Vulnerability index

Browse CVEs

55 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2026-13094 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi… I Access Client Solutions No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-9762 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. Db2 12.1.5+ Fix from $1,9502026-07-17 CRITICAL 9.8 CVE-2026-10109 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling. Db2 after 12.1.4 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-9072 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i… I after 7.6 Fix from $2,3002026-06-22 HIGH 8.8 CVE-2026-8858 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the We… I after 7.6 Fix from $1,9502026-06-22 CRITICAL 9.0 CVE-2026-9311 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-8855 IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-9170 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation. HTTP Server Mitigation only Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-8633 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se… Websphere Application Server after 9.0.5.27 Fix from $2,3002026-05-26 MEDIUM 6.7 CVE-2025-36014 IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory. Integration Bus after 10.1.0.5 Fix from $1,6002025-07-07 HIGH 7.2 CVE-2025-25021 IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code … Cloud Pak For Security after 1.11.2.0 Fix from $1,9502025-06-03 HIGH 7.8 CVE-2025-0161 IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restri… Security Verify Access after 10.0.0.9 Fix from $1,9502025-02-20 HIGH 8.8 CVE-2024-52899 IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on th… Data Virtualization Manager For Z\/os Mitigation only Fix from $1,9502024-11-26 HIGH 8.8 CVE-2024-38319 IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 2948… Soar after 51.0.2.0 Fix from $1,9502024-06-22 HIGH 7.8 CVE-2023-35897 IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary c… Storage Protect after 8.1.19.0 Fix from $1,9502023-10-06 HIGH 8.8 CVE-2023-27867 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code vi… Db2 Patch available Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-27868 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on… Db2 Patch available Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-27869 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on… Db2 Patch available Fix from $1,9502023-07-10 CRITICAL 9.8 CVE-2023-30990 IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-For… I Patch available Fix from $2,3002023-07-04 CRITICAL 9.8 CVE-2023-27866 IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th… Informix Jdbc Driver 4.50.10+ Fix from $2,3002023-06-28 CRITICAL 9.8 CVE-2023-23477 IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft… Websphere Application Server Mitigation only Fix from $2,3002023-02-03 MEDIUM 6.7 CVE-2021-38967 IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441. Mq Appliance Patch available Fix from $1,6002021-11-30 HIGH 8.8 CVE-2021-29679 IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled inp… Cognos Analytics Patch available Fix from $1,9502021-10-15 CRITICAL 9.8 CVE-2021-29772 IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774. Api Connect after 5.0.8.11 Fix from $2,3002021-08-26 CRITICAL 9.8 CVE-2019-4716 KEVEPSS 86% IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th… Planning Analytics after 2.0.8 Fix from $2,3002019-12-18 MEDIUM 6.2 CVE-2019-4038 IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypass… Security Identity Manager after 7.0.1.10 Fix from $1,6002019-02-04 HIGH 8.8 CVE-2018-1808 IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828. Websphere Commerce after 9.0.0.6 Fix from $1,9502018-11-13 HIGH 7.8 CVE-2018-1792 IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that cou… Websphere Mq after 9.0.5 Fix from $1,9502018-11-13 MEDIUM 5.4 CVE-2017-1753 Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec… Rational Doors Next Generation after 6.0.5 Fix from $1,6002018-08-20 MEDIUM 6.1 CVE-2017-1248 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe… Rational Quality Manager after 6.0.5 Fix from $1,6002018-07-06