Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Guardian — Vulnerabilities & Security Advisories 57

All 57 CVE vulnerabilities found in Guardian, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregation data for Guardian, a software product from its respective vendor, focusing on common weakness enumeration and related security tags. It collects a comprehensive range of vulnerability reports, including remote code execution flaws, authentication bypasses, and information disclosure issues, covering incidents reported from 2018 through the present day. The dataset is structured to help security professionals and risk managers effectively track vendor-specific advisories as they are issued, understand the broader implications of specific weakness classes within the Guardian ecosystem, and look up a product’s complete vulnerability history to assess long-term security posture. By centralizing these records, the page serves as a reference point for identifying patterns in defect types and evaluating the vendor’s response timeline. This information supports due diligence processes, third-party risk assessments, and internal security audits by providing transparent access to past security events. The data includes metadata such as release versions affected, severity ratings, and patch availability status, allowing users to correlate technical details with business impact. Users are encouraged to cross-reference this aggregation with official vendor channels for the most current mitigation guidance and to consult internal threat intelligence feeds for real-time monitoring alerts. This resource aims to streamline the review of historical security incidents and facilitate informed decision-making regarding upgrade cycles and remediation priorities.

Vendor: Nozomi Networks

CVE ID Title CVSS Severity Published
CVE-2026-33920 Cross-site request forgery in the Guardian/CMC login before 26.3.0 CWE-352 3.5 Low 2026-09-08
CVE-2026-33391 Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 CWE-863 5.4 Medium 2026-09-08
CVE-2026-33389 Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0 CWE-671 7.5 High 2026-09-08
CVE-2026-33388 Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0 CWE-863 7.4 High 2026-09-08
CVE-2026-33387 Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 CWE-1336 4.6 Medium 2026-09-08
CVE-2026-55734 guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1 CWE-770 6.9 Medium 2026-08-01
CVE-2026-55733 Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation CWE-770 6.9 Medium 2026-08-01
CVE-2026-54894 Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys CWE-770 6.9 Medium 2026-08-01
CVE-2026-55735 Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation CWE-347 8.2 High 2026-08-01
CVE-2026-33390 Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0 CWE-266 8.1 High 2026-07-09
CVE-2026-31984 DoS through oversized audit log entries in Guardian/CMC before 26.2.0 CWE-770 7.5 High 2026-07-09
CVE-2026-31983 Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0 CWE-306 5.3 Medium 2026-07-09
CVE-2026-31982 Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0 CWE-601 7.1 High 2026-07-09
CVE-2026-31981 HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0 CWE-79 5.9 Medium 2026-07-09
CVE-2026-22674 Hashgraph Guardian Stored XSS via branding companyName field CWE-79 4.8 Medium 2026-06-18
CVE-2025-40904 HTML injection in Smart Polling in Guardian/CMC before 26.1.0 CWE-79 6.5 Medium 2026-05-19
CVE-2025-40903 HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0 CWE-79 5.9 Medium 2026-05-19
CVE-2025-40902 HTML injection in Users in Guardian/CMC before 26.1.0 CWE-79 5.9 Medium 2026-05-19
CVE-2025-40901 HTML injection in Credentials Manager in Guardian/CMC before 26.1.0 CWE-79 5.9 Medium 2026-05-19
CVE-2025-40900 Angular template injection in Reports in Guardian/CMC before 26.1.0 CWE-1336 4.6 Medium 2026-05-19
CVE-2026-45248 Hedera Guardian Authentication Bypass Information Disclosure CWE-306 5.3 Medium 2026-05-14
CVE-2025-40899 Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0 CWE-79 8.9 High 2026-04-15
CVE-2025-40897 Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0 CWE-863 8.1 High 2026-04-15
CVE-2026-39911 Hashgraph Guardian 3.5.1 Unsandboxed JavaScript Execution RCE CWE-668 8.8 High 2026-04-09
CVE-2025-40894 HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0 CWE-79 4.4 Medium 2026-03-04
CVE-2025-40898 Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0 CWE-22 8.1 High 2025-12-18
CVE-2025-40893 HTML injection in Asset List in Guardian/CMC before 25.5.0 CWE-79 6.1 Medium 2025-12-18
CVE-2025-40892 Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0 CWE-79 8.9 High 2025-12-18
CVE-2025-40891 HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0 CWE-79 4.7 Medium 2025-12-18
CVE-2025-40890 Stored Cross-Site Scripting (XSS) in Dashboards in Guardian/CMC before 25.4.0 CWE-79 7.9 High 2025-11-25

All 57 known CVE vulnerabilities affecting Guardian with full Chinese analysis, references, and POCs where available.