|
151
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient re…
Update
|
CWE-676
Use of Potentially Dangerous Function
|
CVE-2026-14501
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
152
|
3.9 |
LOW
Local
|
-
|
-
|
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default co…
Update
|
CWE-16
Configuration
|
CVE-2026-14971
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
153
|
5.3 |
MEDIUM
Network
|
-
|
-
|
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remo…
Update
|
CWE-776
XML Entity Expansion
|
CVE-2026-14979
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
154
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.
Update
|
CWE-78
OS Command
|
CVE-2026-15069
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
155
|
9.3 |
CRITICAL
Network
|
-
|
-
|
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-15091
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
156
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
Update
|
CWE-601
Open Redirect
|
CVE-2026-15093
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
157
|
7.5 |
HIGH
Network
|
-
|
-
|
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
Update
|
CWE-598
Information Exposure Through Query Strings in GET Request
|
CVE-2026-15322
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
158
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race…
Update
|
CWE-362
Race Condition
|
CVE-2026-15995
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
159
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Contain…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-4938
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
160
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configu…
Update
|
CWE-757
Algorithm Downgrade
|
CVE-2026-4942
|
2026-07-21 02:15 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|