Vulnerability index

Browse CVEs

81 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
I HIGH 7.8
CVE-2026-18511

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, …

No fix yet
Fix from $4,900 2026-08-13
I HIGH 8.8
CVE-2026-17223

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.5
CVE-2026-18846

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the ho…

No fix yet
Fix from $4,900 2026-08-13
I CRITICAL 9.8
CVE-2026-17206

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

No fix yet
Fix from $5,750 2026-08-13
I HIGH 8.8
CVE-2026-16975

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 8.8
CVE-2026-17029

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.5
CVE-2026-16982

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.5
CVE-2026-16887

IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

No fix yet
Fix from $4,900 2026-08-13
I MEDIUM 6.5
CVE-2026-16929

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow.

No fix yet
Fix from $4,000 2026-08-13
I CRITICAL 9.1
CVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b…

No fix yet
Fix from $5,750 2026-08-13
I MEDIUM 6.5
CVE-2026-16692

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

No fix yet
Fix from $4,000 2026-08-13
I CRITICAL 9.8
CVE-2026-17083

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

No fix yet
Fix from $5,750 2026-08-12
I CRITICAL 9.8
CVE-2026-17218

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 7.6
CVE-2026-16907

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

Fix: after 7.6
Fix from $4,900 2026-08-12
Websphere Application Server HIGH 7.5
CVE-2026-15057

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

Fix: 26.0.0.8+
Fix from $1,950 2026-07-28
Db2 High Performance Unload Load MEDIUM 6.5
CVE-2025-33133

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the pro…

Fix: after 6.1.0.0
Fix from $1,600 2025-10-28
Db2 HIGH 7.5
CVE-2024-49350

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnera…

Fix: after 12.1.1
Fix from $1,950 2025-05-29
Semeru Runtime HIGH 7.5
CVE-2025-2900

IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable …

Fix: after 21.0.6.0
Fix from $1,950 2025-05-14
Cics Tx HIGH 7.8
CVE-2025-1330

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to …

Mitigation only
Fix from $1,950 2025-05-08
Cics Tx HIGH 7.8
CVE-2025-1329

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to h…

Mitigation only
Fix from $1,950 2025-05-08
Common Cryptographic Architecture MEDIUM 6.5
CVE-2024-49823

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Mo…

Fix: 7.5.52+
Fix from $1,600 2025-03-11
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23622

A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vu…

Fix: after 4.2
Fix from $2,300 2024-01-26
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28526

IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a…

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28527

IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local…

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server HIGH 7.8
CVE-2023-28523

IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an…

Mitigation only
Fix from $1,950 2023-12-09
Db2 MEDIUM 6.7
CVE-2023-35012

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow,…

Mitigation only
Fix from $1,600 2023-07-17
3957 Vec Firmware HIGH 8.8
CVE-2023-24958

A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submi…

Fix: 8.51.2.12 / 8.52.102.13+
Fix from $1,950 2023-05-04
Security Verify Password Synchronization MEDIUM 6.5
CVE-2022-22312

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused…

Fix: 10.0.4+
Fix from $1,600 2022-04-27
Security Verify Password Synchronization MEDIUM 6.5
CVE-2022-22323

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused…

Fix: 10.0.4+
Fix from $1,600 2022-04-27
Ibm Rational Lifecycle Integration Adapter For Windchill MEDIUM 5.3
CVE-2021-34587

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack va…

Fix: 5.11.2 / 5.12.5+
Fix from $1,600 2022-04-27