Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.4 CVE-2026-49088

Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosure_CVE-2026-49088

Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance ...

Elastic Kibana 8.0.0 CVE
MEDIUM 6.5 CVE-2026-49087

Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service_CVE-2026-49087

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An a...

Elastic Kibana 9.0.0 CVE
CRITICAL 9.3 CVE-2026-34117

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text_to_subtitles.php_CVE-2026-34117

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34116

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php_CVE-2026-34116

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php j...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34115

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php_CVE-2026-34115

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34114

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php_CVE-2026-34114

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"p...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34113

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech_text.php_CVE-2026-34113

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php ...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34111

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac_text.php_CVE-2026-34111

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"p...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34110

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php_CVE-2026-34110

Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"ph...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34108

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php_CVE-2026-34108

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/te...

guardian language-system CVE