Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Pak System MEDIUM 5.4
CVE-2025-2895

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote att…

Mitigation only
Fix from $1,600 2025-06-30
Informix Dynamic Server HIGH 7.5
CVE-2025-1991

IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processi…

Mitigation only
Fix from $1,950 2025-06-28
Datacap MEDIUM 5.4
CVE-2025-36027

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Mitigation only
Fix from $1,600 2025-06-28
Datacap MEDIUM 5.4
CVE-2024-39730

IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi…

Mitigation only
Fix from $1,600 2025-06-28
Cognos Analytics MEDIUM 5.4
CVE-2024-52900

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allo…

Fix: 11.2.4 / 12.0.4+
Fix from $1,600 2025-06-28
Cloud Pak System MEDIUM 5.4
CVE-2023-38007

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems …

Mitigation only
Fix from $1,600 2025-06-27
Infosphere Information Server MEDIUM 5.9
CVE-2025-36034

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text t…

Mitigation only
Fix from $1,600 2025-06-26
Websphere Application Server CRITICAL 9.8
CVE-2025-36038EPSS 9%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence …

Fix: 8.5.5.28 / 9.0.5.25+
Fix from $2,300 2025-06-25
I HIGH 8.8
CVE-2025-36004

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A mali…

Mitigation only
Fix from $1,950 2025-06-25
Infosphere Information Server HIGH 7.6
CVE-2025-0966

IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow …

Fix: 11.7.1+
Fix from $1,950 2025-06-25
Infosphere Information Server HIGH 7.5
CVE-2025-3221

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation…

Fix: after 11.7.1.6
Fix from $1,950 2025-06-21
Process Mining HIGH 8.2
CVE-2025-36016

IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vi…

Mitigation only
Fix from $1,950 2025-06-21
Spectrum Protect Server CRITICAL 9.8
CVE-2025-3319

IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result …

Fix: after 8.1.26
Fix from $2,300 2025-06-20
Qradar Security Information And Event Manager CRITICAL 9.1
CVE-2025-33117

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a mal…

Mitigation only
Fix from $2,300 2025-06-19
Qradar Security Information And Event Manager HIGH 7.1
CVE-2025-33121

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot…

Mitigation only
Fix from $1,950 2025-06-19
Qradar Security Information And Event Manager MEDIUM 6.2
CVE-2025-36050

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.

Mitigation only
Fix from $1,600 2025-06-19
Webmethods Integration HIGH 8.8
CVE-2025-36049

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2025-06-18
Webmethods Integration HIGH 7.2
CVE-2025-36048

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external enti…

Mitigation only
Fix from $1,950 2025-06-18
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-54183

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. …

Fix: 6.1.2.7 / 6.2.0.5+
Fix from $1,600 2025-06-18
I HIGH 7.5
CVE-2025-33122

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for…

Mitigation only
Fix from $1,950 2025-06-17
Mq Operator CRITICAL 9.8
CVE-2025-36041

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ O…

Fix: after 3.5.3
Fix from $2,300 2025-06-15
Security Verify Directory HIGH 7.8
CVE-2025-1411

IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecess…

Fix: after 10.0.3.1
Fix from $1,950 2025-06-15
I HIGH 8.8
CVE-2025-33108

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri…

Mitigation only
Fix from $1,950 2025-06-14
Cognos Analytics HIGH 7.5
CVE-2025-25032

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a …

Fix: after 12.0.4
Fix from $1,950 2025-06-11
Cognos Analytics MEDIUM 5.3
CVE-2025-0923

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that cou…

Fix: after 12.0.4
Fix from $1,600 2025-06-11
Guardium Data Protection MEDIUM 6.7
CVE-2025-3473

IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by …

Mitigation only
Fix from $1,600 2025-06-11
Security Verify Access MEDIUM 5.3
CVE-2025-0163

IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable respons…

Fix: 10.0.9+
Fix from $1,600 2025-06-11
Vios HIGH 8.4
CVE-2025-33112

IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due t…

Mitigation only
Fix from $1,950 2025-06-10
Security Verify Governance CRITICAL 9.8
CVE-2024-22330

IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to com…

Mitigation only
Fix from $2,300 2025-06-06
Verify Identity Access Digital Credentials MEDIUM 6.5
CVE-2024-56343

IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request.

Mitigation only
Fix from $1,600 2025-06-06