HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 28, 2026, 1:05 AM 40,496 active 1,504 known exploited

Catalog summary

40,496

Active CVEs

20,703

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,251–5,300 of 40,496 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-73468Medium
    Security Advisory 0175
    CVSS 6.5
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-73440Medium
    Security Advisory 0178
    CVSS 4.2
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-73469Medium
    Security Advisory 0176
    CVSS 5.8
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  4. CVE-2026-89793High
    ublk: clear VM_MAYWRITE on read-only ublk char device mmap
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-73453Critical
    Security Advisory 0174
    CVSS 10.0
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  6. CVE-2026-73455High
    Security Advisory 0173
    CVSS 7.5
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-73438Medium
    Security Advisory 0172
    CVSS 5.3
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-85628High
    Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability
    CVSS 7.0
    Fermax Electronica S.A.U./DUOX PLUS monitor firmware (VEO Wi-Fi range), Fermax Electronica S.A.U./DuoxMegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  9. CVE-2026-84501Medium
    Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider
    CVSS 5.3
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  10. CVE-2026-84439Medium
    Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
    CVSS 5.3
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  11. CVE-2026-79993High
    Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  12. CVE-2026-59969High
    Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  13. CVE-2026-59739High
    Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  14. CVE-2026-73436Medium
    Security Advisory 0171
    CVSS 6.5
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  15. CVE-2026-73435High
    Security Advisory 0171
    CVSS 8.2
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  16. CVE-2026-86466High
    Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
    CVSS 8.1
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  17. CVE-2026-86443Medium
    Cleartext Storage of Sensitive Information Vulnerability
    CVSS 6.9
    Fermax Electronica S.A.U./DuoxMegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  18. CVE-2026-19640Medium
    Security Advisory 0170
    CVSS 4.2
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-76187Critical
    Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT
    CVSS 9.8
    Apache Software Foundation/Apache Airflow Keycloak providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  20. CVE-2026-76186Critical
    Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
    CVSS 9.1
    Apache Software Foundation/Apache Airflow Keycloak providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  21. CVE-2026-82310High
    Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
    CVSS 7.2
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  22. CVE-2026-86792High
    Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration
    CVSS 8.8
    Apache Software Foundation/Apache Airflow Apache Kafka provider, apache-airflow-providers-apache-kafkageneric · pypi
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  23. CVE-2026-86462Critical
    Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
    CVSS 9.1
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  24. CVE-2026-73463Medium
    Security Advisory 0169
    CVSS 5.3
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  25. CVE-2026-82311Critical
    Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false
    CVSS 9.8
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  26. CVE-2026-73445Medium
    Security Advisory 0167
    CVSS 4.9
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  27. CVE-2026-86465Medium
    Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key
    CVSS 6.5
    Apache Software Foundation/Apache Airflow Akeyless providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  28. CVE-2026-92081Medium
    fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
    CVSS 5.9
    fastify/fastifygeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  29. CVE-2026-89792High
    ksmbd: prevent out-of-bounds reads in share config responses
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  30. CVE-2026-2380High
    Security Advisory 0168
    CVSS 7.4
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-89791High
    perf: Fix use-after-free when perf mmap() revival races with the last munmap()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-89790Unknown severity
    ipv6: avoid divide by zero in rt6_multipath_rebalance
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  33. CVE-2026-89789High
    gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  34. CVE-2026-89788Critical
    ksmbd: fix tree connection use-after-free in smb2_tree_connect()
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  35. CVE-2026-89787Unknown severity
    ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-89786Critical
    ext4: fix out-of-bounds read in ext4_read_inline_dir()
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  37. CVE-2026-89785Unknown severity
    fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  38. CVE-2026-89784Unknown severity
    SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  39. CVE-2026-89783Critical
    xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  40. CVE-2026-89782High
    fs/ntfs3: reject restart table growth beyond U16_MAX entries
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-89781High
    fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  42. CVE-2026-89780Unknown severity
    net: qualcomm: rmnet: restore skb->dev on deaggregated frames
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  43. CVE-2026-89779Critical
    fs/ntfs3: validate ef->size covers the record's name and value
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  44. CVE-2026-89778Critical
    isofs: fix out-of-bounds page array access on empty zisofs block
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-89777High
    vfio/pci: clear vdev->msi_perm after freeing it on init failure
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  46. CVE-2026-89776Unknown severity
    vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-89775Critical
    KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
    CVSS 9.3
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-73464High
    Security Advisory 0166
    CVSS 8.8
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  49. CVE-2026-85501Medium
    Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-82720Medium
    Use-after-free in DoH stream cleanup code path
    CVSS 5.9
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
Page 106 of 810
Previous104105106107108Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard