Vulnerability index

Browse CVEs

6,266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I HIGH 8.8
CVE-2026-16856

IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-16906

IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.1
CVE-2026-16904

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during mo…

Fix: after 7.6
Fix from $4,900 2026-08-12
I HIGH 7.7
CVE-2026-16863

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

Fix: after 7.6
Fix from $4,900 2026-08-12
I HIGH 7.6
CVE-2026-16907

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

Fix: after 7.6
Fix from $4,900 2026-08-12
I CRITICAL 9.8
CVE-2026-18847

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.

No fix yet
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-18683

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user…

No fix yet
Fix from $4,900 2026-08-12
Websphere Application Server HIGH 8.1
CVE-2026-18499

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.3
CVE-2026-17095

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.1
CVE-2026-18098

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XM…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 7.1
CVE-2026-17094

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal…

Fix unknown
Fix from $4,900 2026-08-12
I MEDIUM 5.4
CVE-2026-16694

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

No fix yet
Fix from $4,000 2026-08-12
Application Gateway Operator CRITICAL 9.8
CVE-2026-17617

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…

Fix: after 26.6.0
Fix from $2,300 2026-08-05
Websphere Application Server CRITICAL 9.8
CVE-2026-8400

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I…

No fix yet
Fix from $2,300 2026-08-05
Maximo Application Suite MEDIUM 5.3
CVE-2026-18531

IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signin…

Fix: 9.0.28 / 9.1.20+
Fix from $1,600 2026-08-05
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…

No fix yet
Fix from $2,300 2026-08-05
Qradar Security Information And Event Manager HIGH 8.8
CVE-2026-13477

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c…

No fix yet
Fix from $1,950 2026-08-05
Business Automation Insights MEDIUM 5.3
CVE-2026-12762

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in man…

No fix yet
Fix from $1,600 2026-08-05
Websphere Application Server HIGH 8.5
CVE-2026-11536

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

Fix: 8.5.5.29 / 9.0.5.28+
Fix from $1,950 2026-07-30
Hardware Management Console CRITICAL 9.8
CVE-2026-12943

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…

Fix: 10.3.1064.1 / 11.1.1112.1+
Fix from $2,300 2026-07-30
Webmethods Integration CRITICAL 9.8
CVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…

No fix yet
Fix from $2,300 2026-07-30
Datapower Gateway HIGH 7.5
CVE-2026-12733

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

Fix: 10.5.0.22 / 10.6.0.10+
Fix from $1,950 2026-07-30
Verify Identity Access MEDIUM 5.3
CVE-2026-11904

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.2
Fix from $1,600 2026-07-30
Db2 HIGH 7.8
CVE-2026-10535

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.

Fix: 12.1.5+
Fix from $1,950 2026-07-30
Planning Analytics Local HIGH 7.5
CVE-2026-10545

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external w…

Fix: after 2.1.21
Fix from $1,950 2026-07-30
Db2 MEDIUM 5.5
CVE-2026-10695

IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.

Fix: 12.1.5+
Fix from $1,600 2026-07-30
Operations Analytics Log Analysis MEDIUM 6.3
CVE-2024-40683

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.…

Fix: after 1.3.8.4
Fix from $1,600 2026-07-30
Engineering Requirements Management Doors Web Access MEDIUM 6.1
CVE-2025-0152

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site…

Fix: after 9.7.2.11
Fix from $1,600 2026-07-30
Engineering Requirements Management Doors Web Access HIGH 7.5
CVE-2024-25039

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of …

Fix: after 9.7.2.11
Fix from $1,950 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-9322

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of …

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-30