Vulnerability index

Browse CVEs

91 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
I Access Client Solutions HIGH 7.8
CVE-2026-16695

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of speci…

No fix yet
Fix from $4,900 2026-08-12
Informix Dynamic Server HIGH 7.3
CVE-2026-13476

IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-17417

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metach…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-17642

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elem…

No fix yet
Fix from $4,900 2026-08-12
Security Verify Access HIGH 7.2
CVE-2026-12005

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.3
CVE-2026-18235

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input val…

Fix: after 7.6
Fix from $4,900 2026-08-12
I MEDIUM 6.3
CVE-2026-17420

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special el…

Fix: after 7.6
Fix from $4,000 2026-08-12
I MEDIUM 6.5
CVE-2026-17248

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special eleme…

Fix: after 7.6
Fix from $4,000 2026-08-12
Db2 Mirror For I CRITICAL 9.8
CVE-2026-16956

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-16856

IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-16906

IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-18683

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user…

No fix yet
Fix from $4,900 2026-08-12
Qradar Security Information And Event Manager HIGH 8.8
CVE-2026-13477

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c…

No fix yet
Fix from $1,950 2026-08-05
Hardware Management Console CRITICAL 9.8
CVE-2026-12943

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…

Fix: 10.3.1064.1 / 11.1.1112.1+
Fix from $2,300 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
Aspera Faspex HIGH 7.2
CVE-2026-14958

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Aspera Faspex HIGH 7.2
CVE-2026-14959

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

Fix: 5.0.16+
Fix from $1,950 2026-07-28
Engineering Ai Hub MEDIUM 5.4
CVE-2026-15069

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input…

Fix: 1.3.0+
Fix from $1,600 2026-07-17
Total Storage Service Console CRITICAL 9.8
CVE-2026-5935

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma…

Mitigation only
Fix from $2,300 2026-04-23
Security Verify Access HIGH 7.3
CVE-2026-1345

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-01
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13687

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13688

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13686

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o…

Fix: 5.3.1+
Fix from $1,950 2026-03-03
Aspera Orchestrator HIGH 8.8
CVE-2025-13481

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system du…

Fix: 4.1.1+
Fix from $1,950 2025-12-11
Security Verify Access HIGH 7.3
CVE-2025-36354

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthent…

Fix: 10.0.9.0 / 11.0.1.0+
Fix from $1,950 2025-10-06
Infosphere Information Server HIGH 8.8
CVE-2025-36245

IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges …

Fix: after 11.7.1.6
Fix from $1,950 2025-09-29
Watsonx.data HIGH 7.2
CVE-2025-36143

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation …

Mitigation only
Fix from $1,950 2025-09-18
Devops Deploy HIGH 7.2
CVE-2024-55904

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, a…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,950 2025-02-14
Security Verify Directory HIGH 8.8
CVE-2024-51450

IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin…

Fix: after 10.0.3
Fix from $1,950 2025-02-06
Websphere Automation HIGH 7.2
CVE-2024-54181

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using sp…

Mitigation only
Fix from $1,950 2024-12-30