Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84031 | CRITICAL | 9.0 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | Sep 18, 2026 |
| CVE-2026-82967 | CRITICAL | 9.8 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the … | Sep 18, 2026 |
| CVE-2026-82896 | HIGH | 7.6 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability. | Sep 18, 2026 |
| CVE-2026-82893 | HIGH | 7.8 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. | Sep 18, 2026 |
| CVE-2026-82892 | HIGH | 8.1 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS … | Sep 18, 2026 |
| CVE-2026-82890 | MEDIUM | 5.9 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page … | Sep 18, 2026 |
| CVE-2026-82887 | HIGH | 8.8 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an … | Sep 18, 2026 |
| CVE-2026-82885 | HIGH | 8.8 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API. | Sep 18, 2026 |
| CVE-2026-82832 | CRITICAL | 9.6 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | Sep 18, 2026 |
| CVE-2026-82340 | CRITICAL | 9.8 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network … | Sep 18, 2026 |
| CVE-2026-81937 | HIGH | 7.2 | IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can … | Sep 18, 2026 |
| CVE-2026-81933 | HIGH | 8.8 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL … | Sep 18, 2026 |
| CVE-2026-81669 | HIGH | 7.2 | IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can … | Sep 18, 2026 |
| CVE-2026-81657 | CRITICAL | 9.8 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | Sep 18, 2026 |
| CVE-2026-81656 | HIGH | 8.8 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject … | Sep 18, 2026 |
| CVE-2026-81626 | HIGH | 8.6 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements … | Sep 18, 2026 |
| CVE-2026-81623 | MEDIUM | 6.3 | IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation … | Sep 18, 2026 |
| CVE-2026-80442 | CRITICAL | 9.9 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to … | Sep 18, 2026 |
| CVE-2026-80441 | CRITICAL | 9.8 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject … | Sep 18, 2026 |
| CVE-2026-77528 | MEDIUM | 5.3 | Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely … | Sep 18, 2026 |
| CVE-2026-76902 | MEDIUM | 5.0 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and … | Sep 18, 2026 |
| CVE-2026-76901 | MEDIUM | 5.8 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in … | Sep 18, 2026 |
| CVE-2026-76900 | MEDIUM | 6.8 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and … | Sep 18, 2026 |
| CVE-2026-76899 | MEDIUM | 5.7 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with … | Sep 18, 2026 |
| CVE-2026-75895 | UNKNOWN | — | In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to … | Sep 18, 2026 |