Api Connect
Vendor:
First CVE: Dec 1, 2016 · Active for 9 years
81
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Api Connect over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2016
9 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
CVE Severity & Scoring
Api Connect81 CVEs
54%
27%
17%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (3.7%)
Network76 (93.8%)
Unknown0 (0.0%)
Physical1 (1.2%)
Adjacent Network1 (1.2%)
Attack Complexity
Low77 (95.1%)
High4 (4.9%)
Unknown0 (0.0%)
User Interaction
None65 (80.2%)
Unknown0 (0.0%)
Required16 (19.8%)
Privileges Required
Low24 (29.6%)
High6 (7.4%)
None51 (63.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (81 CVEs).
81 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13915CRITICAL IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. | Dec 26, 2025 | 9.8 | 42 | NO | NO |
CVE-2026-9074CRITICAL IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality. | Jul 8, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-3144CRITICAL IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credent | Jul 8, 2026 | 9.8 | 39 | NO | NO |
CVE-2019-4202CRITICAL IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain | Apr 15, 2019 | 10.0 | 32 | NO | NO |
CVE-2019-4155CRITICAL IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry. IBM X-Forc | Apr 8, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-4203CRITICAL IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-F | Apr 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-4008CRITICAL API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 1556 | Feb 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-1784CRITICAL IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807. | Dec 20, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-1789CRITICAL IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939. | Sep 7, 2018 | 9.9 | 31 | NO | NO |
CVE-2018-1469CRITICAL IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 1 | Apr 4, 2018 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (81 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (81 CVEs).
Media Mentions
Signals from CVEs in this product scope (81 CVEs).
Top CNAs Publishing CVEs For Api Connect
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.8.2 | 1 | 4.3 | 1.0% | 0 | 0 |
| 5.0.8.1 | 3 | 4.7 | 0.8% | 0 | 0 |
| 5.0.8.0 | 3 | 5.0 | 1.3% | 0 | 0 |
| 5.0.7.2 | 5 | 5.3 | 0.9% | 0 | 0 |
| 5.0.7.1 | 6 | 5.7 | 1.1% | 0 | 0 |
| 5.0.7.0 | 8 | 6.0 | 1.3% | 0 | 0 |
| 5.0.6.4 | 2 | 5.2 | 0.9% | 0 | 0 |
| 5.0.6.3 | 2 | 5.2 | 0.9% | 0 | 0 |
| 5.0.6.2 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.6.1 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.6.0 | 7 | 6.4 | 1.5% | 0 | 0 |
| 5.0.5.0 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.4.0 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.3.0 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.2.0 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.1.0 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.0.1 | 6 | 6.2 | 1.5% | 0 | 0 |
| 5.0.0.0 | 6 | 6.2 | 1.5% | 0 | 0 |
| 2018.4.1.7 | 1 | 7.5 | 0.8% | 0 | 0 |
| 10.0.6.0 | 1 | 5.5 | 0.2% | 0 | 0 |