Vulnerability index

Browse CVEs

2,237 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-36298 IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM St… Sterling B2b Integrator No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-4942 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) pr… I No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-14979 IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 … Engineering Lifecycle Management No fix yet Fix from $1,9502026-07-17 HIGH 7.0 CVE-2026-14971 IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintend… Powervm Novalink No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-9171 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafte… Powervm Novalink No fix yet Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2025-36359 IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to imp… Devops Automation Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.9 CVE-2025-36336 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information us… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2025-36327 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actio… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.4 CVE-2025-36320 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated use… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.7 CVE-2025-36321 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which w… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.4 CVE-2025-36323 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to em… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.9 CVE-2025-12530 IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitiv… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-10852 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in … I Mitigation only Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2026-9610 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI … Datacap Mitigation only Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-8636 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic… Datacap Mitigation only Fix from $1,9502026-06-22 MEDIUM 6.1 CVE-2026-8059 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allow… Datacap Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2026-11372 IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed … Tririga Application Platform Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2024-51454 IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is … Engineering Workflow Management Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2025-33128 IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. T… Engineering Workflow Management Mitigation only Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-7870 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-co… I Mitigation only Fix from $1,9502026-06-11 MEDIUM 6.5 CVE-2026-8405 IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive … Guardium Data Protection Mitigation only Fix from $1,6002026-05-27 HIGH 7.8 CVE-2026-7365 IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing … Operations Analytics Log Analysis Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-3676 IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could a… Cloud Application Performance Managemen Mitigation only Fix from $1,6002026-05-27 HIGH 7.5 CVE-2026-3366 IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote … Infosphere Optim Test Data Fabrication Mitigation only Fix from $1,9502026-05-27 HIGH 8.8 CVE-2024-56462 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and use… Qradar Security Information And Event Manager Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.8 CVE-2024-40684 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.… Operations Analytics Log Analysis Mitigation only Fix from $2,3002026-05-27 HIGH 7.2 CVE-2026-4051 IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exp… Engineering Lifecycle Management Mitigation only Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-3660 IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul… Engineering Lifecycle Management Mitigation only Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-9170 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation. HTTP Server Mitigation only Fix from $2,3002026-05-26 MEDIUM 5.4 CVE-2025-14290 IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vu… Webmethods Integration Server Mitigation only Fix from $1,6002026-05-26