Vulnerability index

Browse CVEs

91 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2026-16695 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of speci… I Access Client Solutions No fix yet Fix from $4,9002026-08-12 HIGH 7.3 CVE-2026-13476 IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges … Informix Dynamic Server No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-17417 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metach… I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-17642 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elem… I No fix yet Fix from $4,9002026-08-12 HIGH 7.2 CVE-2026-12005 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access No fix yet Fix from $4,9002026-08-12 HIGH 8.3 CVE-2026-18235 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input val… I after 7.6 Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2026-17420 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special el… I after 7.6 Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-17248 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special eleme… I after 7.6 Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-16956 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements… Db2 Mirror For I after 7.6 Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-16856 IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command. I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-16906 IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization … I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-18683 IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user… I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-13477 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c… Qradar Security Information And Event Manager No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-12943 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)… Hardware Management Console 10.3.1064.1 / 11.1.1112.1+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-14522 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30 HIGH 7.2 CVE-2026-14958 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. Aspera Faspex 5.0.16+ Fix from $1,9502026-07-28 HIGH 7.2 CVE-2026-14959 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. Aspera Faspex 5.0.16+ Fix from $1,9502026-07-28 MEDIUM 5.4 CVE-2026-15069 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input… Engineering Ai Hub 1.3.0+ Fix from $1,6002026-07-17 CRITICAL 9.8 CVE-2026-5935 IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma… Total Storage Service Console Mitigation only Fix from $2,3002026-04-23 HIGH 7.3 CVE-2026-1345 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $1,9502026-04-01 HIGH 8.8 CVE-2025-13687 IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o… Datastage On Cloud Pak For Data 5.3.1+ Fix from $1,9502026-03-03 HIGH 8.8 CVE-2025-13688 IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o… Datastage On Cloud Pak For Data 5.3.1+ Fix from $1,9502026-03-03 HIGH 8.8 CVE-2025-13686 IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges o… Datastage On Cloud Pak For Data 5.3.1+ Fix from $1,9502026-03-03 HIGH 8.8 CVE-2025-13481 IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system du… Aspera Orchestrator 4.1.1+ Fix from $1,9502025-12-11 HIGH 7.3 CVE-2025-36354 IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthent… Security Verify Access 10.0.9.0 / 11.0.1.0+ Fix from $1,9502025-10-06 HIGH 8.8 CVE-2025-36245 IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges … Infosphere Information Server after 11.7.1.6 Fix from $1,9502025-09-29 HIGH 7.2 CVE-2025-36143 IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation … Watsonx.data Mitigation only Fix from $1,9502025-09-18 HIGH 7.2 CVE-2024-55904 IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, a… Devops Deploy 7.0.5.26 / 7.1.2.22+ Fix from $1,9502025-02-14 HIGH 8.8 CVE-2024-51450 IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin… Security Verify Directory after 10.0.3 Fix from $1,9502025-02-06 HIGH 7.2 CVE-2024-54181 IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using sp… Websphere Automation Mitigation only Fix from $1,9502024-12-30