Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-16856
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.
I
No fix yet
HIGH 8.8
CVE-2026-16906
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization …
I
No fix yet
HIGH 8.1
CVE-2026-16904
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during mo…
I
after 7.6
HIGH 7.7
CVE-2026-16863
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
I
after 7.6
HIGH 7.6
CVE-2026-16907
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.
I
after 7.6
CRITICAL 9.8
CVE-2026-18847
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
I
No fix yet
HIGH 8.8
CVE-2026-18683
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user…
I
No fix yet
HIGH 8.1
CVE-2026-18499
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
Websphere Application Server
No fix yet
HIGH 8.3
CVE-2026-17095
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
I
No fix yet
HIGH 8.1
CVE-2026-18098
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XM…
I
No fix yet
HIGH 7.1
CVE-2026-17094
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal…
I
Fix unknown
MEDIUM 5.4
CVE-2026-16694
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…
I
No fix yet
CRITICAL 9.8
CVE-2026-17617
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…
Application Gateway Operator
after 26.6.0
CRITICAL 9.8
CVE-2026-8400
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I…
Websphere Application Server
No fix yet
MEDIUM 5.3
CVE-2026-18531
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signin…
Maximo Application Suite
9.0.28 / 9.1.20+
CRITICAL 9.8
CVE-2026-10025
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…
Qradar Security Information And Event Manager
No fix yet
HIGH 8.8
CVE-2026-13477
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c…
Qradar Security Information And Event Manager
No fix yet
MEDIUM 5.3
CVE-2026-12762
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in man…
Business Automation Insights
No fix yet
HIGH 8.5
CVE-2026-11536
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Websphere Application Server
8.5.5.29 / 9.0.5.28+
CRITICAL 9.8
CVE-2026-12943
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…
Hardware Management Console
10.3.1064.1 / 11.1.1112.1+
CRITICAL 9.8
CVE-2026-12118
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…
Webmethods Integration
No fix yet
HIGH 7.5
CVE-2026-12733
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
Datapower Gateway
10.5.0.22 / 10.6.0.10+
MEDIUM 5.3
CVE-2026-11904
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…
Verify Identity Access
after 11.0.2
HIGH 7.8
CVE-2026-10535
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
Db2
12.1.5+
HIGH 7.5
CVE-2026-10545
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external w…
Planning Analytics Local
after 2.1.21
MEDIUM 5.5
CVE-2026-10695
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
Db2
12.1.5+
MEDIUM 6.3
CVE-2024-40683
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.…
Operations Analytics Log Analysis
after 1.3.8.4
MEDIUM 6.1
CVE-2025-0152
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site…
Engineering Requirements Management Doors Web Access
after 9.7.2.11
HIGH 7.5
CVE-2024-25039
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of …
Engineering Requirements Management Doors Web Access
after 9.7.2.11
HIGH 7.5
CVE-2026-9322
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of …
Websphere Application Server
8.5.5.31 / 9.0.5.29+