Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-15646

HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion_CVE-2025-15646

HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the element was added to libgumbo 0.10.0 in 2015, ...

BPS HTML::Gumbo CVE
HIGH 7.7 CVE-2026-58454

JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint_CVE-2026-58454

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that allows authenticated attack...

JAIOTlink C492A-W6 Wi-Fi IP Camera 4.8.30.57701411 CVE
CRITICAL 9.3 CVE-2026-58453

JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc_CVE-2026-58453

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent at...

JAIOTlink C492A-W6 Wi-Fi IP Camera 4.8.30.57701411 CVE
HIGH 8.7 CVE-2026-58452

JAIOTlink C492A-W6 4.8.30.57701411 OS Command Injection via SetMAC Endpoint_CVE-2026-58452

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attack...

JAIOTlink C492A-W6 Wi-Fi IP Camera 4.8.30.57701411 CVE
CRITICAL 9.3 CVE-2026-34107

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php_CVE-2026-34107

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jo...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34106

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php_CVE-2026-34106

Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jo...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34105

Guardian Language-System Unauthenticated SQL Injection via id Parameter in translate_text.php_CVE-2026-34105

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, e...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34104

Guardian Language-System Unauthenticated SQL Injection via name Parameter in designer.php_CVE-2026-34104

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHE...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34103

Guardian Language-System Unauthenticated SQL Injection via id Parameter in subtitles.php_CVE-2026-34103

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extens...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34102

Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info_get.php_CVE-2026-34102

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where...

guardian language-system CVE