Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Aspera Faspex MEDIUM 5.4
CVE-2025-36226

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Fix: 5.0.15+
Fix from $1,600 2026-03-10
Infosphere Data Architect MEDIUM 6.1
CVE-2025-36173

Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

No fix yet
Fix from $1,600 2026-03-10
Concert MEDIUM 6.1
CVE-2025-36019

IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to e…

Fix: 2.2.0+
Fix from $1,600 2026-02-17
Engineering Lifecycle Management MEDIUM 5.4
CVE-2025-36033

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 I…

Mitigation only
Fix from $1,600 2026-02-03
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2025-36436

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim…

Mitigation only
Fix from $1,600 2026-02-02
Applinx MEDIUM 6.4
CVE-2025-36408

IBM ApplinX 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2026-01-20
Applinx MEDIUM 5.4
CVE-2025-36409

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2026-01-20
Sterling Connect\ MEDIUM 6.1
CVE-2025-36066

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerab…

Fix: 5.2.0.13+
Fix from $1,600 2026-01-20
Sterling Connect\ MEDIUM 5.4
CVE-2025-36113

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerab…

Fix: 5.2.0.13+
Fix from $1,600 2026-01-20
Application Gateway MEDIUM 5.4
CVE-2025-36396

IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…

Fix: after 25.09
Fix from $1,600 2026-01-20
Websphere Application Server MEDIUM 5.4
CVE-2025-12635

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scriptin…

Fix: 8.5.5.29 / 9.0.5.27+
Fix from $1,600 2025-12-08
Concert MEDIUM 6.1
CVE-2025-36153

IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaS…

Fix: 2.1.0+
Fix from $1,600 2025-11-20
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-36135

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, …

Fix: after 6.2.0.5
Fix from $1,600 2025-11-07
Business Automation Workflow MEDIUM 6.1
CVE-2025-36054

IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Au…

Patch available
Fix from $1,600 2025-11-06
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2025-36172

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix…

Mitigation only
Fix from $1,600 2025-11-03
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-36138

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-10-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-36170

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-10-27
Jazz Foundation MEDIUM 5.4
CVE-2025-1826

IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) i…

Patch available
Fix from $1,600 2025-10-07
Planning Analytics Local MEDIUM 5.4
CVE-2025-36132

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authe…

Fix: after 2.1.13
Fix from $1,600 2025-09-30
License Metric Tool MEDIUM 5.4
CVE-2025-36352

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed a…

Fix: 9.2.41+
Fix from $1,600 2025-09-29
Storage Ts4500 Library Firmware MEDIUM 6.1
CVE-2025-36239

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to em…

Mitigation only
Fix from $1,600 2025-09-27
Watson Studio MEDIUM 5.4
CVE-2025-33116

IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to e…

Fix: 5.2.1+
Fix from $1,600 2025-09-25
Copy Services Manager MEDIUM 6.1
CVE-2025-36248

IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScri…

Fix: 6.3.14+
Fix from $1,600 2025-09-19
Hardware Management Console MEDIUM 5.4
CVE-2025-36125

IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-09-09
Jazz Foundation MEDIUM 6.1
CVE-2024-43184

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. …

Patch available
Fix from $1,600 2025-09-04
Concert MEDIUM 5.4
CVE-2025-33082

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Concert MEDIUM 5.4
CVE-2025-33083

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Concert MEDIUM 6.1
CVE-2025-0656

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary …

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Watson Assistant For Ibm Cloud Pak For Data MEDIUM 5.4
CVE-2024-49790

IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed a…

Fix: 5.2.0+
Fix from $1,600 2025-08-28
Qradar Incident Forensics MEDIUM 5.4
CVE-2025-36042

IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…

Mitigation only
Fix from $1,600 2025-08-22