Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-36396 IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary… Application Gateway after 25.09 Fix from $1,6002026-01-20 HIGH 8.8 CVE-2025-33015 IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Concert 2.2.0+ Fix from $1,9502026-01-20 MEDIUM 5.5 CVE-2025-36058 IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 I… Business Automation Workflow Mitigation only Fix from $1,6002026-01-20 MEDIUM 5.5 CVE-2025-36059 IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 I… Business Automation Workflow Mitigation only Fix from $1,6002026-01-20 HIGH 7.5 CVE-2025-1722 IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap … Concert 2.2.0+ Fix from $1,9502026-01-20 HIGH 7.5 CVE-2025-1719 IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap … Concert 2.2.0+ Fix from $1,9502026-01-20 HIGH 7.4 CVE-2025-64645 IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link. Concert 2.2.0+ Fix from $1,9502025-12-26 MEDIUM 5.4 CVE-2025-36230 IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, wo… Aspera Faspex 5.0.14.2+ Fix from $1,6002025-12-26 CRITICAL 9.8 CVE-2025-13915EPSS 9% IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acce… Api Connect after 10.0.8.5 Fix from $2,3002025-12-26 HIGH 7.1 CVE-2025-36192 IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8… Ds8a00 Firmware Mitigation only Fix from $1,9502025-12-26 MEDIUM 6.5 CVE-2025-14687 IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of s… Db2 Intelligence Center 1.1.3+ Fix from $1,6002025-12-26 HIGH 7.5 CVE-2025-1721 IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap … Concert 2.2.0+ Fix from $1,9502025-12-26 HIGH 7.8 CVE-2025-12771 IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the b… Concert 2.2.0+ Fix from $1,9502025-12-26 MEDIUM 6.2 CVE-2025-36154 IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user. Concert 2.2.0+ Fix from $1,6002025-12-24 MEDIUM 5.0 CVE-2025-36360 IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1… Devops Deploy 7.1.2.28 / 7.2.3.21+ Fix from $1,6002025-12-15 MEDIUM 6.5 CVE-2025-14148 IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previous… Devops Deploy 8.1.2.4+ Fix from $1,6002025-12-15 MEDIUM 5.9 CVE-2025-13489 IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive infor… Devops Deploy 8.1.2.4+ Fix from $1,6002025-12-15 HIGH 8.8 CVE-2025-13214 IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which coul… Aspera Orchestrator 4.1.1+ Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-13481 IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system du… Aspera Orchestrator 4.1.1+ Fix from $1,9502025-12-11 MEDIUM 6.5 CVE-2025-13148 IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of… Aspera Orchestrator 4.1.1+ Fix from $1,6002025-12-11 MEDIUM 6.5 CVE-2025-13211 IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper contr… Aspera Orchestrator 4.1.1+ Fix from $1,6002025-12-11 MEDIUM 6.5 CVE-2025-36140 IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation o… Watsonx.data 2.2.2+ Fix from $1,6002025-12-08 MEDIUM 6.5 CVE-2025-64650 IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. Storage Defender Resiliency Service after 2.0.18 Fix from $1,6002025-12-08 MEDIUM 6.5 CVE-2025-36015 IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of servi… Cognos Controller 11.0.1.7 / 11.1.2+ Fix from $1,6002025-12-08 MEDIUM 6.5 CVE-2025-36017 IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental va… Controller 11.1.2+ Fix from $1,6002025-12-08 MEDIUM 5.4 CVE-2025-12635 IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scriptin… Websphere Application Server 8.5.5.29 / 9.0.5.27+ Fix from $1,6002025-12-08 HIGH 7.8 CVE-2024-45675 IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password. Informix Dynamic Server 14.10+ Fix from $1,9502025-12-02 HIGH 7.5 CVE-2025-36134 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive in… Sterling B2b Integrator 6.1.2.7_2 / 6.2.0.5_1+ Fix from $1,9502025-11-25 HIGH 7.5 CVE-2025-36150 IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati… Concert after 2.0.0 Fix from $1,9502025-11-24 MEDIUM 5.3 CVE-2025-36112 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive serv… Sterling B2b Integrator 6.1.2.7_2 / 6.2.0.5_1+ Fix from $1,6002025-11-24