Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-31896 IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl… Spss Statistics Mitigation only Fix from $1,9502025-03-25 MEDIUM 6.8 CVE-2023-43029 IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment. Storage Virtualize Plugin For Vsphere Mitigation only Fix from $1,6002025-03-21 HIGH 7.8 CVE-2024-51459 IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions. Infosphere Information Server 11.7.1.136+ Fix from $1,9502025-03-19 CRITICAL 10.0 CVE-2024-56346 IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls. Aix Mitigation only Fix from $2,3002025-03-18 CRITICAL 9.6 CVE-2024-56347 IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process c… Aix Mitigation only Fix from $2,3002025-03-18 HIGH 7.5 CVE-2024-45643 IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential informat… Security Qradar Edr 3.12.16+ Fix from $1,9502025-03-14 CRITICAL 9.8 CVE-2025-2000 A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY forma… Qiskit 1.4.2+ Fix from $2,3002025-03-14 MEDIUM 6.5 CVE-2024-52362 IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 1… App Connect Enterprise Certified Containers Operands 12.9.0+ Fix from $1,6002025-03-12 MEDIUM 6.5 CVE-2024-22340 IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of E… Common Cryptographic Architecture 7.5.52+ Fix from $1,6002025-03-11 MEDIUM 6.5 CVE-2024-49823 IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Mo… Common Cryptographic Architecture 7.5.52+ Fix from $1,6002025-03-11 MEDIUM 5.3 CVE-2024-47109 IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid… Sterling File Gateway 6.1.2.7 / 6.2.0.4+ Fix from $1,6002025-03-10 HIGH 7.1 CVE-2025-0162 IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenti… Aspera Shares 1.10.0+ Fix from $1,9502025-03-07 MEDIUM 5.3 CVE-2023-43052 IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input.… Control Center Mitigation only Fix from $1,6002025-03-07 MEDIUM 6.1 CVE-2023-35894 IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could… Sterling Control Center Mitigation only Fix from $1,6002025-03-07 HIGH 7.5 CVE-2024-51476 IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. Concert Software Mitigation only Fix from $1,9502025-03-06 HIGH 7.5 CVE-2024-41771 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 MEDIUM 6.5 CVE-2024-43169 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integr… Engineering Requirements Management Doors Next Mitigation only Fix from $1,6002025-03-03 HIGH 7.5 CVE-2024-41770 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 MEDIUM 5.4 CVE-2024-54179 IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vuln… Business Automation Workflow after 24.0.1 Fix from $1,6002025-03-03 MEDIUM 5.3 CVE-2024-55907 IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming … Cognos Analytics Mobile 1.1.21+ Fix from $1,6002025-03-02 MEDIUM 6.5 CVE-2024-41778 IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attack… Controller Mitigation only Fix from $1,6002025-03-01 CRITICAL 9.8 CVE-2025-0160 IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug… Storage Virtualize 8.5.0.14 / 8.6.0.6+ Fix from $2,3002025-02-28 CRITICAL 9.1 CVE-2025-0159 IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug… Storage Virtualize 8.5.0.14 / 8.6.0.6+ Fix from $2,3002025-02-28 MEDIUM 5.5 CVE-2024-54175 IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper check for unusual or exception… Mq Mitigation only Fix from $1,6002025-02-28 MEDIUM 5.5 CVE-2025-0985 IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local use… Mq Mitigation only Fix from $1,6002025-02-28 HIGH 8.8 CVE-2025-0975 IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape charac… Mq Appliance after 9.4.2 Fix from $1,9502025-02-28 MEDIUM 6.5 CVE-2024-56340 IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $1,6002025-02-28 MEDIUM 6.5 CVE-2025-0823 IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An atta… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $1,6002025-02-28 MEDIUM 6.5 CVE-2025-23225 IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid he… Mq Appliance after 9.4.2 Fix from $1,6002025-02-28 MEDIUM 5.5 CVE-2024-56812 IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information coul… Entirex Mitigation only Fix from $1,6002025-02-27