Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Verify Access CRITICAL 9.3
CVE-2025-36356

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authen…

Fix: 10.0.9.0 / 11.0.1.0+
Fix from $2,300 2025-10-06
Security Verify Access HIGH 8.5
CVE-2025-36355

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally auth…

Fix: 10.0.9.0 / 11.0.1.0+
Fix from $1,950 2025-10-06
Security Verify Access HIGH 7.3
CVE-2025-36354

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthent…

Fix: 10.0.9.0 / 11.0.1.0+
Fix from $1,950 2025-10-06
Transformation Extender Advanced CRITICAL 9.8
CVE-2023-49886

IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserializa…

Mitigation only
Fix from $2,300 2025-10-06
Transformation Extender Advanced HIGH 8.8
CVE-2023-49881

IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another…

Mitigation only
Fix from $1,950 2025-10-01
Transformation Extender Advanced HIGH 7.5
CVE-2023-49883

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for atta…

Mitigation only
Fix from $1,950 2025-10-01
Transformation Extender Advanced MEDIUM 6.2
CVE-2023-50300

IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.

Mitigation only
Fix from $1,600 2025-10-01
Planning Analytics Local MEDIUM 5.4
CVE-2025-36132

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authe…

Fix: after 2.1.13
Fix from $1,600 2025-09-30
Infosphere Information Server HIGH 8.8
CVE-2025-36245

IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges …

Fix: after 11.7.1.6
Fix from $1,950 2025-09-29
License Metric Tool MEDIUM 5.4
CVE-2025-36352

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed a…

Fix: 9.2.41+
Fix from $1,600 2025-09-29
Storage Ts4500 Library Firmware MEDIUM 6.1
CVE-2025-36239

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to em…

Mitigation only
Fix from $1,600 2025-09-27
Storage Ts4500 Library Firmware HIGH 8.8
CVE-2024-43192

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Mitigation only
Fix from $1,950 2025-09-27
Watsonx.data MEDIUM 5.5
CVE-2025-36144

IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

Mitigation only
Fix from $1,600 2025-09-27
Aspera Http Gateway HIGH 7.5
CVE-2025-36274

IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthentic…

Fix: 2.3.2+
Fix from $1,950 2025-09-26
Cognos Controller HIGH 7.5
CVE-2025-36326

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to …

Fix: after 11.1.1
Fix from $1,950 2025-09-26
Watson Studio MEDIUM 5.4
CVE-2025-33116

IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to e…

Fix: 5.2.1+
Fix from $1,600 2025-09-25
Sterling Connect\ MEDIUM 5.9
CVE-2025-36064

IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote atta…

Fix: 3.1.0.23+
Fix from $1,600 2025-09-22
Webmethods Integration HIGH 8.8
CVE-2025-36202

IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to t…

Mitigation only
Fix from $1,950 2025-09-22
Webmethods Integration MEDIUM 5.4
CVE-2025-36037

IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una…

Mitigation only
Fix from $1,600 2025-09-22
Copy Services Manager MEDIUM 6.1
CVE-2025-36248

IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScri…

Fix: 6.3.14+
Fix from $1,600 2025-09-19
Watsonx.data HIGH 7.2
CVE-2025-36143

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation …

Mitigation only
Fix from $1,950 2025-09-18
Vios MEDIUM 5.5
CVE-2025-36244

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the sy…

Mitigation only
Fix from $1,600 2025-09-16
Powervm Hypervisor MEDIUM 5.1
CVE-2025-36035

IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to…

Mitigation only
Fix from $1,600 2025-09-14
Storage Fusion CRITICAL 9.8
CVE-2025-36222

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default confi…

Fix: 2.11.0+
Fix from $2,300 2025-09-11
Security Verify Information Queue HIGH 7.5
CVE-2024-45671

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an att…

Fix: 10.0.11+
Fix from $1,950 2025-09-10
Security Verify Information Queue MEDIUM 6.8
CVE-2024-47120

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surfac…

Fix: 10.0.11+
Fix from $1,600 2025-09-10
Security Verify Information Queue MEDIUM 6.5
CVE-2024-45669

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handl…

Fix: 10.0.11+
Fix from $1,600 2025-09-10
Hardware Management Console MEDIUM 5.4
CVE-2025-36125

IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authen…

Mitigation only
Fix from $1,600 2025-09-09
Concert HIGH 7.5
CVE-2025-1761

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing…

Fix: after 1.1.0
Fix from $1,950 2025-09-08
Mq MEDIUM 5.5
CVE-2025-36100

IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.…

Fix: 9.1.0.31 / 9.2.0.37+
Fix from $1,600 2025-09-07