Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
I MEDIUM 5.4
CVE-2026-18099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-cont…

No fix yet
Fix from $4,000 2026-08-12
I MEDIUM 5.4
CVE-2026-16694

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

No fix yet
Fix from $4,000 2026-08-12
Engineering Requirements Management Doors Web Access MEDIUM 6.1
CVE-2025-0152

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site…

Fix: after 9.7.2.11
Fix from $1,600 2026-07-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11707

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the …

Mitigation only
Fix from $2,300 2026-07-30
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-36431

IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. …

No fix yet
Fix from $1,600 2026-07-30
Websphere Application Server MEDIUM 5.4
CVE-2026-11383

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative C…

No fix yet
Fix from $1,600 2026-07-30
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-36298

IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM St…

No fix yet
Fix from $1,600 2026-07-30
Websphere Application Server MEDIUM 6.1
CVE-2026-14515

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,600 2026-07-28
Engineering Ai Hub CRITICAL 9.3
CVE-2026-15091

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…

Fix: 1.3.0+
Fix from $2,300 2026-07-17
Websphere Application Server MEDIUM 6.1
CVE-2026-11594

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 6.4
CVE-2025-36320

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated use…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.4
CVE-2025-36323

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to em…

Mitigation only
Fix from $1,600 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Datacap MEDIUM 6.1
CVE-2026-8059

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allow…

Mitigation only
Fix from $1,600 2026-06-22
Tririga Application Platform MEDIUM 5.4
CVE-2026-11372

IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed …

Mitigation only
Fix from $1,600 2026-06-22
Engineering Workflow Management MEDIUM 5.4
CVE-2025-33128

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. T…

Mitigation only
Fix from $1,600 2026-06-22
Cognos Analytics HIGH 8.2
CVE-2025-3633

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2026-05-27
Financial Transaction Manager For Multiplatform MEDIUM 6.1
CVE-2025-36148

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerabl…

Fix: 3.2.4.16+
Fix from $1,600 2026-05-26
Cognos Analytics HIGH 7.6
CVE-2025-36126

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) …

Fix: 12.1.2+
Fix from $1,950 2026-05-26
Content Navigator MEDIUM 5.4
CVE-2026-1243

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr…

Mitigation only
Fix from $1,600 2026-04-02
Aspera Shares MEDIUM 5.4
CVE-2025-66484

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Fix: 1.11.1+
Fix from $1,600 2026-04-01
Security Verify Access MEDIUM 5.4
CVE-2026-4364

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,600 2026-04-01
Infosphere Information Server MEDIUM 5.4
CVE-2026-2483

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-15051

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Mitigation only
Fix from $1,600 2026-03-19
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2026-1276

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed…

Mitigation only
Fix from $1,600 2026-03-19
Sterling B2b Integrator MEDIUM 5.4
CVE-2026-0835

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-14504

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2025-13702

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,600 2026-03-13
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-40693

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vul…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13