8.8
CVE-2026-26119 - Windows Admin Center Elevation of Privilege Vulnerability
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
9.3
CVE-2026-1670 - Honeywell CCTV Products Missing Authentication for Critical Function
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
4.8
CVE-2025-62183 - Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerabiβ¦
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.
4.4
CVE-2025-13333 - IBM WebSphere Application Server could provide weaker than expected security
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
8.8
CVE-2025-13689 - DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environment
IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to unrestricted file uploads.
6.9
CVE-2026-2629 - jishi node-sonos-http-api TTS Provider mac-os.js Promise os command injection
A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the file lib/tts-providers/mac-os.js of the component TTS Provider. This manipulation of the argument phrase causes os command injection. It is possible toβ¦
4.3
CVE-2023-38005 - Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affecβ¦
IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauthorized tasks due to improper access controls.
6.1
CVE-2025-33135 - IBM Financial Transaction Manager for ACH Services and Check Services is impacted by multiple vulneβ¦
IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform 3.0.0.0 through 3.0.5.4 Interim Fix 027 IBM Financial Transaction Manager for Check Services v3 (Multiplatforms) is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to eβ¦
7.4
CVE-2025-33088 - Multiple Vulnerabilities in IBM Concert Software.
IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.
3.8
CVE-2025-36183 - Privileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.β¦
IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.