Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Guardian — Vulnerabilities & Security Advisories 48

All 48 CVE vulnerabilities found in Guardian, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the product Guardian, focusing on Common Weakness Enumeration (CWE) classifications and general security tags. It compiles known security issues affecting Guardian across various versions and deployment environments. The collected data encompasses historical vulnerability records spanning several years, ensuring a comprehensive view of past and present security incidents. This aggregation allows users to track vendor advisories and security bulletins issued for Guardian, providing a clear timeline of how specific issues were addressed over time. Additionally, it offers insights into common weakness classes that have impacted this product, helping security professionals understand the nature and frequency of different vulnerability types. Users can also look up a product's vulnerability history to assess its overall security posture and identify recurring patterns in reported issues. This resource is designed for security analysts, vulnerability researchers, and system administrators who need detailed information about Guardian's security landscape. By centralizing this data, the page serves as a reference for understanding the evolution of security threats and the corresponding mitigation strategies implemented by the vendor. The information presented here is intended to support informed decision-making in vulnerability management and risk assessment processes.

Vendor: Nozomi Networks

CVE IDTitleCVSSSeverityPublished
CVE-2026-33390 Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0 CWE-266 8.1 High2026-07-09
CVE-2026-31984 DoS through oversized audit log entries in Guardian/CMC before 26.2.0 CWE-770 7.5 High2026-07-09
CVE-2026-31983 Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0 CWE-306 5.3 Medium2026-07-09
CVE-2026-31982 Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0 CWE-601 7.1 High2026-07-09
CVE-2026-31981 HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0 CWE-79 5.9 Medium2026-07-09
CVE-2026-22674 Hashgraph Guardian Stored XSS via branding companyName field CWE-79 4.8 Medium2026-06-18
CVE-2025-40904 HTML injection in Smart Polling in Guardian/CMC before 26.1.0 CWE-79 6.5 Medium2026-05-19
CVE-2025-40903 HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0 CWE-79 5.9 Medium2026-05-19
CVE-2025-40902 HTML injection in Users in Guardian/CMC before 26.1.0 CWE-79 5.9 Medium2026-05-19
CVE-2025-40901 HTML injection in Credentials Manager in Guardian/CMC before 26.1.0 CWE-79 5.9 Medium2026-05-19
CVE-2025-40900 Angular template injection in Reports in Guardian/CMC before 26.1.0 CWE-1336 4.6 Medium2026-05-19
CVE-2026-45248 Hedera Guardian Authentication Bypass Information Disclosure CWE-306 5.3 Medium2026-05-14
CVE-2025-40899 Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0 CWE-79 8.9 High2026-04-15
CVE-2025-40897 Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0 CWE-863 8.1 High2026-04-15
CVE-2026-39911 Hashgraph Guardian 3.5.1 Unsandboxed JavaScript Execution RCE CWE-668 8.8 High2026-04-09
CVE-2025-40894 HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0 CWE-79 4.4 Medium2026-03-04
CVE-2025-40898 Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0 CWE-22 8.1 High2025-12-18
CVE-2025-40893 HTML injection in Asset List in Guardian/CMC before 25.5.0 CWE-79 6.1 Medium2025-12-18
CVE-2025-40892 Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0 CWE-79 8.9 High2025-12-18
CVE-2025-40891 HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0 CWE-79 4.7 Medium2025-12-18
CVE-2025-40890 Stored Cross-Site Scripting (XSS) in Dashboards in Guardian/CMC before 25.4.0 CWE-79 7.9 High2025-11-25
CVE-2025-40888 Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0 CWE-89 5.3 Medium2025-10-07
CVE-2025-40889 Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0 CWE-22 8.1 High2025-10-07
CVE-2025-40887 Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 CWE-89 5.3 Medium2025-10-07
CVE-2025-40886 Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 CWE-89 7.5 High2025-10-07
CVE-2025-40885 Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0 CWE-89 5.3 Medium2025-10-07
CVE-2025-3719 Incorrect authorization for CLI in Guardian/CMC before 25.2.0 CWE-863 8.1 High2025-10-07
CVE-2025-3718 Client-side path traversal in Guardian/CMC before 25.2.0 CWE-22 7.9 High2025-10-07
CVE-2024-13090 Privilege escalation in Guardian/CMC before 24.6.0 CWE-250 7.0 High2025-06-10
CVE-2024-13089 Authenticated RCE in update functionality in Guardian/CMC before 24.6.0 CWE-78 7.2 High2025-06-10

All 48 known CVE vulnerabilities affecting Guardian with full Chinese analysis, references, and POCs where available.