Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-9201HIGHLangflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handlingEPSS 0.4%CVE-2026-19300HIGHLangflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flowsEPSS 0.4%CVE-2024-54171HIGHIBM EntireX XML external entity injectionEPSS 0.4%CVE-2026-7657MEDIUMLangflow OSS is affected by server-side request forgery in provider validation and API request functionalityEPSS 0.4%CVE-2023-38018MEDIUMIBM Aspera Shares session fixationEPSS 0.4%CVE-2023-33851MEDIUMIBM PowerVM Hypervisor information disclosureEPSS 0.4%CVE-2026-10853HIGHIBM MQ queue manager is vulnerable to remote code executionEPSS 0.4%CVE-2026-16192HIGHIBM WebSphere Application Server Liberty is affected by a denial of serviceEPSS 0.4%CVE-2025-36387MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%CVE-2025-13379HIGHA SQL Injection vulnerability has been addressed in IBM Aspera ConsoleEPSS 0.4%CVE-2025-3050MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2016-0205LOWA vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authenticatiEPSS 0.4%CVE-2017-1452—IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privEPSS 0.4%CVE-2017-1382—IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissioEPSS 0.4%CVE-2017-1304—IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) durinEPSS 0.4%CVE-2025-36424MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%CVE-2024-35114MEDIUMIBM Control Center information disclosureEPSS 0.4%CVE-2018-1411—IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting EPSS 0.4%CVE-2024-45669MEDIUMIBM Security Verify Information Queue denial of serviceEPSS 0.4%CVE-2025-36222HIGHIBM Fusion insecure default configurationEPSS 0.4%