Vulnerability index

Browse CVEs

6,286 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-8644 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.0 CVE-2026-9311 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.0 CVE-2026-9319 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 HIGH 8.5 CVE-2026-9330 IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web S… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-06-01 HIGH 7.5 CVE-2026-8180 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-8405 IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive … Guardium Data Protection Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-9035 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $1,6002026-05-27 HIGH 8.8 CVE-2026-8179 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $1,9502026-05-27 CRITICAL 9.8 CVE-2026-8175 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $2,3002026-05-27 CRITICAL 9.1 CVE-2026-7876 IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage … Aspera High Speed Transfer Server For Cloud Pak For Integration 1.5.20+ Fix from $2,3002026-05-27 HIGH 7.8 CVE-2026-7365 IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing … Operations Analytics Log Analysis Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-6938 IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. Db2 after 12.1.4 Fix from $1,9502026-05-27 MEDIUM 5.3 CVE-2026-7254 IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users. Openbmc after 1110.11 Fix from $1,6002026-05-27 HIGH 7.5 CVE-2026-6051 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small s… Db2 after 12.1.4 Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-6052 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. Db2 after 12.1.4 Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-6936 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) co… I after 7.6 Fix from $1,6002026-05-27 MEDIUM 5.9 CVE-2026-5516 IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypas… Websphere Application Server after 26.0.0.5 Fix from $1,6002026-05-27 MEDIUM 5.5 CVE-2026-5515 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. App Connect Enterprise 13.0.7.1+ Fix from $1,6002026-05-27 MEDIUM 5.5 CVE-2026-6053 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partit… Db2 after 12.1.4 Fix from $1,6002026-05-27 HIGH 8.8 CVE-2026-5065 IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own… Controller 11.1.3+ Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-4410 IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Serv… Websphere Application Server after 26.0.0.5 Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-3623 IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privilege… Netezza Performance Server Replication Services 3.0.5.1+ Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-3676 IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could a… Cloud Application Performance Managemen Mitigation only Fix from $1,6002026-05-27 HIGH 7.5 CVE-2026-3366 IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote … Infosphere Optim Test Data Fabrication Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-1718 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transact… Db2 after 12.1.4 Fix from $1,9502026-05-27 HIGH 8.2 CVE-2025-3633 IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $1,9502026-05-27 HIGH 8.8 CVE-2024-56462 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and use… Qradar Security Information And Event Manager Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.8 CVE-2024-40684 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.… Operations Analytics Log Analysis Mitigation only Fix from $2,3002026-05-27 MEDIUM 5.3 CVE-2024-28765 IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive in… Security Directory Integrator 7.2.0.15 / 10.0.0.3+ Fix from $1,6002026-05-27 HIGH 7.2 CVE-2026-4051 IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exp… Engineering Lifecycle Management Mitigation only Fix from $1,9502026-05-26