HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 28, 2026, 12:07 AM 40,493 active 1,504 known exploited

Catalog summary

40,493

Active CVEs

20,703

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,151–5,200 of 40,493 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-89881Unknown severity
    media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-89880High
    media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-89879Unknown severity
    media: s2255: bound JPEG frame size before copying into the buffer
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-89878Unknown severity
    media: s2255: check firmware size before reading trailing marker
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-89877High
    media: saa7164: fix cleanup on resource allocation failure
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  6. CVE-2026-89876Unknown severity
    media: tda18250: fix possible integer overflow
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-89875High
    media: ti: vpe: quiesce overflow recovery before freeing streams
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-89874Unknown severity
    media: v4l2-async: avoid deleting unlinked ASC entry on link error
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  9. CVE-2026-89873High
    media: v4l2-ctrls: validate HEVC EXT SPS RPS counts
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  10. CVE-2026-89872Unknown severity
    media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  11. CVE-2026-89871Unknown severity
    media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  12. CVE-2026-89870High
    media: zoran: Avoid freeing a registered video_device twice
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-89869Unknown severity
    media: qcom: iris: use disable_irq() during power-off
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  14. CVE-2026-89868Unknown severity
    media: chips-media: wave5: Add timeout while stop_streaming
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  15. CVE-2026-89867Unknown severity
    media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  16. CVE-2026-89866Unknown severity
    media: chips-media: wave5: Resume device before setting EOS flag
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-89865Unknown severity
    scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-89864Unknown severity
    scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-89863High
    scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  20. CVE-2026-89862Unknown severity
    scsi: qla2xxx: Fix BSG job leak on validate flash image error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  21. CVE-2026-89861High
    scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
    CVSS 8.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  22. CVE-2026-89860High
    scsi: qla2xxx: Initialize NVMe abort_work once at submission
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-89859Unknown severity
    scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  24. CVE-2026-89858Unknown severity
    scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  25. CVE-2026-89857Critical
    scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  26. CVE-2026-89856High
    scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  27. CVE-2026-89855Unknown severity
    scsi: qla2xxx: Serialize flash version read in reset handler
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  28. CVE-2026-89854High
    scsi: qla2xxx: Fix cs84xx use-after-free on host teardown
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  29. CVE-2026-89853Unknown severity
    scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  30. CVE-2026-89852Unknown severity
    scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-89851Unknown severity
    scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-89850Unknown severity
    scsi: qla2xxx: Don't query firmware state while chip is down
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  33. CVE-2026-89849High
    scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  34. CVE-2026-89848High
    scsi: qla2xxx: Quiesce response IRQ before freeing request queue
    CVSS 8.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  35. CVE-2026-89847Critical
    scsi: qla2xxx: Avoid double completion in async IOCB timeout
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-89846Critical
    scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  37. CVE-2026-89845Unknown severity
    scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  38. CVE-2026-89844High
    scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  39. CVE-2026-89843Unknown severity
    scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  40. CVE-2026-89842Unknown severity
    scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-89841High
    f2fs: only redirty pinned folios in redirty_blocks
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  42. CVE-2026-89840High
    f2fs: validate MOVE_RANGE destination size
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  43. CVE-2026-89839Unknown severity
    f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  44. CVE-2026-89838High
    f2fs: limit recovery filename logging to stored length
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  45. CVE-2026-89837Unknown severity
    f2fs: fix dentry folio leak in find_in_level
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  46. CVE-2026-89836High
    f2fs: fix folio_nr_pages() race after put in large folio invalidate
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-89835Unknown severity
    f2fs: avoid NULL checkpoint thread access in sysfs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-89834Unknown severity
    f2fs: fix to migrate all curseg types during free_segment_range
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  49. CVE-2026-89833Unknown severity
    f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-89832High
    f2fs: fix to clear dirty flag on folio in error path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
Page 104 of 810
Previous102103104105106Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard