3.1

CVSS3.1

CVE-2025-36410 - Multiple vulnerabilities found in IBM ApplinX.

IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.

πŸ“… Published: Jan. 20, 2026, 3:39 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 7:47 p.m.

5.4

CVSS3.1

CVE-2025-36409 - Multiple vulnerabilities found in IBM ApplinX.

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: Jan. 20, 2026, 3:37 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 7:46 p.m.

6.4

CVSS3.1

CVE-2025-36408 - Multiple vulnerabilities found in IBM ApplinX.

IBM ApplinX 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: Jan. 20, 2026, 3:33 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 7:46 p.m.

5.4

CVSS3.1

CVE-2025-36397 - Security vulnerabilities have been found in IBM Application Gateway

IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

πŸ“… Published: Jan. 20, 2026, 3:23 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 7:47 p.m.

5.4

CVSS3.1

CVE-2025-36396 - Security vulnerabilities have been found in IBM Application Gateway

IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: Jan. 20, 2026, 3:22 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 7:46 p.m.

6.3

CVSS3.1

CVE-2025-36115 - Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: Jan. 20, 2026, 3:18 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 9:56 p.m.

5.4

CVSS3.1

CVE-2025-36113 - Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr…

πŸ“… Published: Jan. 20, 2026, 3:15 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 9:57 p.m.

6.1

CVSS3.1

CVE-2025-36066 - Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading…

πŸ“… Published: Jan. 20, 2026, 3:14 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 9:57 p.m.

6.3

CVSS3.1

CVE-2025-36065 - Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: Jan. 20, 2026, 3:12 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 9:57 p.m.

6.3

CVSS3.1

CVE-2025-36063 - Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: Jan. 20, 2026, 3:10 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 5:33 p.m.
Total resulsts: 349182
Page 2056 of 34,919
Β« previous page Β» next page
Filters