π¨ CVE-2025-14753
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
π@cveNotify
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
π@cveNotify
Ibm
Security Bulletin: IBM Cloud Pak for Data is vulnerable to path traversal (CVE-2025-14753)
IBM Cloud Pak for Data is vulnerable to a path traversal attack. A remote attacker could send a specially crafted URL containing "dot dot" sequences (/../) to traverse directories and view arbitrary files on the system, potentially exposing sensitive information.
π¨ CVE-2025-14754
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
π@cveNotify
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
π@cveNotify
Ibm
Security Bulletin: IBM Cloud Pak for Data is vulnerable to OS command injection (CVE-2025-14754)
IBM Cloud Pak for Data is vulnerable to OS command injection due to improper validation of user-supplied input. An authenticated remote attacker could exploit this vulnerability to execute arbitrary commands with elevated privileges on the system, potentiallyβ¦
π¨ CVE-2025-15399
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
π@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administrationβ¦
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
π¨ CVE-2025-33141
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
π@cveNotify
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
π@cveNotify
π¨ CVE-2025-33147
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.
π@cveNotify
IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.
π@cveNotify
Ibm
Security Bulletin: IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities
There are vulnerabilities in multiple Open Source Software (OSS) components consumed by IBM Cognos Analytics application versions 12.0.4 and 12.1.3. This Security Bulletin addresses the affected versions and the rememdiation fixes. Please note that certainβ¦
π¨ CVE-2025-36045
IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
π@cveNotify
IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
π@cveNotify
Ibm
Security Bulletin: TS4300 Tape Library addresses security vulnerability CVE-2025-36045
Certain email-related functions in the web GUI and APIs did not enforce rate limiting, allowing authenticated users to generate excessive email traffic by repeatedly invoking email-sending requests. This could lead to email flooding, increased mail serverβ¦
π¨ CVE-2025-36147
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
Ibm
Security Bulletin: IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to cross-site scripting.
Current security configuration lacks specific content security directives, relying on a broad fallback policy in FTM SWIFT user interfaces (CVE-2025-36147).
π¨ CVE-2025-36178
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
π@cveNotify
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities in IBM Controller
Multiple vulnerabilities were addressed in IBM Controller version 11.2.0
π¨ CVE-2025-36421
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
π@cveNotify
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities in IBM Controller
Multiple vulnerabilities were addressed in IBM Controller version 11.2.0
π¨ CVE-2025-53837
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.
π@cveNotify
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.
π@cveNotify
GitHub
XRENDERING-693: XHTML printer does not protect against closing HTML m⦠· xwiki/xwiki-rendering@92bc809
β¦acro in raw output
* Escape raw output to prevent the injection of `{{/html}}`.
* Escape raw output to prevent the injection of `{{/html}}`.
π¨ CVE-2025-61682
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
π@cveNotify
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
π@cveNotify
GitHub
Release SMW 7.0.0 Β· SemanticMediaWiki/SemanticMediaWiki
Released on June 4, 2026 - RELEASE NOTES
Note: The provided source code links do not include required dependencies. The recommended way to install Semantic MediaWiki is documented in the installati...
Note: The provided source code links do not include required dependencies. The recommended way to install Semantic MediaWiki is documented in the installati...
π¨ CVE-2026-10027
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
π@cveNotify
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to unauthenticated remote code execution (CVE-2026-10027)
IBM MQ has addressed a heap out-of-bounds write vulnerability in the queue manager's message decompression handling that could allow an unauthenticated remote attacker with network access to the listener port to execute arbitrary code
π¨ CVE-2026-10030
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
π@cveNotify
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
π@cveNotify
Ibm
Security Bulletin: IBM MQ Console is vulnerable to privilege escalation
IBM MQ has addressed a missing authorization check in the IBM MQ Console that could allow a remote authenticated user with read-only console access to create and start queue managers on the host
π¨ CVE-2026-10575
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
π@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-10575)
IBM MQ has addressed an heap buffer overflow vulnerability when processing MQPUT operations with malformed distribution headers that could allow a remote authenticated attacker to cause a denial of service or potentially escalate privileges.
π¨ CVE-2026-10744
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
π@cveNotify
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
π@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation (CVE-2026-10744)
IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation when CONNAUTH is being used.
π¨ CVE-2026-10747
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
π@cveNotify
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
π@cveNotify
Ibm
Security Bulletin: IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing (CVE-2026β¦
IBM MQ Appliance has addressed a heap buffer overflow vulnerability in protocol message processing that could allow a remote attacker to cause a denial of service or execute arbitrary code prior to authentication.
π¨ CVE-2026-10751
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
π@cveNotify
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
π@cveNotify
Ibm
Security Bulletin: IBM MQ Java messaging is vulnerable to remote code execution (CVE-2026-10751)
IBM MQ has addressed a Java deserialization filter bypass in the IBM MQ JMS client that could allow a remote authenticated attacker to execute arbitrary code
π¨ CVE-2026-10841
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
π@cveNotify
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
π@cveNotify
Ibm
Security Bulletin: Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. IBM WebSphere Liberty has been updated within IBM CICS TX Advanced to address these vulnerabilities.
π¨ CVE-2026-10853
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
π@cveNotify
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-10853)
IBM MQ has addressed a heap buffer overflow vulnerability in the queue manager's cluster repository manager
π¨ CVE-2026-10858
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
π@cveNotify
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
π@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a denial of service attack (CVE-2026-10858)
IBM MQ for HPE NonStop is vulnerable to a denial of service issue caused by a heap buffer overflow.
π¨ CVE-2026-11375
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
π@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-11375)
IBM MQ has addressed a stack buffer overflow vulnerability in the queue manager's XA transaction handling that could allow a remote authenticated attacker to execute arbitrary code by sending a crafted transaction identifier