Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91203 | MEDIUM | 6.0 | A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged … | Sep 18, 2026 |
| CVE-2026-91202 | MEDIUM | 6.1 | A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then … | Sep 18, 2026 |
| CVE-2026-84241 | HIGH | 8.1 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization. | Sep 18, 2026 |
| CVE-2026-84239 | HIGH | 7.6 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an … | Sep 18, 2026 |
| CVE-2026-84108 | HIGH | 8.1 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation. | Sep 18, 2026 |
| CVE-2026-84106 | HIGH | 8.9 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | Sep 18, 2026 |
| CVE-2026-84105 | HIGH | 7.7 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an … | Sep 18, 2026 |
| CVE-2026-84089 | HIGH | 7.8 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. | Sep 18, 2026 |
| CVE-2026-84086 | HIGH | 7.2 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted … | Sep 18, 2026 |
| CVE-2026-84085 | HIGH | 8.1 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an … | Sep 18, 2026 |
| CVE-2026-84084 | HIGH | 8.8 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. | Sep 18, 2026 |
| CVE-2026-84083 | HIGH | 7.8 | IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged … | Sep 18, 2026 |
| CVE-2026-84082 | CRITICAL | 9.8 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an … | Sep 18, 2026 |
| CVE-2026-84081 | HIGH | 8.1 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation. | Sep 18, 2026 |
| CVE-2026-84078 | CRITICAL | 9.9 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting … | Sep 18, 2026 |
| CVE-2026-84077 | HIGH | 8.1 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability. | Sep 18, 2026 |
| CVE-2026-84076 | HIGH | 7.6 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. | Sep 18, 2026 |
| CVE-2026-84075 | CRITICAL | 9.9 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. | Sep 18, 2026 |
| CVE-2026-84074 | HIGH | 8.9 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | Sep 18, 2026 |
| CVE-2026-84073 | CRITICAL | 9.1 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in … | Sep 18, 2026 |
| CVE-2026-84071 | HIGH | 7.2 | IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a … | Sep 18, 2026 |
| CVE-2026-84070 | HIGH | 8.9 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | Sep 18, 2026 |
| CVE-2026-84064 | CRITICAL | 9.9 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in … | Sep 18, 2026 |
| CVE-2026-84036 | HIGH | 7.4 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. | Sep 18, 2026 |
| CVE-2026-84034 | HIGH | 8.8 | IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master … | Sep 18, 2026 |