Qradar
21 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Qradar, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Qradar CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 2 |
| 2026-09 | 2 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High5
- Medium16
Latest CVEs
The 15 most recently published vulnerabilities affecting Qradar.
- CVE-2025-33141IBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.6.5
- CVE-2026-5522QRadar contains hard-coded credentials6.7
- CVE-2026-10025IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability8.2
- CVE-2026-13477IBM QRadar SIEM is vulnerable to remote code execution by privileged users4.7
- CVE-2024-56462IBM QRadar SIEM is vulnerable to using components with known vulnerabilities7.2
- CVE-2025-13995IBM QRadar SIEM Information Disclosure5.0
- CVE-2020-4980IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.6.5
- CVE-2020-4274IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.5.4
- CVE-2020-4294IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to...6.3
- CVE-2020-4272IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, w...8.8
- CVE-2020-4271IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897.6.3
- CVE-2020-4268IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po...5.4
- CVE-2020-4270IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.7.8
- CVE-2020-4269IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external comp...7.5
- CVE-2019-4594IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit t...5.9
Product grouping is registry-driven, with AI assist and human review. How it works