Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-31913

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This v…

Fix: after 6.2.0.2
Fix from $1,600 2025-01-06
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-20553

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 6.1.1.0
Fix from $1,600 2024-12-19
Cognos Analytics MEDIUM 6.1
CVE-2024-25042

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker c…

Fix: after 12.0.3
Fix from $1,600 2024-12-18
Cognos Analytics MEDIUM 6.1
CVE-2024-41752

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML c…

Fix: after 12.0.3
Fix from $1,600 2024-12-18
Carbon Charts MEDIUM 5.4
CVE-2024-47117

IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user…

Fix: 1.13.17+
Fix from $1,600 2024-12-10
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2024-47107

IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-12-07
Jazz Foundation MEDIUM 6.1
CVE-2023-45181

IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Fix: 7.0.3+
Fix from $1,600 2024-11-25
Concert MEDIUM 6.1
CVE-2024-41785

IBM Concert Software 1.0.0 through 1.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitr…

Mitigation only
Fix from $1,600 2024-11-15
Maximo Asset Management MEDIUM 5.4
CVE-2024-45088

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2024-11-11
Maximo Application Suite MEDIUM 5.4
CVE-2024-35146

IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unaut…

Mitigation only
Fix from $1,600 2024-11-06
Cics Tx MEDIUM 6.1
CVE-2024-41745

IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-11-01
Security Directory Integrator MEDIUM 5.4
CVE-2024-28772

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulner…

Mitigation only
Fix from $1,600 2024-07-25
Rational Clearquest MEDIUM 5.4
CVE-2024-28796

IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Fix: 9.1.0.7+
Fix from $1,600 2024-07-17
Datacap MEDIUM 5.4
CVE-2024-39735

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to…

Mitigation only
Fix from $1,600 2024-07-15
Datacap MEDIUM 5.4
CVE-2024-39728

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2024-07-15
Infosphere Information Server MEDIUM 5.4
CVE-2024-40690

IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-07-12
Security Qradar Edr MEDIUM 5.4
CVE-2023-35006

IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be execute…

Mitigation only
Fix from $1,600 2024-07-10
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-37528

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2,…

Fix: after 20.0.3
Fix from $1,600 2024-07-08
Infosphere Information Server MEDIUM 5.4
CVE-2023-50964

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28794

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28797

IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 6.1
CVE-2024-28798

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2024-06-30
Infosphere Information Server MEDIUM 5.4
CVE-2024-28795

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-06-30
Cognos Analytics MEDIUM 5.4
CVE-2024-25041

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A re…

Fix: after 12.0.2
Fix from $1,600 2024-06-28
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-42014

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticate…

Fix: after 6.2.0.2
Fix from $1,600 2024-06-27
Planning Analytics Local MEDIUM 5.4
CVE-2024-31889

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31907

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2024-05-31
Planning Analytics Local MEDIUM 5.4
CVE-2024-31908

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Mitigation only
Fix from $1,600 2024-05-31
Aspera Console MEDIUM 5.4
CVE-2022-43384

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 3.4.2
Fix from $1,600 2024-05-30
Aspera Console MEDIUM 5.4
CVE-2022-43575

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 3.4.2
Fix from $1,600 2024-05-30