1.3
Fix from $1,600 2026-04-30
Aspera Shares MEDIUM 6.5
CVE-2025-66487

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in e…

Fix: 1.11.1+
Fix from $1,600 2026-04-01
I HIGH 7.5
CVE-2026-1376

IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

Mitigation only
Fix from $1,950 2026-03-17
Db2 MEDIUM 6.5
CVE-2025-36387

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when…

Fix: after 11.5.9
Fix from $1,600 2026-01-30
Db2 HIGH 7.5
CVE-2025-36070

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap…

Fix: after 12.1.3
Fix from $1,950 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36098

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a de…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 5.5
CVE-2025-36123

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of s…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-2668

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when a…

Fix: after 11.5.9
Fix from $1,600 2026-01-30
Watsonx.data MEDIUM 6.5
CVE-2025-36140

IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation o…

Fix: 2.2.2+
Fix from $1,600 2025-12-08
Db2 MEDIUM 5.5
CVE-2025-36136

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause …

Fix: after 12.1.3
Fix from $1,600 2025-11-07
Db2 MEDIUM 6.5
CVE-2025-36008

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.3
Fix from $1,600 2025-11-07
Powervm Hypervisor MEDIUM 5.1
CVE-2025-36035

IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to…

Mitigation only
Fix from $1,600 2025-09-14
Security Verify Information Queue MEDIUM 6.5
CVE-2024-45669

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handl…

Fix: 10.0.11+
Fix from $1,600 2025-09-10
Websphere Application Server HIGH 7.5
CVE-2025-36047

IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted reques…

Fix: 25.0.0.9+
Fix from $1,950 2025-08-14
Infosphere Information Server HIGH 7.5
CVE-2025-3221

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation…

Fix: after 11.7.1.6
Fix from $1,950 2025-06-21
Cognos Analytics HIGH 7.5
CVE-2025-25032

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a …

Fix: after 12.0.4
Fix from $1,950 2025-06-11
Db2 MEDIUM 6.5
CVE-2025-3050

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user t…

Fix: after 12.1.1
Fix from $1,600 2025-05-29
4769 Developers Toolkit HIGH 7.5
CVE-2025-3632

IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due…

Fix: 7.5.62+
Fix from $1,950 2025-05-12
Db2 MEDIUM 6.5
CVE-2025-1000

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user…

Fix: after 12.1.1
Fix from $1,600 2025-05-05
Db2 MEDIUM 6.5
CVE-2025-0915

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations c…

Fix: after 12.1.1
Fix from $1,600 2025-05-05
Qradar Wincollect MEDIUM 6.5
CVE-2024-51461

IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that coul…

Fix: 10.1.14+
Fix from $1,600 2025-04-11
Aspera Shares MEDIUM 6.5
CVE-2024-38316

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result …

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Txseries For Multiplatforms HIGH 7.5
CVE-2024-41742

IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operation…

Mitigation only
Fix from $1,950 2025-01-19