Skip to main content

Daily materialized evidence profile

Vendor ibm

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
8,292
CVEs with mentions
695
Total mentions
850
CVEs with KEV
8
CVEs with PoC
3

Attack vector counts

Network
6,687
Adjacent network
127
Local
1,431
Physical
47

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2017-5638

Published Mar 11, 2017

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload atte…

CVSS 9.8 · Critical
evidence mentions
76
Buzz score
75.0
KEV listed

CVE-2022-47986

Published Feb 17, 2023

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specia…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
65.2
KEV listed

CVE-2014-3566

Published Oct 15, 2014

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clea…

CVSS 3.4 · Low
evidence mentions
12
Buzz score
38.6

CVE-2015-7450

Published Jan 2, 2016

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed

CVE-2025-13915

Published Dec 26, 2025

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
32.6