Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required. An unauthenticated attacker can perform error-based SQL injection to extract the database version, current user,… | |
| Aplazada | Media (4.8) | 0.24% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action attributes in media.php (lines 119, 129). An authenticated attacker can craft a URL that injects script tags executing in the victim's browser session. | |
| Aplazada | Media (4.8) | 0.24% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attributes in text_file.php (lines 94, 101, 323, 403, 826, 852). An authenticated attacker can craft a URL that injects script tags executing in the victim's browser session. | |
| Aplazada | Media (4.8) | 0.24% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribute in designer.php (line 57). An authenticated attacker can craft a URL containing script tags that execute in the victim's browser session. | |
| Aplazada | Media (4.8) | 0.31% | — | Hashgraph GuardianAI | 18/6/2026 | 14/7/2026 | Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the… | |
| Modificada | Media (5.1) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote strategy in the… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected schedule, the injected… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user,… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected identity, the injected… | |
| Modificada | Media (5.1) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to import a malicious… | |
| Analizada | Media (6.9) | 0.43% | — | Hedera Guardian | 14/5/2026 | 14/7/2026 | Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can access the endpoint without providing authentication credentials to obtain usernames, Hedera DIDs,… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Guardianwall MailsuiteAIGuardianwall Mail Security CloudAI | 13/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user… | |
| Modificada | Alta (8.7) | 0.79% | — | Hedera Guardian | 9/4/2026 | 14/7/2026 | Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows authenticated Standard Registry users to execute arbitrary code by passing user-supplied JavaScript expressions directly to the Node.js… | |
| Aplazada | Media (4.3) | 0.13% | — | Guardian News FeedAI | 7/3/2026 | 17/6/2026 | The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the Guardian… | |
| Modificada | Baja (2.1) | 0.17% | — | Nozominetworks CMCNozominetworks Guardian | 4/3/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit a node label to inject HTML tags. If the system is configured to use the Alerted Nodes Dashboard,… | |
| Aplazada | Alta (7.5) | 0.37% | 💥 PoC | Guardian GryphonAI | 17/2/2026 | 5/7/2026 | An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root. | |
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device… | |
| Modificada | Media (5.3) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and… | |
| Modificada | Alta (7.1) | 0.26% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a malicious report… | |
| Modificada | Baja (2.3) | 0.18% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 30/9/2026 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots.… | |
| Analizada | Alta (7.2) | 0.41% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their… | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. |