I

Vendor:

First CVE: Jul 23, 2013 · Active for 13 years

129
Total CVEs
More Total CVEs than 99% of tracked products
11.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact I over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 23, 2013
13 years ago
Most Recent CVE
Jun 22, 2026
33 days ago

CVE Severity & Scoring

I129 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local28 (21.7%)
Network97 (75.2%)
Unknown2 (1.6%)
Physical1 (0.8%)
Adjacent Network1 (0.8%)
Attack Complexity
Low118 (91.5%)
High9 (7.0%)
Unknown2 (1.6%)
User Interaction
None107 (82.9%)
Unknown2 (1.6%)
Required20 (15.5%)
Privileges Required
Low73 (56.6%)
High5 (3.9%)
None49 (38.0%)
Unknown2 (1.6%)

Top CVEs

Signals from CVEs in this product scope (129 CVEs).

129 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to
Jun 22, 20269.839NONO
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker co
Jun 22, 20269.137NONO
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized re
Jun 22, 20269.136NONO
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-co
Apr 30, 20269.836NONO
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
Jun 25, 20259.835NONO
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1
Jul 23, 20137.134NONO
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in comp
Jun 22, 20268.833NONO
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with admin
Jun 11, 20268.833NONO
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering securit
Mar 25, 20269.831NONO
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.
Jul 4, 20239.831NONO

Exploit Exposure

Signals from CVEs in this product scope (129 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.6% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (129 CVEs).

Media Mentions

Signals from CVEs in this product scope (129 CVEs).

Top CNAs Publishing CVEs For I

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.6147.80.3%00
7.5446.90.4%02
7.4546.80.5%02
7.3526.80.5%02
7.2407.10.4%00
7.147.71.9%00
6.128.02.4%00