Digital Guardian provides data loss prevention and content-aware security solutions centered on its management console and endpoint agent products, protecting sensitive information across enterprise networks and endpoints. The observed vulnerabilities cluster around input-handling and file-upload weaknesses such as path traversal, XML external entity injection, and server-side request forgery, reflecting the challenge of safely processing and validating user-supplied content in security-focused middleware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digitalguardian over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10173HIGH Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality. | Apr 20, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-10176MEDIUM Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue. | Apr 20, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-10174MEDIUM Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtai | Apr 20, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-10175MEDIUM Digital Guardian Management Console 7.1.2.0015 has an XXE issue. | Apr 20, 2018 | 6.5 | 20 | NO | NO |
CVE-2022-35412MEDIUM Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the product) to disable some of the agent functionality and the | Jul 8, 2022 | 5.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digitalguardian.
Media articles that mention a CVE ID that affects a product developed by Digitalguardian — matched by CVE ID, not by vendor name.