Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-33008

IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authent…

Mitigation only
Fix from $1,600 2025-08-19
Storage Ts4500 Library Firmware MEDIUM 5.4
CVE-2025-36088

IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an auth…

Mitigation only
Fix from $1,600 2025-08-15
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-33118

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed…

Mitigation only
Fix from $1,600 2025-08-01
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-33097

IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary …

Mitigation only
Fix from $1,600 2025-07-15
Openpages With Watson MEDIUM 6.1
CVE-2023-43039

IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Fix: 9.0.0.3+
Fix from $1,600 2025-07-08
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-2793

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug…

Fix: 6.1.2.7_1 / 6.2.0.5+
Fix from $1,600 2025-07-08
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-3630

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug…

Fix: 6.1.2.7_1 / 6.2.0.5+
Fix from $1,600 2025-07-08
3957 Ved Firmware MEDIUM 5.4
CVE-2025-36056

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0…

Fix: after 8.60.0.115
Fix from $1,600 2025-07-01
3948 Vef Firmware MEDIUM 6.1
CVE-2025-2141

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0…

Fix: after 8.60.0.115
Fix from $1,600 2025-07-01
Cloud Pak System MEDIUM 5.4
CVE-2025-2895

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote att…

Mitigation only
Fix from $1,600 2025-06-30
Cognos Analytics MEDIUM 5.4
CVE-2024-52900

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allo…

Fix: 11.2.4 / 12.0.4+
Fix from $1,600 2025-06-28
Cloud Pak System MEDIUM 5.4
CVE-2023-38007

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems …

Mitigation only
Fix from $1,600 2025-06-27
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-54183

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. …

Fix: 6.1.2.7 / 6.2.0.5+
Fix from $1,600 2025-06-18
Planning Analytics Local MEDIUM 5.4
CVE-2025-25044

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2025-06-01
Planning Analytics Local MEDIUM 5.4
CVE-2025-2896

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2025-06-01
Hardware Management Console R10.0 Firmware MEDIUM 5.4
CVE-2024-45094

IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to…

Mitigation only
Fix from $1,600 2025-05-27
Aspera Faspex MEDIUM 6.1
CVE-2025-33138

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Fix: 5.0.12.1+
Fix from $1,600 2025-05-22
Content Navigator MEDIUM 6.1
CVE-2024-51475

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…

Mitigation only
Fix from $1,600 2025-05-16
Security Guardium MEDIUM 5.5
CVE-2025-3440

IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2025-05-15
Websphere Application Server HIGH 7.6
CVE-2025-33104

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Fix: 8.5.5.28 / 9.0.5.24+
Fix from $1,950 2025-05-14
Cloud Pak For Business Automation MEDIUM 6.1
CVE-2024-41753

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnera…

Mitigation only
Fix from $1,600 2025-05-03
Operational Decision Manager MEDIUM 6.1
CVE-2025-1551

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauth…

Mitigation only
Fix from $1,600 2025-04-29
Maximo Asset Management MEDIUM 5.4
CVE-2025-2986

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary Java…

Mitigation only
Fix from $1,600 2025-04-25
Aspera Console MEDIUM 5.4
CVE-2022-43850

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: 3.4.5+
Fix from $1,600 2025-04-14
Aspera Faspex MEDIUM 5.4
CVE-2025-3423

IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Java…

Fix: 5.0.12+
Fix from $1,600 2025-04-13
Sterling Control Center MEDIUM 5.4
CVE-2023-42007

IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Mitigation only
Fix from $1,600 2025-04-10
Security Verify Governance MEDIUM 5.4
CVE-2023-33844

IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Mitigation only
Fix from $1,600 2025-04-09
Txseries For Multiplatforms MEDIUM 5.4
CVE-2024-56475

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrar…

Mitigation only
Fix from $1,600 2025-04-02
Content Navigator MEDIUM 5.4
CVE-2024-56341

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbit…

Mitigation only
Fix from $1,600 2025-04-02
Business Automation Workflow MEDIUM 5.4
CVE-2024-54179

IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vuln…

Fix: after 24.0.1
Fix from $1,600 2025-03-03