VendorsIBMdb2any version
Vulnerabilities

IBM DB2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

133CVEs
CVE-2024-37071
IBM Db2 denial of service
Published 2024-12-07 · Analyzed
6.5EPSS 0.004
CVE-2025-36366
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-3050
IBM Db2 denial of service
Published 2025-05-29 · Analyzed
6.5EPSS 0.004
CVE-2025-1000
IBM Db2 denial of service
Published 2025-05-05 · Modified
6.5EPSS 0.004
CVE-2025-36098
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-1992
IBM Db2 denial of service
Published 2025-05-05 · Modified
6.5EPSS 0.004
CVE-2025-2668
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-36001
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-36009
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-36387
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-36427
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-36424
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-2669
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
6.5EPSS 0.003
CVE-2026-1577
IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries
Published 2026-04-30 · Modified
6.5EPSS 0.003
CVE-2026-1352
IBM® Db2® is vulnerable to a trap or return SQLCODE -901 when compiling a specially crafted query with a defined index
Published 2026-04-22 · Analyzed
6.5EPSS 0.003
CVE-2025-36372
IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2025-36407
IBM Db2 Denial of Service
Published 2026-01-30 · Modified
6.5EPSS 0.003
CVE-2025-36006
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
6.5EPSS 0.003
CVE-2025-36008
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
6.5EPSS 0.003
CVE-2025-36423
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-14689
IBM Db2 Denial of Service
Published 2026-02-17 · Analyzed
6.5EPSS 0.002
CVE-2025-36122
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic
Published 2026-04-30 · Analyzed
6.5EPSS 0.002
CVE-2025-13867
IBM Db2 Denial of Service
Published 2026-02-17 · Analyzed
6.5EPSS 0.002
CVE-2025-36425
IBM Db2 Information Disclosure
Published 2026-02-17 · Analyzed
6.5EPSS 0.002
CVE-2025-36353
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.2EPSS 0.002
CVE-2025-36123
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.2EPSS 0.001
CVE-2026-10695
IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries
Published 2026-07-30 · Analyzed
6.2EPSS 0.001
CVE-2025-36185
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
6.2EPSS 0.001
CVE-2023-25930
IBM Db2 denial of service
Published 2023-04-28 · Modified
5.9EPSS 0.010
CVE-2026-7771
IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service
Published 2026-07-17 · Analyzed
5.5EPSS 0.001
CVE-2026-18097
IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
Published 2026-08-12 · Analyzed
5.5EPSS 0.001
CVE-2026-6053
IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables
Published 2026-05-27 · Analyzed
5.5EPSS 0.001
CVE-2025-13755
IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets
Published 2026-05-26 · Analyzed
5.5EPSS 0.001
CVE-2025-36136
IBM denial of service
Published 2025-11-07 · Analyzed
5.5EPSS 0.001
CVE-2025-1493
IBM Db2 denial of service
Published 2025-05-05 · Modified
5.3EPSS 0.003
CVE-2025-36428
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
5.3EPSS 0.003
CVE-2023-33854
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
5.3EPSS 0.003
CVE-2025-14688
IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations
Published 2026-04-30 · Analyzed
5.3EPSS 0.002
CVE-2020-4976
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.
Published 2021-03-11 · Modified
5.1EPSS 0.003
CVE-2008-3959
IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.
Published 2008-09-09 · Modified
5.0EPSS 0.022
← Prev3 / 4Next →