Filtered by vendor Ibm
Subscriptions
Total
8966 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12733 | 1 Ibm | 5 Datapower Gateway, Datapower Gateway 1050, Datapower Gateway 1060 and 2 more | 2026-07-31 | 7.5 High |
| IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. | ||||
| CVE-2026-12946 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-07-31 | 9.9 Critical |
| IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. | ||||
| CVE-2026-13435 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-07-31 | 9.9 Critical |
| IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. | ||||
| CVE-2026-12940 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-07-31 | 9.8 Critical |
| IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables. | ||||
| CVE-2026-13444 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-07-30 | 8.1 High |
| IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace. | ||||
| CVE-2026-11536 | 1 Ibm | 1 Websphere Application Server | 2026-07-30 | 8.5 High |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. | ||||
| CVE-2026-10569 | 1 Ibm | 6 Devops Deploy, Ucd Ibm Devops Deploy, Ucd Ibm Urbancode Deploy and 3 more | 2026-07-30 | 4.3 Medium |
| IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step. | ||||
| CVE-2026-12118 | 1 Ibm | 2 Webmethods Integration, Webmethods Integration On Prem | 2026-07-30 | 9.8 Critical |
| IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | ||||
| CVE-2025-36374 | 1 Ibm | 3 Datapower Gateway 1050, Datapower Gateway 1060, Datapower Gateway 106cd | 2026-07-30 | 5.5 Medium |
| IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. | ||||
| CVE-2026-9322 | 1 Ibm | 2 Websphere Application Server, Websphere Application Server Liberty | 2026-07-30 | 7.5 High |
| IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. | ||||
| CVE-2026-12943 | 1 Ibm | 3 Hardware Management Console, Hmc V10310500, Hmc V11111100 | 2026-07-30 | 9.8 Critical |
| IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | ||||
| CVE-2026-10545 | 1 Ibm | 1 Planning Analytics Local | 2026-07-30 | 7.5 High |
| IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions. | ||||
| CVE-2026-12086 | 1 Ibm | 6 Devops Deploy, Ucd Ibm Devops Deploy, Ucd Ibm Urbancode Deploy and 3 more | 2026-07-30 | 6.2 Medium |
| IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy stores potentially sensitive information in log files that could be read by a local user. | ||||
| CVE-2025-36336 | 1 Ibm | 3 Software Hub, Watsonx.data Intelligence, Watsonxdata Intelligence | 2026-07-30 | 5.9 Medium |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | ||||
| CVE-2025-12530 | 1 Ibm | 3 Software Hub, Watsonx.data Intelligence, Watsonxdata Intelligence | 2026-07-30 | 5.9 Medium |
| IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | ||||
| CVE-2026-10842 | 1 Ibm | 3 Websphere Application Server, Websphere Application Server Liberty, Websphere Application Server Liberty | 2026-07-30 | 7.5 High |
| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. | ||||
| CVE-2026-11904 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-07-30 | 5.3 Medium |
| IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | ||||
| CVE-2026-14980 | 1 Ibm | 2 Websphere Application Server, Websphere Application Server Liberty | 2026-07-30 | 8.3 High |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. | ||||
| CVE-2026-11897 | 1 Ibm | 2 Websphere Application Server, Websphere Application Server Liberty | 2026-07-30 | 7.5 High |
| IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | ||||
| CVE-2026-11885 | 1 Ibm | 1 Powervm Hypervisor | 2026-07-30 | 8.4 High |
| IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity. | ||||