Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2025-33008 IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authent… Sterling B2b Integrator Mitigation only Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-36088 IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an auth… Storage Ts4500 Library Firmware Mitigation only Fix from $1,6002025-08-15 MEDIUM 5.4 CVE-2025-33118 IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed… Qradar Security Information And Event Manager Mitigation only Fix from $1,6002025-08-01 MEDIUM 5.4 CVE-2025-33097 IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary … Qradar Security Information And Event Manager Mitigation only Fix from $1,6002025-07-15 MEDIUM 6.1 CVE-2023-43039 IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Openpages With Watson 9.0.0.3+ Fix from $1,6002025-07-08 MEDIUM 5.4 CVE-2025-2793 IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug… Sterling B2b Integrator 6.1.2.7_1 / 6.2.0.5+ Fix from $1,6002025-07-08 MEDIUM 5.4 CVE-2025-3630 IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 throug… Sterling B2b Integrator 6.1.2.7_1 / 6.2.0.5+ Fix from $1,6002025-07-08 MEDIUM 5.4 CVE-2025-36056 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0… 3957 Ved Firmware after 8.60.0.115 Fix from $1,6002025-07-01 MEDIUM 6.1 CVE-2025-2141 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0… 3948 Vef Firmware after 8.60.0.115 Fix from $1,6002025-07-01 MEDIUM 5.4 CVE-2025-2895 IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote att… Cloud Pak System Mitigation only Fix from $1,6002025-06-30 MEDIUM 5.4 CVE-2024-52900 IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allo… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $1,6002025-06-28 MEDIUM 5.4 CVE-2023-38007 IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems … Cloud Pak System Mitigation only Fix from $1,6002025-06-27 MEDIUM 5.4 CVE-2024-54183 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. … Sterling B2b Integrator 6.1.2.7 / 6.2.0.5+ Fix from $1,6002025-06-18 MEDIUM 5.4 CVE-2025-25044 IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja… Planning Analytics Local Mitigation only Fix from $1,6002025-06-01 MEDIUM 5.4 CVE-2025-2896 IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja… Planning Analytics Local Mitigation only Fix from $1,6002025-06-01 MEDIUM 5.4 CVE-2024-45094 IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to… Hardware Management Console R10.0 Firmware Mitigation only Fix from $1,6002025-05-27 MEDIUM 6.1 CVE-2025-33138 IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would … Aspera Faspex 5.0.12.1+ Fix from $1,6002025-05-22 MEDIUM 6.1 CVE-2024-51475 IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe… Content Navigator Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.5 CVE-2025-3440 IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript co… Security Guardium Mitigation only Fix from $1,6002025-05-15 HIGH 7.6 CVE-2025-33104 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod… Websphere Application Server 8.5.5.28 / 9.0.5.24+ Fix from $1,9502025-05-14 MEDIUM 6.1 CVE-2024-41753 IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnera… Cloud Pak For Business Automation Mitigation only Fix from $1,6002025-05-03 MEDIUM 6.1 CVE-2025-1551 IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauth… Operational Decision Manager Mitigation only Fix from $1,6002025-04-29 MEDIUM 5.4 CVE-2025-2986 IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary Java… Maximo Asset Management Mitigation only Fix from $1,6002025-04-25 MEDIUM 5.4 CVE-2022-43850 IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in … Aspera Console 3.4.5+ Fix from $1,6002025-04-14 MEDIUM 5.4 CVE-2025-3423 IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Java… Aspera Faspex 5.0.12+ Fix from $1,6002025-04-13 MEDIUM 5.4 CVE-2023-42007 IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr… Sterling Control Center Mitigation only Fix from $1,6002025-04-10 MEDIUM 5.4 CVE-2023-33844 IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th… Security Verify Governance Mitigation only Fix from $1,6002025-04-09 MEDIUM 5.4 CVE-2024-56475 IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrar… Txseries For Multiplatforms Mitigation only Fix from $1,6002025-04-02 MEDIUM 5.4 CVE-2024-56341 IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbit… Content Navigator Mitigation only Fix from $1,6002025-04-02 MEDIUM 5.4 CVE-2024-54179 IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vuln… Business Automation Workflow after 24.0.1 Fix from $1,6002025-03-03