Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56102
Total
4437
Critical
16640
High
16418
Medium
CVE ID Severity Score Description Published
CVE-2026-84031 CRITICAL 9.0 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. Sep 18, 2026
CVE-2026-82967 CRITICAL 9.8 IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the … Sep 18, 2026
CVE-2026-82896 HIGH 7.6 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability. Sep 18, 2026
CVE-2026-82893 HIGH 7.8 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. Sep 18, 2026
CVE-2026-82892 HIGH 8.1 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS … Sep 18, 2026
CVE-2026-82890 MEDIUM 5.9 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page … Sep 18, 2026
CVE-2026-82887 HIGH 8.8 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an … Sep 18, 2026
CVE-2026-82885 HIGH 8.8 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API. Sep 18, 2026
CVE-2026-82832 CRITICAL 9.6 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. Sep 18, 2026
CVE-2026-82340 CRITICAL 9.8 IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network … Sep 18, 2026
CVE-2026-81937 HIGH 7.2 IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can … Sep 18, 2026
CVE-2026-81933 HIGH 8.8 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL … Sep 18, 2026
CVE-2026-81669 HIGH 7.2 IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can … Sep 18, 2026
CVE-2026-81657 CRITICAL 9.8 IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. Sep 18, 2026
CVE-2026-81656 HIGH 8.8 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject … Sep 18, 2026
CVE-2026-81626 HIGH 8.6 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements … Sep 18, 2026
CVE-2026-81623 MEDIUM 6.3 IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation … Sep 18, 2026
CVE-2026-80442 CRITICAL 9.9 IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to … Sep 18, 2026
CVE-2026-80441 CRITICAL 9.8 IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject … Sep 18, 2026
CVE-2026-77528 MEDIUM 5.3 Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely … Sep 18, 2026
CVE-2026-76902 MEDIUM 5.0 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and … Sep 18, 2026
CVE-2026-76901 MEDIUM 5.8 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in … Sep 18, 2026
CVE-2026-76900 MEDIUM 6.8 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and … Sep 18, 2026
CVE-2026-76899 MEDIUM 5.7 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with … Sep 18, 2026
CVE-2026-75895 UNKNOWN — In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to … Sep 18, 2026