Qradar
This hub aggregates every CVE we track for Qradar, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
21
CVEs tracked
0
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM16HIGH5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
0
0
2
2
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Qradar.
- CVE-2025-33141IBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.6.5
- CVE-2026-5522QRadar contains hard-coded credentials6.7
- CVE-2026-10025IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability8.2
- CVE-2026-13477IBM QRadar SIEM is vulnerable to remote code execution by privileged users4.7
- CVE-2024-56462IBM QRadar SIEM is vulnerable to using components with known vulnerabilities7.2
- CVE-2025-13995IBM QRadar SIEM Information Disclosure5.0
- CVE-2020-4980IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.6.5
- CVE-2020-4274IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.5.4
- CVE-2020-4294IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to...6.3
- CVE-2020-4272IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, w...8.8
- CVE-2020-4271IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897.6.3
- CVE-2020-4270IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.7.8
- CVE-2020-4269IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external comp...7.5
- CVE-2020-4268IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po...5.4
- CVE-2019-4654IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM ...4.8
Product normalization is registry-driven with AI assist and human review. How it works