Where
AND
-Infinity
0

Vendor Risk Score

See how ibm compares to other vendors in security performance

View Risk Score →

Software

ibm aix
43
ibm websphere application server feature pack for web services
36
ibm maximo asset management
25
ibm websphere portal
14
ibm business process manager
12
ibm control desk
12
ibm maximo asset management essentials
12
ibm tivoli it asset management for it
12
ibm db2 universal database
11
ibm infosphere data architect
11
ibm concert software
10
ibm lotus domino
10
ibm rational quality manager
10
ibm tivoli service request manager
10
ibm b2b sterling integrator
9
ibm maximo for life sciences
9
ibm maximo for nuclear power
9
ibm maximo for oil and gas
9
ibm maximo for transportation
9
ibm maximo for utilities
9
ibm maximo service desk
9
ibm rational team concert
9
ibm infosphere master data management server for product information management
8
ibm maximo for government
8
ibm qradar security information and event manager
8
ibm rational requirements composer
8
ibm sametime
8
ibm curam social program management
7
ibm db2 recovery expert for luw
7
ibm lotus domino mail server
7
ibm tivoli storage manager
7
ibm websphere mq appliance
7
ibm algo one
6
ibm db2
6
ibm engineering requirements management doors next generation
6
ibm ibm® db2® on cloud pak for data and db2 warehouse on cloud pak for data
6
ibm security verify governance
6
ibm watsonx.data intelligence
6
ibm api connect v12 onprem
5
ibm cognos analytics
5
ibm infosphere information server
5
ibm security verify access
5
ibm security verify access container
5
ibm verify identity access
5
ibm verify identity access container
5
ibm websphere message broker
5
ibm aspera faspex 5
4
ibm change and configuration management database
4
ibm cloud orchestrator
4
ibm cognos business intelligence
4

IBM PowerVM NovalinkThis PowerVM Novalink update is being released to address

Risk 30
Severity
3.9
First published (updated )

IBM Verify Identity AccessSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

Risk 17
Severity
3.1
First published (updated )

IBM Engineering AI HubPyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

Risk 20
Severity
3.7
First published (updated )

Apache TomcatApache Tomcat: AJP secret compared in non-constant time

Risk 22
Severity
3.7
First published (updated )

maven/io.netty:netty-handler-proxyNetty: HTTP Header Injection via HttpProxyHandler Disabled Validation

Risk 43
Severity
2.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/axiosAxios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

Risk 20
Severity
3.7
First published (updated )

Uuidjs Uuid Node.jsuuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID ve…

Risk 18
Severity
3.2
First published (updated )

Oracle JREInfoleak

Risk 16
Severity
2.9
First published (updated )

Oracle JRELast updated 2 June 2026

Risk 20
Severity
3.7
First published (updated )

Oracle JREInfoleak

Risk 16
Severity
2.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft azl3 xz 5.4.4-2XZ Utils: Buffer overflow in lzma_index_append()

Risk 29
Severity
1.7
First published (updated )

Microsoft azl3 openssh 9.8p1-5OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

Risk 15
Severity
2.5
First published (updated )

go/github.com/go-git/go-git/v5go-git: Missing validation decoding Index v4 files leads to panic

Risk 15
Severity
2.8
First published (updated )

IBM InfoSphere Information ServerIBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information

Risk 17
Severity
3.1
First published (updated )

PyTorch PyTorchPyTorch pt2 Loading deserialization

Risk 51
Severity
1.9
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/org.springframework:spring-webfluxServer Sent Event stream corruption

Risk 15
Severity
2.6
First published (updated )

Golang GoFileInfo can escape from a Root in os

Risk 15
Severity
2.5
First published (updated )

npm/fast-xml-parserfast-xml-parser has stack overflow in XMLBuilder with preserveOrder

Risk 31
Severity
2.7
EPSS
0.05%
First published (updated )

pip/flaskFlask session does not add `Vary: Cookie` header when accessed in some ways

Risk 16
Severity
2.3
EPSS
0.03%
First published (updated )

IBM watsonx.dataPrivileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.data

Risk 26
Severity
3.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/webpackwebpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

Risk 25
Severity
3.7
First published (updated )

npm/webpackwebpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects

Risk 25
Severity
3.7
First published (updated )

IBM Jazz Reporting ServiceIBM Jazz Reporting Service Denial of Service

Risk 19
Severity
3.5
First published (updated )

IBM Jazz Reporting ServiceIBM Jazz Reporting Service Information Disclosure

Risk 19
Severity
3.5
First published (updated )

IBM Jazz Reporting ServiceIBM Jazz Reporting Service Denial of Service

Risk 19
Severity
3.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/pipLimited path traversal when installing wheel archives

Risk 14
Severity
2
First published (updated )

IBM PowerVM HypervisorThis Power System update is being released to address

Risk 18
Severity
3.3
First published (updated )

maven/qos.ch/logback-coreMalicious logback.xml configuration file allows instantiation of arbitrary classes

Risk 19
Severity
1.8
EPSS
0.01%
First published (updated )

npm/jsdiffjsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Risk 31
Severity
2.7
EPSS
0.02%
First published (updated )

IBM ApplinXMultiple vulnerabilities found in IBM ApplinX.

Risk 19
Severity
3.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203