Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jazz Foundation MEDIUM 5.4
CVE-2025-15395

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to v…

Mitigation only
Fix from $1,600 2026-02-02
Websphere Application Server HIGH 7.6
CVE-2025-14914

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal se…

Fix: after 26.0.0.1
Fix from $1,950 2026-02-02
Db2 HIGH 7.5
CVE-2025-36442

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the ser…

Fix: after 12.1.3
Fix from $1,950 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36424

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to improper neutralization of s…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36427

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of s…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 5.3
CVE-2025-36428

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a de…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 HIGH 7.8
CVE-2025-36384

IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted searc…

Fix: after 12.1.3
Fix from $1,950 2026-01-30
Db2 HIGH 7.5
CVE-2025-36365

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remot…

Fix: after 12.1.3
Fix from $1,950 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36366

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that invokes t…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36387

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when…

Fix: after 11.5.9
Fix from $1,600 2026-01-30
Db2 MEDIUM 5.5
CVE-2025-36407

IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 5.5
CVE-2025-36423

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improp…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 HIGH 7.5
CVE-2025-36070

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap…

Fix: after 12.1.3
Fix from $1,950 2026-01-30
Db2 HIGH 7.2
CVE-2025-36184

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escala…

Fix: after 11.5.9
Fix from $1,950 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36001

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a de…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36009

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36098

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a de…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 5.5
CVE-2025-36123

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of s…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 5.5
CVE-2025-36353

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of s…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-2668

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when a…

Fix: after 11.5.9
Fix from $1,600 2026-01-30
Applinx CRITICAL 9.8
CVE-2025-36418

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra…

Mitigation only
Fix from $2,300 2026-01-20
Applinx MEDIUM 6.4
CVE-2025-36408

IBM ApplinX 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2026-01-20
Application Gateway MEDIUM 5.4
CVE-2025-36397

IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, w…

Fix: after 25.09
Fix from $1,600 2026-01-20
Applinx MEDIUM 5.4
CVE-2025-36409

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2026-01-20
Applinx MEDIUM 5.3
CVE-2025-36419

IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks against the system.

No fix yet
Fix from $1,600 2026-01-20
Sterling Connect\ MEDIUM 6.5
CVE-2025-36063

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which cou…

Fix: 5.2.0.13+
Fix from $1,600 2026-01-20
Sterling Connect\ MEDIUM 6.5
CVE-2025-36065

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure …

Fix: 5.2.0.13+
Fix from $1,600 2026-01-20
Sterling Connect\ MEDIUM 6.5
CVE-2025-36115

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could all…

Fix: 5.2.0.13+
Fix from $1,600 2026-01-20
Sterling Connect\ MEDIUM 6.1
CVE-2025-36066

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerab…

Fix: 5.2.0.13+
Fix from $1,600 2026-01-20
Sterling Connect\ MEDIUM 5.4
CVE-2025-36113

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerab…

Fix: 5.2.0.13+
Fix from $1,600 2026-01-20