Ibm
102 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-13445
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component …
2026-07-17
CVE-2026-13446
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key…
2026-07-17
CVE-2026-13448
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerabil…
2026-07-17
CVE-2026-13473
HIGH 8.1
Storage Protect Client — IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect…
2026-07-17
CVE-2026-14499
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands…
2026-07-17
CVE-2026-14501
MEDIUM 4.3
Db2 Genius Hub — IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or…
2026-07-17
CVE-2026-14971
LOW 3.9
Powervm Novalink — IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may incr…
2026-07-17
CVE-2026-14979
MEDIUM 5.3
Engineering Lifecycle Management — IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 00…
2026-07-17
CVE-2026-15069
MEDIUM 5.4
Engineering Ai Hub — IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code …
2026-07-17
CVE-2026-15091
CRITICAL 9.3
Engineering Ai Hub — IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due …
2026-07-17
CVE-2026-15093
MEDIUM 4.3
Engineering Ai Hub — IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious we…
2026-07-17
CVE-2026-15322
HIGH 7.5
Engineering Ai Hub — IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information d…
2026-07-17
CVE-2026-15995
MEDIUM 5.4
Cognos Analytics — IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to …
2026-07-17
CVE-2026-4938
MEDIUM 6.5
Verify Identity Access — IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Ve…
2026-07-17
CVE-2026-4942
MEDIUM 5.9
I — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrad…
2026-07-17
CVE-2026-7364
LOW 3.1
Verify Identity Access — IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Ve…
2026-07-17
CVE-2026-7667
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to …
2026-07-17
CVE-2026-7754
HIGH 7.7
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to ins…
2026-07-17
CVE-2026-7755
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation …
2026-07-17
CVE-2026-7771
MEDIUM 5.5
Db2 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially cr…
2026-07-17
CVE-2026-7872
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the J…
2026-07-17
CVE-2026-8056
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime v…
2026-07-17
CVE-2026-8476
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based…
2026-07-17
CVE-2026-8481
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code valid…
2026-07-17
CVE-2026-8505
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows un…
2026-07-17
CVE-2026-8635
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by direct…
2026-07-17
CVE-2026-8859
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended …
2026-07-17
CVE-2026-8861
MEDIUM 5.3
Verify Identity Access — IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical er…
2026-07-17
CVE-2026-9103
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to imprope…
2026-07-17
CVE-2026-9135
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc…
2026-07-17
CVE-2026-9171
HIGH 7.5
Powervm Novalink — IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A r…
2026-07-17
CVE-2026-9198
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPE…
2026-07-17
CVE-2026-9202
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on an…
2026-07-17
CVE-2026-9762
HIGH 7.8
Db2 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url …
2026-07-17
CVE-2026-3144
HIGH 8.1
Api Connect — IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unaut…
2026-07-08
CVE-2026-9074
CRITICAL 9.1
Api Connect — IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL inject…
2026-07-08
CVE-2026-10109
CRITICAL 9.8
Db2 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to imprope…
2026-06-30
CVE-2026-10129
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerabi…
2026-06-30
CVE-2026-10134
CRITICAL 10
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process…
2026-06-30
CVE-2026-10140
CRITICAL 9.6
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of …
2026-06-30
CVE-2026-10546
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL co…
2026-06-30
CVE-2026-10560
HIGH 8.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_t…
2026-06-30
CVE-2026-10564
HIGH 8.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderCompon…
2026-06-30
CVE-2026-11541
HIGH 7.4
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through …
2026-06-30
CVE-2026-11546
HIGH 7.1
Websphere Application Server Liberty — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forg…
2026-06-30
CVE-2026-11594
HIGH 8.5
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the admin…
2026-06-30
CVE-2026-11595
MEDIUM 4.3
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information fr…
2026-06-30
CVE-2026-11708
CRITICAL 9.3
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the admin…
2026-06-30
CVE-2026-11712
CRITICAL 9.3
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the admin…
2026-06-30
CVE-2026-11714
HIGH 8.5
Websphere Application Server Liberty — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forg…
2026-06-30
CVE-2026-11806
HIGH 7.2
Websphere Application Server Liberty — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vul…
2026-06-30
CVE-2026-11906
MEDIUM 6.5
Db2 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Ser…
2026-06-30
CVE-2026-12084
MEDIUM 5.4
Ucd Ibm Devops Deploy — IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (C…
2026-06-30
CVE-2026-12085
MEDIUM 6.5
Ucd Ibm Urbancode Deploy — IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 …
2026-06-30
CVE-2026-12086
MEDIUM 6.2
Ucd Ibm Urbancode Deploy — IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy …
2026-06-30
CVE-2026-13449
HIGH 7.6
Business Automation Manager Open Editions — IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity inje…
2026-06-30
CVE-2026-13759
HIGH 7.5
Websphere Extreme Scale — IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStr…
2026-06-30
CVE-2026-13772
HIGH 7.5
Websphere Extreme Scale — IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied…
2026-06-30
CVE-2026-13773
MEDIUM 6
Websphere Extreme Scale — IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere…
2026-06-30
CVE-2026-3602
MEDIUM 4.7
App Connect Enterprise — IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus …
2026-06-30
CVE-2026-7663
CRITICAL 9.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project res…
2026-06-30
CVE-2026-7803
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow …
2026-06-30
CVE-2026-7871
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full appli…
2026-06-30
CVE-2026-7873
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read…
2026-06-30
CVE-2026-7874
CRITICAL 9.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use…
2026-06-30
CVE-2026-9002
MEDIUM 6.5
Websphere Extreme Scale — IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of serv…
2026-06-30
CVE-2026-9836
LOW 3.5
Infosphere Information Server — IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerabi…
2026-06-30
CVE-2025-12530
MEDIUM 5.9
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that cou…
2026-06-30
CVE-2025-36319
MEDIUM 4.3
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporar…
2026-06-30
CVE-2025-36320
MEDIUM 6.4
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vu…
2026-06-30
CVE-2025-36321
MEDIUM 5.7
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker co…
2026-06-30
CVE-2025-36323
MEDIUM 5.4
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerabi…
2026-06-30
CVE-2025-36324
MEDIUM 4.3
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). T…
2026-06-30
CVE-2025-36327
MEDIUM 6.5
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security …
2026-06-30
CVE-2025-36328
MEDIUM 4.3
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive inf…
2026-06-30
CVE-2025-36333
MEDIUM 4.3
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthor…
2026-06-30
CVE-2025-36336
MEDIUM 5.9
Watsonx.Data Intelligence — IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an atta…
2026-06-30
CVE-2025-36359
HIGH 8.1
Devops Automation — IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which c…
2026-06-30
CVE-2025-36372
MEDIUM 5.5
Db2 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Ser…
2026-06-30
CVE-2026-10561
CRITICAL 10
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution com…
2026-06-22
CVE-2026-10845
HIGH 7.3
Websphere Application Server — IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain u…
2026-06-22
CVE-2026-10852
MEDIUM 5.9
Websphere Application Server — IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of serv…
2026-06-22
CVE-2026-11372
MEDIUM 5.4
Tririga Application Platform — IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability…
2026-06-22
CVE-2026-12628
CRITICAL 9.1
Storage Protect Client — IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 throug…
2026-06-22
CVE-2026-7253
MEDIUM 5.3
Ibm Watson Speech Services Cartridge — IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gate…
2026-06-22
CVE-2026-7664
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project res…
2026-06-22
CVE-2026-8059
MEDIUM 6.1
Datacap — IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-s…
2026-06-22
CVE-2026-8636
MEDIUM 5.5
Datacap — IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to re…
2026-06-22
CVE-2026-8646
HIGH 7.4
Websphere Application Server — IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 2…
2026-06-22
CVE-2026-8858
HIGH 7.5
Websphere Application Server — IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code ex…
2026-06-22
CVE-2026-9006
HIGH 7.4
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Aja…
2026-06-22
CVE-2026-9071
HIGH 7.5
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through …
2026-06-22
CVE-2026-9072
HIGH 8.1
Websphere Application Server — IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Managem…
2026-06-22
CVE-2026-9320
MEDIUM 5.9
Websphere Application Server — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through …
2026-06-22
CVE-2026-9610
LOW 2.3
Datacap — IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or fun…
2026-06-22
CVE-2025-2669
MEDIUM 6
Db2 On Cloud Pak For Data And Db2 Warehouse On Cloud Pak For Data — IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could a…
2026-06-22
CVE-2025-33128
MEDIUM 5.4
Engineering Workflow Management — IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 i…
2026-06-22
CVE-2026-4870
HIGH 7.5
Qiskit Sdk — IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denia…
2026-06-12
CVE-2026-3341
MEDIUM 5.4
Langflow Desktop — IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). Thi…
2026-06-11
CVE-2026-4096
MEDIUM 6.5
Devops Plan — IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of i…
2026-06-11
CVE-2026-7787
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information…
2026-06-11
CVE-2026-7870
HIGH 8.8
I — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call…
2026-06-11