Vulnerabilities

Summary — last 7 days

New vulnerabilities2,844▲ 206 vs. last week
Critical / high1,323▼ 110 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
–

33 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (5.9)0.20%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
AnalyzedMedium (4.3)0.28%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.
AnalyzedMedium (4.3)0.37%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
AnalyzedMedium (6.5)0.36%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security.
AnalyzedMedium (4.3)0.27%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AnalyzedMedium (5.4)0.23%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalyzedMedium (5.7)0.41%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalyzedMedium (6.4)0.26%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalyzedMedium (4.3)0.43%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling.
ModifiedMedium (5.9)0.20%—IBM Watsonx.data Intelligence6/30/20269/29/2026
IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
ModifiedHigh (7.5)0.79%—IBM Security Guardium BIG Data Intelligence10/16/20206/17/2026
IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 175560.
ModifiedMedium (4.4)0.34%—SAP Data Intelligence8/12/20206/17/2026
Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to access confidential system configuration information, that should otherwise be restricted, leading to Information Disclosure.
ModifiedHigh (7.5)0.98%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418.
ModifiedMedium (4.3)1.1%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.
ModifiedMedium (4.3)0.90%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 161209.
ModifiedHigh (7.5)0.98%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. IBM X-Force ID: 1610141.
ModifiedMedium (5.3)1.2%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 161037.
ModifiedMedium (5.5)0.28%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035.
ModifiedMedium (5.5)0.28%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 160987.
ModifiedMedium (6.5)1.0%—IBM Security Guardium BIG Data Intelligence10/29/20196/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended parties. IBM X-Force ID: 160986.
ModifiedHigh (8.2)2.4%—IBM Security Guardium BIG Data Intelligence8/20/20196/17/2026
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 161419.
ModifiedHigh (7.5)1.7%—IBM Security Guardium BIG Data Intelligence8/20/20196/17/2026
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced by an actor. This weakness can be used to consume more resources than intended. IBM X-Force ID: 161417.
ModifiedHigh (7.5)2.2%—IBM Security Guardium BIG Data Intelligence8/20/20196/17/2026
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036.
ModifiedMedium (6.1)0.89%—IBM Security Guardium BIG Data Intelligence5/29/20186/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137777.
ModifiedHigh (7.5)2.0%—IBM Security Guardium BIG Data Intelligence5/29/20186/17/2026
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 137776.
Orbitaley — Vulnerabilities