Vulnerability index

Browse CVEs

2,256 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-2950 IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigato… I Mitigation only Fix from $1,6002025-04-18 CRITICAL 9.8 CVE-2025-2947 IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command … I Mitigation only Fix from $2,3002025-04-17 MEDIUM 5.4 CVE-2023-42007 IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr… Sterling Control Center Mitigation only Fix from $1,6002025-04-10 MEDIUM 5.4 CVE-2023-33844 IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th… Security Verify Governance Mitigation only Fix from $1,6002025-04-09 HIGH 7.8 CVE-2025-1095 IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows an… Personal Communications Mitigation only Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-0154 IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers. Txseries For Multiplatforms Mitigation only Fix from $1,9502025-04-02 MEDIUM 5.3 CVE-2024-56476 IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy. Txseries For Multiplatforms Mitigation only Fix from $1,6002025-04-02 HIGH 8.8 CVE-2024-56474 IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut… Txseries For Multiplatforms Mitigation only Fix from $1,9502025-04-02 MEDIUM 5.4 CVE-2024-56475 IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrar… Txseries For Multiplatforms Mitigation only Fix from $1,6002025-04-02 MEDIUM 5.4 CVE-2024-56341 IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbit… Content Navigator Mitigation only Fix from $1,6002025-04-02 HIGH 7.2 CVE-2024-25051 IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate… Jazz Reporting Service Mitigation only Fix from $1,9502025-04-02 HIGH 7.5 CVE-2023-38272 IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.… Cloud Pak System Mitigation only Fix from $1,9502025-03-27 MEDIUM 6.5 CVE-2023-37405 IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.… Cloud Pak System Mitigation only Fix from $1,6002025-03-27 HIGH 7.5 CVE-2024-31896 IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl… Spss Statistics Mitigation only Fix from $1,9502025-03-25 MEDIUM 6.8 CVE-2023-43029 IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment. Storage Virtualize Plugin For Vsphere Mitigation only Fix from $1,6002025-03-21 CRITICAL 10.0 CVE-2024-56346 IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls. Aix Mitigation only Fix from $2,3002025-03-18 CRITICAL 9.6 CVE-2024-56347 IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process c… Aix Mitigation only Fix from $2,3002025-03-18 MEDIUM 5.3 CVE-2023-43052 IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input.… Control Center Mitigation only Fix from $1,6002025-03-07 MEDIUM 6.1 CVE-2023-35894 IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could… Sterling Control Center Mitigation only Fix from $1,6002025-03-07 HIGH 7.5 CVE-2024-51476 IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. Concert Software Mitigation only Fix from $1,9502025-03-06 HIGH 7.5 CVE-2024-41771 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 MEDIUM 6.5 CVE-2024-43169 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integr… Engineering Requirements Management Doors Next Mitigation only Fix from $1,6002025-03-03 HIGH 7.5 CVE-2024-41770 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 MEDIUM 6.5 CVE-2024-41778 IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attack… Controller Mitigation only Fix from $1,6002025-03-01 MEDIUM 5.5 CVE-2024-54175 IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper check for unusual or exception… Mq Mitigation only Fix from $1,6002025-02-28 MEDIUM 5.5 CVE-2025-0985 IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local use… Mq Mitigation only Fix from $1,6002025-02-28 MEDIUM 5.5 CVE-2024-56812 IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information coul… Entirex Mitigation only Fix from $1,6002025-02-27 MEDIUM 6.5 CVE-2024-54169 IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request … Entirex Mitigation only Fix from $1,6002025-02-27 MEDIUM 5.5 CVE-2024-54170 IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity that consume… Entirex Mitigation only Fix from $1,6002025-02-27 HIGH 8.5 CVE-2024-55898 IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified… I Mitigation only Fix from $1,9502025-02-24