Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

Found 69 results / 5232 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-19875 Unauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in Langflow — Langflow OSS CWE-306 7.5 High 2026-08-19
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint — Langflow OSS CWE-307 9.1 Critical 2026-08-13
CVE-2026-17624 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling — Langflow OSS CWE-94 8.5 High 2026-08-05
CVE-2026-17633 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling — Langflow OSS CWE-94 8.5 High 2026-08-05
CVE-2026-17632 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling — Langflow OSS CWE-94 8.8 High 2026-08-05
CVE-2026-9196 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling — Langflow OSS CWE-94 8.1 High 2026-08-05
CVE-2026-8182 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling — Langflow OSS CWE-94 8.8 High 2026-08-05
CVE-2026-9201 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling — Langflow OSS CWE-326 8.8 High 2026-08-05
CVE-2026-8478 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling — Langflow OSS CWE-94 8.8 High 2026-08-05
CVE-2026-8183 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement — Langflow OSS CWE-22 7.7 High 2026-08-05
CVE-2026-7658 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement — Langflow OSS CWE-22 6.5 Medium 2026-08-05
CVE-2026-9130 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement — Langflow OSS 7.1 High 2026-08-05
CVE-2026-10547 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement — Langflow OSS CWE-284 5.9 Medium 2026-08-05
CVE-2026-7869 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement — Langflow OSS CWE-22 5.4 Medium 2026-08-05
CVE-2026-8470 Langflow is affected by weaknesses in secret handling and sensitive configuration access — Langflow OSS CWE-327 7.4 High 2026-08-05
CVE-2026-9205 Langflow is affected by weaknesses in secret handling and sensitive configuration access — Langflow OSS CWE-338 7.4 High 2026-08-05
CVE-2026-10128 Langflow is affected by weaknesses in secret handling and sensitive configuration access — Langflow OSS CWE-200 6.5 Medium 2026-08-05
CVE-2026-9081 Langflow OSS is affected by server-side request forgery in provider validation and API request functionality — Langflow OSS CWE-918 7.1 High 2026-08-05
CVE-2026-7657 Langflow OSS is affected by server-side request forgery in provider validation and API request functionality — Langflow OSS CWE-918 6.5 Medium 2026-08-05
CVE-2026-17625 Langflow is affected by OS Command Injection in Model Context Protocol features — Langflow OSS CWE-78 7.2 High 2026-08-05
CVE-2026-17623 Langflow is affected OS Command Injection in Model Context Protocol features — Langflow OSS CWE-78 8.8 High 2026-08-05
CVE-2026-17630 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-184 7.2 High 2026-08-05
CVE-2026-17626 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-266 8.8 High 2026-08-05
CVE-2026-8446 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-306 7.5 High 2026-08-05
CVE-2026-7646 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-22 6.5 Medium 2026-08-05
CVE-2026-9077 Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features — Langflow OSS CWE-807 8.5 High 2026-08-05
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent — Langflow OSS CWE-94 9.9 Critical 2026-07-30
CVE-2026-13444 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-520 - - 2026-07-30
CVE-2026-10700 Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files — Langflow OSS CWE-639 6.5 Medium 2026-07-30
CVE-2026-13435 Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure — Langflow OSS CWE-94 9.9 Critical 2026-07-30

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.