Vulnerability index

Browse CVEs

2,256 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Webmethods Integration HIGH 8.8
CVE-2025-36202

IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to t…

Mitigation only
Fix from $1,950 2025-09-22
Webmethods Integration MEDIUM 5.4
CVE-2025-36037

IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Mitigation only
Fix from $1,600 2025-09-22
Watsonx.data HIGH 7.2
CVE-2025-36143

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation …

Mitigation only
Fix from $1,950 2025-09-18
Vios MEDIUM 5.5
CVE-2025-36244

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the sy…

Mitigation only
Fix from $1,600 2025-09-16
Powervm Hypervisor MEDIUM 5.1
CVE-2025-36035

IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to…

Mitigation only
Fix from $1,600 2025-09-14
Hardware Management Console MEDIUM 5.4
CVE-2025-36125

IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-09-09
Security Verify Governance MEDIUM 5.3
CVE-2025-36003

IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error me…

Mitigation only
Fix from $1,600 2025-08-28
Cognos Command Center CRITICAL 9.3
CVE-2025-2697

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi…

Mitigation only
Fix from $2,300 2025-08-26
Cognos Command Center HIGH 7.8
CVE-2025-1994

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of th…

Mitigation only
Fix from $1,950 2025-08-26
Cognos Command Center MEDIUM 6.1
CVE-2025-1494

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi…

Mitigation only
Fix from $1,600 2025-08-26
Qradar Incident Forensics HIGH 7.8
CVE-2025-33120

IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution wi…

Mitigation only
Fix from $1,950 2025-08-22
Qradar Incident Forensics MEDIUM 5.4
CVE-2025-36042

IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…

Mitigation only
Fix from $1,600 2025-08-22
Edge Application Manager MEDIUM 5.4
CVE-2025-1142

IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized r…

Mitigation only
Fix from $1,600 2025-08-20
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-33008

IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authent…

Mitigation only
Fix from $1,600 2025-08-19
Storage Ts4500 Library Firmware MEDIUM 5.4
CVE-2025-36088

IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an auth…

Mitigation only
Fix from $1,600 2025-08-15
I HIGH 8.8
CVE-2025-36119

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due …

Mitigation only
Fix from $1,950 2025-08-08
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2025-36023

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive…

Mitigation only
Fix from $1,600 2025-08-08
Guardium Data Protection HIGH 7.5
CVE-2025-36020

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential info…

Mitigation only
Fix from $1,950 2025-08-06
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3320

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…

Mitigation only
Fix from $2,300 2025-08-06
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3354

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re…

Mitigation only
Fix from $2,300 2025-08-06
Engineering Lifecycle Optimization MEDIUM 6.1
CVE-2024-52890

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

Mitigation only
Fix from $1,600 2025-08-05
Operational Decision Manager HIGH 7.4
CVE-2025-2824

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an…

Mitigation only
Fix from $1,950 2025-08-01
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-33118

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed…

Mitigation only
Fix from $1,600 2025-08-01
Db2 HIGH 7.8
CVE-2025-33092

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local u…

Mitigation only
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2025-33114

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under certain non-default conditio…

Mitigation only
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2025-36010

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to executable segments that are w…

Mitigation only
Fix from $1,950 2025-07-29
Db2 HIGH 7.5
CVE-2025-2533

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially c…

Mitigation only
Fix from $1,950 2025-07-29
Informix Dynamic Server HIGH 7.5
CVE-2024-49342

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cred…

Mitigation only
Fix from $1,950 2025-07-28
Informix Dynamic Server MEDIUM 5.4
CVE-2024-49343

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, w…

Mitigation only
Fix from $1,600 2025-07-28
I HIGH 8.8
CVE-2025-33109

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a…

Mitigation only
Fix from $1,950 2025-07-24