Vulnerability index

Browse CVEs

2,256 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Vios CRITICAL 9.8
CVE-2025-36251

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due …

Mitigation only
Fix from $2,300 2025-11-13
Vios CRITICAL 9.8
CVE-2025-36250

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute a…

Mitigation only
Fix from $2,300 2025-11-13
Vios CRITICAL 9.1
CVE-2025-36236

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse …

Mitigation only
Fix from $2,300 2025-11-13
Vios HIGH 8.1
CVE-2025-36096

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthoriz…

Mitigation only
Fix from $1,950 2025-11-13
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2025-33119

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.

Mitigation only
Fix from $1,600 2025-11-12
Openpages MEDIUM 6.1
CVE-2025-36223

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an att…

Mitigation only
Fix from $1,600 2025-11-12
Cognos Analytics Certified Containers MEDIUM 5.3
CVE-2025-33150

IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.

Mitigation only
Fix from $1,600 2025-11-10
Openpages MEDIUM 5.4
CVE-2025-33110

IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Mitigation only
Fix from $1,600 2025-11-06
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2025-36172

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix…

Mitigation only
Fix from $1,600 2025-11-03
Cloud Pak For Business Automation HIGH 7.4
CVE-2025-36093

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actio…

Mitigation only
Fix from $1,950 2025-11-03
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2025-36092

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper v…

Mitigation only
Fix from $1,600 2025-11-03
I HIGH 8.8
CVE-2025-36367

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious acto…

Mitigation only
Fix from $1,950 2025-11-01
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3356

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $2,300 2025-10-30
Tivoli Monitoring HIGH 7.5
CVE-2025-3355

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $1,950 2025-10-30
Qradar Security Information And Event Manager HIGH 7.8
CVE-2025-36007

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an …

Mitigation only
Fix from $1,950 2025-10-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-36138

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-10-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-36170

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-10-27
Openpages MEDIUM 5.4
CVE-2025-36121

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, wou…

Mitigation only
Fix from $1,600 2025-10-27
Mq HIGH 7.5
CVE-2025-36128

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read …

Mitigation only
Fix from $1,950 2025-10-16
Content Navigator MEDIUM 5.3
CVE-2025-27906

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Applicati…

Mitigation only
Fix from $1,600 2025-10-14
Engineering Requirements Management Doors Next MEDIUM 6.5
CVE-2025-33096

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading …

Mitigation only
Fix from $1,600 2025-10-12
Engineering Requirements Management Doors Next MEDIUM 5.7
CVE-2025-2140

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of …

Mitigation only
Fix from $1,600 2025-10-12
Infosphere Data Replication Vsam For Z\/os Remote Source HIGH 7.8
CVE-2025-36156

IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. …

Mitigation only
Fix from $1,950 2025-10-07
Transformation Extender Advanced CRITICAL 9.8
CVE-2023-49886

IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserializa…

Mitigation only
Fix from $2,300 2025-10-06
Transformation Extender Advanced HIGH 8.8
CVE-2023-49881

IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another…

Mitigation only
Fix from $1,950 2025-10-01
Transformation Extender Advanced HIGH 7.5
CVE-2023-49883

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for atta…

Mitigation only
Fix from $1,950 2025-10-01
Transformation Extender Advanced MEDIUM 6.2
CVE-2023-50300

IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.

Mitigation only
Fix from $1,600 2025-10-01
Storage Ts4500 Library Firmware MEDIUM 6.1
CVE-2025-36239

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to em…

Mitigation only
Fix from $1,600 2025-09-27
Storage Ts4500 Library Firmware HIGH 8.8
CVE-2024-43192

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Mitigation only
Fix from $1,950 2025-09-27
Watsonx.data MEDIUM 5.5
CVE-2025-36144

IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

Mitigation only
Fix from $1,600 2025-09-27