Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Verify Directory HIGH 7.2
CVE-2025-36074

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not v…

Fix: after 10.0.3
Fix from $1,950 2026-04-23
Tivoli Netcool\/impact MEDIUM 5.5
CVE-2026-4788

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.

Fix: 7.1.0.38+
Fix from $1,600 2026-04-08
Security Verify Access HIGH 7.8
CVE-2026-1346

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-08
Security Verify Access HIGH 7.2
CVE-2026-1343

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-08
Security Verify Access HIGH 7.9
CVE-2026-1342

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-08
Concert MEDIUM 6.2
CVE-2025-13044

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink a…

Fix: after 2.2.0
Fix from $1,600 2026-04-07
Content Navigator MEDIUM 5.4
CVE-2026-1243

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr…

Mitigation only
Fix from $1,600 2026-04-02
Aspera Shares MEDIUM 6.5
CVE-2025-66487

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in e…

Fix: 1.11.1+
Fix from $1,600 2026-04-01
Aspera Shares MEDIUM 6.1
CVE-2025-66486

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Fix: 1.11.1+
Fix from $1,600 2026-04-01
Aspera Shares MEDIUM 5.4
CVE-2025-66484

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Fix: 1.11.1+
Fix from $1,600 2026-04-01
Aspera Shares MEDIUM 5.4
CVE-2025-66485

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This coul…

Fix: 1.11.1+
Fix from $1,600 2026-04-01
Datapower Gateway HIGH 8.8
CVE-2025-36375

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 1…

Fix: 10.5.0.21 / 10.6.0.9+
Fix from $1,950 2026-04-01
Aspera Shares MEDIUM 6.5
CVE-2025-66483

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate anot…

Fix: after 1.11.0
Fix from $1,600 2026-04-01
Security Verify Access CRITICAL 9.8
CVE-2026-4101

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $2,300 2026-04-01
Security Verify Access MEDIUM 5.4
CVE-2026-4364

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,600 2026-04-01
Security Verify Access MEDIUM 5.3
CVE-2026-2862

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,600 2026-04-01
Security Verify Access HIGH 7.3
CVE-2026-1345

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,950 2026-04-01
Security Verify Access MEDIUM 5.3
CVE-2026-1491

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,600 2026-04-01
Datapower Gateway MEDIUM 6.8
CVE-2025-36373

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 1…

Fix: 10.5.0.21 / 10.6.0.9+
Fix from $1,600 2026-04-01
Aspera Shares HIGH 7.5
CVE-2025-13916

IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive in…

Fix: 1.11.1+
Fix from $1,950 2026-04-01
Storage Protect Server HIGH 8.8
CVE-2025-13855

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s…

Mitigation only
Fix from $1,950 2026-04-01
Infosphere Information Server MEDIUM 5.4
CVE-2026-2483

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 6.5
CVE-2026-1014

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 5.4
CVE-2026-1015

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Websphere Application Server MEDIUM 5.4
CVE-2026-1561

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request fo…

Fix: 26.0.0.4+
Fix from $1,600 2026-03-25
Concert HIGH 7.5
CVE-2025-64647

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati…

Fix: after 2.2.0
Fix from $1,950 2026-03-25
Concert MEDIUM 5.9
CVE-2025-64648

IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle tec…

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Concert MEDIUM 5.5
CVE-2025-36438

IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to…

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Concert MEDIUM 5.5
CVE-2025-36440

IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Concert MEDIUM 5.5
CVE-2025-64646

IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

Fix: after 2.2.0
Fix from $1,600 2026-03-25