Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Verify Identity Access Digital Credentials MEDIUM 5.3
CVE-2024-56342

IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error me…

Mitigation only
Fix from $1,600 2025-06-06
Cloud Pak For Security HIGH 8.8
CVE-2025-25022

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in…

Fix: after 1.11.2.0
Fix from $1,950 2025-06-03
Cloud Pak For Security HIGH 7.2
CVE-2025-25021

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code …

Fix: after 1.11.2.0
Fix from $1,950 2025-06-03
Cloud Pak For Security MEDIUM 6.5
CVE-2025-25020

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to c…

Fix: after 1.11.2.0
Fix from $1,600 2025-06-03
Cloud Pak For Security MEDIUM 6.5
CVE-2025-25019

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a lo…

Fix: after 1.11.2.0
Fix from $1,600 2025-06-03
Application Gateway MEDIUM 5.5
CVE-2024-45655

IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignme…

Fix: after 24.09
Fix from $1,600 2025-06-03
Planning Analytics Local HIGH 8.8
CVE-2025-33005

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another us…

Mitigation only
Fix from $1,950 2025-06-01
Planning Analytics Local MEDIUM 6.5
CVE-2025-33004

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

Mitigation only
Fix from $1,600 2025-06-01
Planning Analytics Local MEDIUM 5.4
CVE-2025-25044

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2025-06-01
Planning Analytics Local MEDIUM 5.4
CVE-2025-2896

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary Ja…

Mitigation only
Fix from $1,600 2025-06-01
Infosphere Information Server MEDIUM 6.5
CVE-2025-1499

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed b…

Mitigation only
Fix from $1,600 2025-06-01
Db2 HIGH 7.5
CVE-2025-2518

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnerable to a denial of serv…

Fix: after 12.1.1
Fix from $1,950 2025-05-29
Db2 MEDIUM 6.5
CVE-2025-3050

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user t…

Fix: after 12.1.1
Fix from $1,600 2025-05-29
Db2 HIGH 7.5
CVE-2024-49350

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnera…

Fix: after 12.1.1
Fix from $1,950 2025-05-29
Sterling Secure Proxy HIGH 7.5
CVE-2024-51453

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a speci…

Fix: after 6.2.0.1
Fix from $1,950 2025-05-28
Sterling Secure Proxy HIGH 7.5
CVE-2024-38341

IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algor…

Fix: after 6.2.0.1
Fix from $1,950 2025-05-28
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3357

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of a…

Mitigation only
Fix from $2,300 2025-05-28
Security Guardium MEDIUM 6.5
CVE-2025-25029

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

Mitigation only
Fix from $1,600 2025-05-28
Security Guardium MEDIUM 5.3
CVE-2025-25025

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the b…

Mitigation only
Fix from $1,600 2025-05-28
Hardware Management Console R10.0 Firmware MEDIUM 5.4
CVE-2024-45094

IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to…

Mitigation only
Fix from $1,600 2025-05-27
Cognos Controller MEDIUM 6.5
CVE-2025-33079

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc…

Mitigation only
Fix from $1,600 2025-05-27
Aspera Faspex HIGH 8.8
CVE-2025-33136

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of…

Fix: 5.0.12.1+
Fix from $1,950 2025-05-22
Aspera Faspex HIGH 8.8
CVE-2025-33137

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of…

Fix: 5.0.12.1+
Fix from $1,950 2025-05-22
Aspera Faspex MEDIUM 6.1
CVE-2025-33138

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Fix: 5.0.12.1+
Fix from $1,600 2025-05-22
Security Qradar Edr MEDIUM 6.5
CVE-2024-45641

IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.

Fix: 3.12.17+
Fix from $1,600 2025-05-20
Security Qradar Edr MEDIUM 6.5
CVE-2023-33861

IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.

Fix: 3.12.17+
Fix from $1,600 2025-05-20
I HIGH 8.8
CVE-2025-33103

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor wi…

Mitigation only
Fix from $1,950 2025-05-17
Content Navigator MEDIUM 6.1
CVE-2024-51475

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…

Mitigation only
Fix from $1,600 2025-05-16
Security Guardium MEDIUM 5.5
CVE-2025-3440

IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2025-05-15
Websphere Application Server HIGH 7.6
CVE-2025-33104

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Fix: 8.5.5.28 / 9.0.5.24+
Fix from $1,950 2025-05-14