Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56102
Total
4437
Critical
16640
High
16418
Medium
CVE ID Severity Score Description Published
CVE-2026-91203 MEDIUM 6.0 A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged … Sep 18, 2026
CVE-2026-91202 MEDIUM 6.1 A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then … Sep 18, 2026
CVE-2026-84241 HIGH 8.1 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization. Sep 18, 2026
CVE-2026-84239 HIGH 7.6 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an … Sep 18, 2026
CVE-2026-84108 HIGH 8.1 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation. Sep 18, 2026
CVE-2026-84106 HIGH 8.9 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. Sep 18, 2026
CVE-2026-84105 HIGH 7.7 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an … Sep 18, 2026
CVE-2026-84089 HIGH 7.8 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. Sep 18, 2026
CVE-2026-84086 HIGH 7.2 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted … Sep 18, 2026
CVE-2026-84085 HIGH 8.1 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an … Sep 18, 2026
CVE-2026-84084 HIGH 8.8 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. Sep 18, 2026
CVE-2026-84083 HIGH 7.8 IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged … Sep 18, 2026
CVE-2026-84082 CRITICAL 9.8 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an … Sep 18, 2026
CVE-2026-84081 HIGH 8.1 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation. Sep 18, 2026
CVE-2026-84078 CRITICAL 9.9 IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting … Sep 18, 2026
CVE-2026-84077 HIGH 8.1 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability. Sep 18, 2026
CVE-2026-84076 HIGH 7.6 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. Sep 18, 2026
CVE-2026-84075 CRITICAL 9.9 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. Sep 18, 2026
CVE-2026-84074 HIGH 8.9 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. Sep 18, 2026
CVE-2026-84073 CRITICAL 9.1 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in … Sep 18, 2026
CVE-2026-84071 HIGH 7.2 IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a … Sep 18, 2026
CVE-2026-84070 HIGH 8.9 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. Sep 18, 2026
CVE-2026-84064 CRITICAL 9.9 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in … Sep 18, 2026
CVE-2026-84036 HIGH 7.4 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. Sep 18, 2026
CVE-2026-84034 HIGH 8.8 IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master … Sep 18, 2026