Vulnerability index

Browse CVEs

2,256 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Engineering Systems Design Rhapsody HIGH 8.8
CVE-2025-33076

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A…

Mitigation only
Fix from $1,950 2025-07-23
Engineering Systems Design Rhapsody HIGH 8.8
CVE-2025-33077

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A…

Mitigation only
Fix from $1,950 2025-07-23
Engineering Systems Design Rhapsody HIGH 7.5
CVE-2025-33020

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to ob…

Mitigation only
Fix from $1,950 2025-07-23
Db2 Mirror For I MEDIUM 6.3
CVE-2025-36116

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an u…

Mitigation only
Fix from $1,600 2025-07-23
Db2 Mirror For I MEDIUM 6.3
CVE-2025-36117

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user…

Mitigation only
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 5.5
CVE-2024-41751

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypas…

Mitigation only
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 6.1
CVE-2024-40686

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by im…

Mitigation only
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 5.5
CVE-2024-40682

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of servic…

No fix yet
Fix from $1,600 2025-07-23
Smartcloud Analytics Log Analysis MEDIUM 5.5
CVE-2024-41750

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypas…

Mitigation only
Fix from $1,600 2025-07-23
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-33097

IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary …

Mitigation only
Fix from $1,600 2025-07-15
Storage Scale MEDIUM 6.5
CVE-2025-36104

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions in…

Mitigation only
Fix from $1,600 2025-07-12
Infosphere Data Replication MEDIUM 6.5
CVE-2024-56468

IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service by sending an invalid HTTP re…

Mitigation only
Fix from $1,600 2025-07-08
Storage Virtualize HIGH 7.0
CVE-2025-1351

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time…

Mitigation only
Fix from $1,950 2025-07-07
Cloud Pak System MEDIUM 5.4
CVE-2025-2895

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote att…

Mitigation only
Fix from $1,600 2025-06-30
Informix Dynamic Server HIGH 7.5
CVE-2025-1991

IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processi…

Mitigation only
Fix from $1,950 2025-06-28
Datacap MEDIUM 5.4
CVE-2025-36027

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Mitigation only
Fix from $1,600 2025-06-28
Datacap MEDIUM 5.4
CVE-2024-39730

IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi…

Mitigation only
Fix from $1,600 2025-06-28
Cloud Pak System MEDIUM 5.4
CVE-2023-38007

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems …

Mitigation only
Fix from $1,600 2025-06-27
Infosphere Information Server MEDIUM 5.9
CVE-2025-36034

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text t…

Mitigation only
Fix from $1,600 2025-06-26
I HIGH 8.8
CVE-2025-36004

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A mali…

Mitigation only
Fix from $1,950 2025-06-25
Process Mining HIGH 8.2
CVE-2025-36016

IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi…

Mitigation only
Fix from $1,950 2025-06-21
Qradar Security Information And Event Manager CRITICAL 9.1
CVE-2025-33117

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a mal…

Mitigation only
Fix from $2,300 2025-06-19
Qradar Security Information And Event Manager HIGH 7.1
CVE-2025-33121

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot…

Mitigation only
Fix from $1,950 2025-06-19
Qradar Security Information And Event Manager MEDIUM 6.2
CVE-2025-36050

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.

Mitigation only
Fix from $1,600 2025-06-19
Webmethods Integration HIGH 8.8
CVE-2025-36049

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2025-06-18
Webmethods Integration HIGH 7.2
CVE-2025-36048

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external enti…

Mitigation only
Fix from $1,950 2025-06-18
I HIGH 7.5
CVE-2025-33122

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for…

Mitigation only
Fix from $1,950 2025-06-17
I HIGH 8.8
CVE-2025-33108

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri…

Mitigation only
Fix from $1,950 2025-06-14
Guardium Data Protection MEDIUM 6.7
CVE-2025-3473

IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by …

Mitigation only
Fix from $1,600 2025-06-11
Vios HIGH 8.4
CVE-2025-33112

IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due t…

Mitigation only
Fix from $1,950 2025-06-10