VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2026-10547MedAug 5, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache…

  • CVE-2026-4942MedJul 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.

  • CVE-2026-10852MedJun 22, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

  • CVE-2026-9320MedJun 22, 2026
    risk 0.38cvss 5.9epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to…

  • CVE-2024-40684MedMay 27, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default,…

  • CVE-2025-13916MedApr 1, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

  • CVE-2025-64648MedMar 25, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2025-64647MedMar 25, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

  • CVE-2025-13219MedMar 10, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.

  • CVE-2025-14456MedMar 3, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1

  • CVE-2025-36363MedMar 3, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2025-13490MedMar 3, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and…

  • CVE-2025-36379MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-33101MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.

  • CVE-2025-27903MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2024-43178MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-36253MedFeb 2, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-1722MedJan 20, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-1719MedJan 20, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2026-0990MedJan 15, 2026
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent…

  • CVE-2025-1721MedDec 26, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-13489MedDec 15, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2025-36150MedNov 24, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-36161MedNov 20, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

  • CVE-2023-49883MedOct 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2025-36064MedSep 22, 2025
    risk 0.38cvss 5.9epss 0.01

    IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2024-45671MedSep 10, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-1761MedSep 8, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-33102MedSep 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-33099MedSep 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.

  • CVE-2025-33084MedSep 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2025-36133MedSep 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.

  • CVE-2025-1759MedAug 18, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-36124MedAug 12, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration

  • CVE-2025-36020MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

  • CVE-2025-36005MedJul 24, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session…

  • CVE-2025-33020MedJul 23, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information.

  • CVE-2025-36062MedJul 21, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic.

  • CVE-2025-36107MedJul 21, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data.

  • CVE-2024-43190MedJul 7, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.

  • CVE-2024-22330MedJun 6, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2024-38341MedMay 28, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2024-55912MedMay 2, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2024-22314MedApr 16, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2022-43851MedApr 14, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2023-38272MedMar 27, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments.

  • CVE-2024-31896MedMar 25, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2024-45643MedMar 14, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

  • CVE-2024-28780MedFeb 19, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client  uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2024-49797MedFeb 6, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

Page 60 of 177