Vulnerability index

Browse CVEs

6,266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server CRITICAL 9.8
CVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server MEDIUM 6.5
CVE-2026-16192

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feat…

Fix: 26.0.0.9+
Fix from $1,600 2026-07-28
Sterling B2b Integrator HIGH 8.1
CVE-2026-7769

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0…

Fix: after 6.2.2.0_1
Fix from $1,950 2026-07-28
Sterling B2b Integrator MEDIUM 6.5
CVE-2026-7362

IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2…

Fix: after 6.2.2.0_1
Fix from $1,600 2026-07-28
Sterling B2b Integrator MEDIUM 5.3
CVE-2026-3482

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could…

Fix: after 6.2.2.0_1
Fix from $1,600 2026-07-22
Security Verify Access MEDIUM 5.3
CVE-2026-8861

IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.…

Fix: 10.0.9.2 / 11.0.3+
Fix from $1,600 2026-07-17
Db2 MEDIUM 5.5
CVE-2026-7771

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries …

Fix: 12.1.5+
Fix from $1,600 2026-07-17
Security Verify Access MEDIUM 6.1
CVE-2026-7364

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.2.0
Fix from $1,600 2026-07-17
I HIGH 7.5
CVE-2026-4942

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) pr…

No fix yet
Fix from $1,950 2026-07-17
Security Verify Access MEDIUM 6.5
CVE-2026-4938

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.2.0
Fix from $1,600 2026-07-17
Agentics CRITICAL 9.8
CVE-2026-14501

IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to th…

Fix: 1.1.3+
Fix from $2,300 2026-07-17
Engineering Ai Hub CRITICAL 9.3
CVE-2026-15091

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…

Fix: 1.3.0+
Fix from $2,300 2026-07-17
Engineering Lifecycle Management HIGH 7.5
CVE-2026-14979

IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 …

No fix yet
Fix from $1,950 2026-07-17
Engineering Ai Hub HIGH 7.5
CVE-2026-15322

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in…

Fix: 1.3.0+
Fix from $1,950 2026-07-17
Powervm Novalink HIGH 7.0
CVE-2026-14971

IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintend…

No fix yet
Fix from $1,950 2026-07-17
Engineering Ai Hub MEDIUM 5.4
CVE-2026-15069

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input…

Fix: 1.3.0+
Fix from $1,600 2026-07-17
Storage Protect CRITICAL 9.8
CVE-2026-13473

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer o…

Fix: 8.2.1.2+
Fix from $2,300 2026-07-17
Powervm Novalink HIGH 7.5
CVE-2026-9171

IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafte…

No fix yet
Fix from $1,950 2026-07-17
Db2 HIGH 7.8
CVE-2026-9762

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.

Fix: 12.1.5+
Fix from $1,950 2026-07-17
Api Connect CRITICAL 9.8
CVE-2026-9074

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…

Fix: 10.0.8.10 / 12.1.1.0+
Fix from $2,300 2026-07-08
Api Connect CRITICAL 9.8
CVE-2026-3144

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application befor…

Fix: 12.1.1.0+
Fix from $2,300 2026-07-08
Websphere Application Server CRITICAL 9.8
CVE-2026-11541

IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application S…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Devops Automation MEDIUM 6.5
CVE-2025-36359

IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to imp…

Mitigation only
Fix from $1,600 2026-06-30
Websphere Application Server MEDIUM 6.1
CVE-2026-11594

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.9
CVE-2025-36336

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information us…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 6.5
CVE-2025-36327

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actio…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 6.4
CVE-2025-36320

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated use…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.7
CVE-2025-36321

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which w…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.4
CVE-2025-36323

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to em…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.9
CVE-2025-12530

IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitiv…

Mitigation only
Fix from $1,600 2026-06-30