Cyber Resilience

← All vendors

IBM

CPE vendor key: ibm · 1,308 CVEs published in the last 24 months.

CVEs (365 d)
739
▲ +204 vs prior 30d
Avg CVSS (365 d)
6.51
over 739 CVEs
Avg EPSS pct (365 d)
0.19
higher = more likely exploited
KEV hit rate (365 d)
0.0%
0 of 739 added to CISA KEV
LLM-credited CVEs
0
none detected

Monthly CVE volume — last 24 months

2024202520260203
Each point is one calendar month. Bars in the severity card to the right slice the same volume by CVSS band.

Severity mix

CritHighMedLow
Stacked by CVSS band (Critical / High / Medium / Low) using the best available metric per CVE.

Top affected products (24 mo)

aix
165
i
154
db2
79
websphere_application_server
72
concert
65
vios
53
sterling_b2b_integrator
48
security_verify_access
41
infosphere_information_server
41
sterling_file_gateway
37
Distinct CVEs that include each product in their CPE configuration.

Top CWEs (24 mo)

CWE-79
149
CWE-209
48
CWE-770
46
CWE-22
44
CWE-78
41
CWE-787
36
CWE-327
28
CWE-532
25
CWE-497
25
CWE-250
25
Distinct CVEs assigned each weakness.

Recent CISA KEV adds (last 12 months)

AddedCVEProductKEV name
2026-08-04CVE-2026-9198LangflowIBM Langflow Code Injection Vulnerability
Filtered to KEV entries whose CISA vendor or product name matches this vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps that CPE-map to Microsoft).

Generated 23 August 2026 22:22 UTC .