6.3

CVSS3.1

CVE-2025-36063 - Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

๐Ÿ“… Published: Jan. 20, 2026, 3:10 p.m. ๐Ÿ”„ Last Modified: Feb. 5, 2026, 5:33 p.m.

5.5

CVSS3.1

CVE-2025-36058 - Multiple security vulnerabilities are addressed in IBM Business Automation Workflow Containers fixeโ€ฆ

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information โ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 3:09 p.m. ๐Ÿ”„ Last Modified: Feb. 17, 2026, 5:29 p.m.

4.7

CVSS3.1

CVE-2025-36059 - Multiple security vulnerabilities are addressed in IBM Business Automation Workflow Containers fixeโ€ฆ

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls.

๐Ÿ“… Published: Jan. 20, 2026, 3:07 p.m. ๐Ÿ”„ Last Modified: Feb. 17, 2026, 5:24 p.m.

8.8

CVSS3.1

CVE-2025-33015 - Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

๐Ÿ“… Published: Jan. 20, 2026, 3:04 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

5.9

CVSS3.1

CVE-2025-1722 - Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

๐Ÿ“… Published: Jan. 20, 2026, 3:02 p.m. ๐Ÿ”„ Last Modified: Jan. 26, 2026, 7:40 p.m.

5.9

CVSS3.1

CVE-2025-1719 - Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

๐Ÿ“… Published: Jan. 20, 2026, 3:01 p.m. ๐Ÿ”„ Last Modified: Jan. 26, 2026, 7:41 p.m.

8.4

CVSS3.1

CVE-2025-14115 - IBM Sterling Connect:Direct for UNIX Container is affected by vulnerability where hard-coded credenโ€ฆ

IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBMยฎ Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses forย its own inbound authentication, outboโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 2:59 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-13925 - Multiple vulnerabilities in IBM Aspera Console

IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.

๐Ÿ“… Published: Jan. 20, 2026, 2:56 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:55 p.m.

8.4

CVSS3.1

CVE-2025-12985 - License Service: Privilege escalation vulnerability

IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image.

๐Ÿ“… Published: Jan. 20, 2026, 2:50 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-54817 -

A reflected cross-site scripting (xss) vulnerability exists in the autoPurge functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascript code execution. An attacker can provide a URL to a malicious website to trigger this vulnerability.

๐Ÿ“… Published: Jan. 20, 2026, 2:50 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 3:21 p.m.
Total resulsts: 346087
Page 1748 of 34,609
ยซ previous page ยป next page
Filters