Guardian
Guardian Language-system: vulnerabilidades y CVE
Guardian Language-system tiene 21 vulnerabilidades publicadas, 21 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses21
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34117 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"php jobs/text_to_subtitles.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34116 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php jobs/transcribe.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34115 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(\"php jobs/transcribe_amazon.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34114 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php jobs/translate_text.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34113 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php jobs/speech_audio_text.php \".$login_session.\" \".$_GET['id'].\"… |
| CVE-2026-34112 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without sanitization: exec(\"php jobs/speech_audio_mac.php \".$login_session.\" \".$_GET['id'].\" ...\").… |
| CVE-2026-34110 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php jobs/complex.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34109 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/speech_audio.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34108 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication… |
| CVE-2026-34107 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].\" ...\"). No… |
| CVE-2026-34106 | Crítica (9.3) | 0.93% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\" ...\").… |
| CVE-2026-34105 | Alta (8.7) | 0.46% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An… |
| CVE-2026-34104 | Alta (8.7) | 0.46% | — | 1 jul 2026 | Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attacker can perform… |
| CVE-2026-34103 | Alta (8.7) | 0.46% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated… |
| CVE-2026-34102 | Alta (8.7) | 0.46% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform… |
| CVE-2026-34101 | Alta (8.7) | 0.46% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =… |
| CVE-2026-34100 | Alta (8.7) | 0.46% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id =… |
| CVE-2026-34099 | Crítica (9.3) | 0.63% | — | 1 jul 2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required. An unauthenticated… |
| CVE-2026-34098 | Media (4.8) | 0.24% | — | 1 jul 2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action attributes in media.php (lines 119, 129). An authenticated attacker can craft a URL that injects… |
| CVE-2026-34097 | Media (4.8) | 0.24% | — | 1 jul 2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attributes in text_file.php (lines 94, 101, 323, 403, 826, 852). An authenticated attacker can craft a… |
| CVE-2026-34096 | Media (4.8) | 0.24% | — | 1 jul 2026 | Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribute in designer.php (line 57). An authenticated attacker can craft a URL containing script tags that… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.