VendorsIBMdb2all versions
Vulnerabilities

IBM DB2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

353CVEs
CVE-2024-25046
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
CVE-2024-31881
IBM Db2 denial of service
Published 2024-06-12 · Modified
6.5EPSS 0.006
CVE-2024-28762
IBM Db2 denial of service
Published 2024-06-12 · Modified
6.5EPSS 0.006
CVE-2023-29267
IBM Db2 denial of service
Published 2024-06-12 · Modified
6.5EPSS 0.006
CVE-2024-35152
IBM Db2 denial of service
Published 2024-08-14 · Modified
6.5EPSS 0.006
CVE-2024-31882
IBM Db2 denial of service
Published 2024-08-14 · Modified
6.5EPSS 0.006
CVE-2024-35136
IBM Db2 denial of service
Published 2024-08-14 · Modified
6.5EPSS 0.006
CVE-2024-37529
IBM Db2 denial of service
Published 2024-08-14 · Modified
6.5EPSS 0.006
CVE-2023-30443
IBM Db2 denial of service
Published 2024-12-19 · Analyzed
6.5EPSS 0.005
CVE-2024-54178
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
6.5EPSS 0.004
CVE-2026-11906
IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user
Published 2026-06-30 · Analyzed
6.5EPSS 0.004
CVE-2024-31880
IBM Db2 denial of service
Published 2024-10-23 · Modified
6.5EPSS 0.004
CVE-2024-41762
IBM Db2 denial of service
Published 2024-12-07 · Analyzed
6.5EPSS 0.004
CVE-2025-0915
IBM Db2 denial of service
Published 2025-05-05 · Modified
6.5EPSS 0.004
CVE-2024-37071
IBM Db2 denial of service
Published 2024-12-07 · Analyzed
6.5EPSS 0.004
CVE-2025-36366
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-3050
IBM Db2 denial of service
Published 2025-05-29 · Analyzed
6.5EPSS 0.004
CVE-2025-1000
IBM Db2 denial of service
Published 2025-05-05 · Modified
6.5EPSS 0.004
CVE-2025-36098
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-1992
IBM Db2 denial of service
Published 2025-05-05 · Modified
6.5EPSS 0.004
CVE-2025-2668
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-36001
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-36009
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2025-36387
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-36427
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-36424
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-2669
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
6.5EPSS 0.003
CVE-2026-1577
IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries
Published 2026-04-30 · Modified
6.5EPSS 0.003
CVE-2026-1352
IBM® Db2® is vulnerable to a trap or return SQLCODE -901 when compiling a specially crafted query with a defined index
Published 2026-04-22 · Analyzed
6.5EPSS 0.003
CVE-2025-36372
IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2025-36407
IBM Db2 Denial of Service
Published 2026-01-30 · Modified
6.5EPSS 0.003
CVE-2025-36006
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
6.5EPSS 0.003
CVE-2025-36008
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
6.5EPSS 0.003
CVE-2025-36423
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.5EPSS 0.003
CVE-2025-14689
IBM Db2 Denial of Service
Published 2026-02-17 · Analyzed
6.5EPSS 0.002
CVE-2025-36122
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic
Published 2026-04-30 · Analyzed
6.5EPSS 0.002
CVE-2025-13867
IBM Db2 Denial of Service
Published 2026-02-17 · Analyzed
6.5EPSS 0.002
CVE-2025-36425
IBM Db2 Information Disclosure
Published 2026-02-17 · Analyzed
6.5EPSS 0.002
CVE-2009-4325
The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."
Published 2009-12-16 · Modified
6.4EPSS 0.027
CVE-2018-1427
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a local attacker could overflow and cause a denial of service. IBM X-Force ID: 139072.
Published 2018-03-22 · Modified
6.2EPSS 0.004
← Prev6 / 9Next →