Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

Found 69 results / 5232 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-12942 Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-22 7.5 High 2026-07-30
CVE-2026-12945 Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-639 7.1 High 2026-07-30
CVE-2026-12940 Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-78 9.8 Critical 2026-07-30
CVE-2026-13442 Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-520 7.1 High 2026-07-28
CVE-2026-13445 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-639 8.1 High 2026-07-17
CVE-2026-13446 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-798 9.8 Critical 2026-07-17
CVE-2026-13448 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS 8.1 High 2026-07-17
CVE-2026-14499 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-78 8.8 High 2026-07-17
CVE-2026-7667 Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing — Langflow OSS CWE-22 8.8 High 2026-07-17
CVE-2026-7754 SSRF Protection Configuration Vulnerability — Langflow OSS 7.7 High 2026-07-17
CVE-2026-7755 MCP Server Configuration Validator Bypass via File Upload API — Langflow OSS 8.8 High 2026-07-17
CVE-2026-7872 Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass — Langflow OSS CWE-22 7.5 High 2026-07-17
CVE-2026-8056 Parameter Injection Vulnerability in API Graph Execution Engine — Langflow OSS CWE-94 8.8 High 2026-07-17
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability — Langflow OSS CWE-502 9.9 Critical 2026-07-17
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint — Langflow OSS CWE-94 9.9 Critical 2026-07-17
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution — Langflow OSS 9.8 Critical 2026-07-17
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component — Langflow OSS CWE-94 9.9 Critical 2026-07-17
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header — Langflow OSS CWE-22 9.9 Critical 2026-07-17
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint — Langflow OSS CWE-306 9.8 Critical 2026-07-17
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation — Langflow OSS CWE-94 9.9 Critical 2026-07-17
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation — Langflow OSS CWE-94 9.8 Critical 2026-07-17
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution — Langflow OSS CWE-306 9.8 Critical 2026-07-17
CVE-2026-10129 SSRF via HTTP Redirect Following in Langflow API Request Component — Langflow OSS CWE-918 8.5 High 2026-06-30
CVE-2026-10134 Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows — Langflow OSS CWE-94 10.0 Critical 2026-06-30
CVE-2026-10140 Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem — Langflow OSS CWE-639 9.6 Critical 2026-06-30
CVE-2026-10546 DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component — Langflow OSS CWE-918 7.1 High 2026-06-30
CVE-2026-10560 Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS — Langflow OSS CWE-287 8.2 High 2026-06-30
CVE-2026-10564 SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection — Langflow OSS CWE-918 8.2 High 2026-06-30
CVE-2026-7663 Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass — Langflow OSS CWE-285 9.1 Critical 2026-06-30
CVE-2026-7803 Flow Validation Bypass via Empty Component Type Field — Langflow OSS CWE-20 9.8 Critical 2026-06-30

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.