Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-36221 — Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the inst…

May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
9.8 CRITICAL
CVE-2025-36220 — Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
6.1 MEDIUM
CVE-2025-36148 — IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to …

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allo…

May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
5.4 MEDIUM
CVE-2025-36145 — Multiple Vulnerabilities in watsonx.data

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.

watsonx.data watsonxdata | Remote | Misconfiguration
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
7.6 HIGH
CVE-2025-36126 — IBM Cognos Analytics is affected by Cross-site scripting.

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows…

cognos_analytics cognos_transformer | Remote | Cross-Site Scripting
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
5.4 MEDIUM
CVE-2025-14290 — IBM webMethods Integration Sever is vulnerable to server-side request forgery

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). Th…

May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
5.5 MEDIUM
CVE-2025-13755 — IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcas…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local …

db2 | Information Disclosure
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
Showing 20 of 8287 Results