Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-3660 IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul… Engineering Lifecycle Management Mitigation only Fix from $2,3002026-05-26 HIGH 7.1 CVE-2026-3603 IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7… Engineering Lifecycle Management Patch available Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-8855 IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-9170 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation. HTTP Server Mitigation only Fix from $2,3002026-05-26 CRITICAL 9.1 CVE-2026-8856 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-05-26 HIGH 7.5 CVE-2026-8854 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-8633 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se… Websphere Application Server after 9.0.5.27 Fix from $2,3002026-05-26 HIGH 8.0 CVE-2026-8834 IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit t… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-8620 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se… Websphere Application Server 8.5.5.30 / 9.0.5.28+ Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-8835 IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could explo… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-8850 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload. HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-8852 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module. HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2025-36220 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote atta… Cloud Pak For Data System Cyclops 11.3.0.2+ Fix from $2,3002026-05-26 HIGH 7.5 CVE-2025-36221 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from… Cloud Pak For Data System Cyclops 11.3.0.2+ Fix from $1,9502026-05-26 MEDIUM 6.1 CVE-2025-36148 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerabl… Financial Transaction Manager For Multiplatform 3.2.4.16+ Fix from $1,6002026-05-26 HIGH 7.6 CVE-2025-36126 IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) … Cognos Analytics 12.1.2+ Fix from $1,9502026-05-26 MEDIUM 5.4 CVE-2025-14290 IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vu… Webmethods Integration Server Mitigation only Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2025-36145 IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfe… Watsonx.data after 2.3.1 Fix from $1,6002026-05-26 MEDIUM 5.5 CVE-2025-13755 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive infor… Db2 after 12.1.4 Fix from $1,6002026-05-26 HIGH 7.8 CVE-2026-6389 IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, inclu… Turbonomic Prometurbo Agent 8.18.0+ Fix from $1,9502026-04-30 CRITICAL 9.8 CVE-2026-2311 IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali… I Mitigation only Fix from $2,3002026-04-30 MEDIUM 6.5 CVE-2026-1577 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user … Db2 after 12.1.4 Fix from $1,6002026-04-30 HIGH 7.5 CVE-2025-36180 IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data b… Watsonx.data after 2.3 Fix from $1,9502026-04-30 MEDIUM 6.5 CVE-2025-36122 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user … Db2 after 12.1.3 Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2025-36335 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user. Watsonx.data Mitigation only Fix from $1,6002026-04-30 MEDIUM 5.3 CVE-2025-14688 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user … Db2 after 12.1.3 Fix from $1,6002026-04-30 CRITICAL 9.8 CVE-2026-5935 IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma… Total Storage Service Console Mitigation only Fix from $2,3002026-04-23 MEDIUM 6.5 CVE-2026-5926 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $1,6002026-04-23 MEDIUM 5.9 CVE-2026-3621 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing unde… Websphere Application Server 26.0.0.5+ Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-1352 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user … Db2 after 12.1.4 Fix from $1,6002026-04-23