HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 28, 2026, 1:09 AM 40,496 active 1,504 known exploited

Catalog summary

40,496

Active CVEs

20,703

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,301–5,350 of 40,496 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-82717High
    CNAME synthesis could lead to heap corruption
    CVSS 8.4
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-81642Critical
    Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
    CVSS 9.1
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-81634High
    Possible heap buffer overflow during DNSSEC canonicalization
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-80225Medium
    Possible degradation of service from continuous queries on the same TCP/DoT connection
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-78227Medium
    Use-after-free in DoQ stream output buffer on reset re-transmission
    CVSS 6.5
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  6. CVE-2026-77955Medium
    Possible ZONEMD verification bypass window
    CVSS 4.4
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-77860Low
    'serve-expired' can bypass Unbound 'wait-limit'
    CVSS 3.7
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-86338Medium
    Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
    CVSS 6.0
    ash-project/ashgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  9. CVE-2026-88255Medium
    mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot
    CVSS 6.3
    ZenHive/mppgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  10. CVE-2026-89774High
    Bluetooth: SCO: hold sk properly in sco_conn_ready
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  11. CVE-2026-89186Medium
    mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches
    CVSS 6.3
    ZenHive/mppgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  12. CVE-2026-73454High
    Security Advisory 0165
    CVSS 8.1
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  13. CVE-2026-73439High
    Security Advisory 0164
    CVSS 7.5
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026View HOL analysis
  14. CVE-2026-73461High
    Security Advisory 0163
    CVSS 8.0
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  15. CVE-2026-89207Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Siemens/WTV676-HB6035 Web Interface, Siemens/WTV776-HB6035 Web Interfacegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  16. CVE-2026-86341Medium
    Access Control Check Implemented After Asset is Accessed in GitLab
    CVSS 4.4
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-27565Critical
    Remote code execution via uploading a malicious IODD file
    CVSS 9.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-27564High
    Command Injection via PUT in /api/datastorage/data
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-27563High
    Command Injection via GET in /api/datastorage/data
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  20. CVE-2026-27562High
    Command Injection via PUT in /api/iodd/config
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  21. CVE-2026-27561High
    Command Injection via GET in /api/iodd/config
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  22. CVE-2026-27560High
    Command Injection via DELETE in /api/status/data
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-27559High
    Command Injection via GET in /api/status/data
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  24. CVE-2026-27558High
    Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  25. CVE-2026-27557High
    Path Traversal in /index.php/view_uploaded_iodd_file
    CVSS 7.5
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  26. CVE-2026-27556High
    Local File Inclusion in /index.php/ajax/save_iodd_parameters
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  27. CVE-2026-27555High
    Local File Inclusion in /index.php/ajax/get_iodd_port_info
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  28. CVE-2026-27554High
    Command Injection in /index.php/ajax/save_iodd_parameters
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  29. CVE-2026-27553Medium
    Information Disclosure via Schema Path Manipulation
    CVSS 6.5
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  30. CVE-2026-27552High
    Unauthorized IODD File Upload due to Improper Authorization
    CVSS 8.1
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-27551High
    Command Injection in /index.php/ajax/parameterManage
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-27550High
    Command Injection in Field_Shadow_Password Class
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  33. CVE-2026-27549High
    Command Injection in /index.php/attached_devices_tab/do_upload
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  34. CVE-2026-27548High
    Command Injection in /index.php/ajax/get_iodd_port_info
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  35. CVE-2026-27547High
    Command Injection in /index.php/ajax/get_iodd_menu_info
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-27546Critical
    Authentication Bypass in _account_log
    CVSS 9.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  37. CVE-2026-92091Medium
    Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  38. CVE-2026-84408High
    CISA ADP Vulnrichment
    CVSS 8.7
    QualitySoft Corporation/QND Advance, QualitySoft Corporation/QND Premium +1generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  39. CVE-2026-81326Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    QualitySoft Corporation/QND Advance, QualitySoft Corporation/QND Premium +1generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  40. CVE-2026-92355High
    CISA ADP Vulnrichment
    CVSS 8.7
    Octopus Deploy/Octopus Servergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-88263High
    CISA ADP Vulnrichment
    CVSS 8.7
    XikeStor/SKS8300-12E2T2X, XikeStor/SKS8300-8T +1generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  42. CVE-2026-19248High
    Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt
    CVSS 7.1
    qt/qtgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  43. CVE-2024-11222Medium
    Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
    CVSS 6.4
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  44. CVE-2025-14871High
    Allocation of Resources Without Limits or Throttling in GitLab
    CVSS 7.5
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-1168High
    Allocation of Resources Without Limits or Throttling in GitLab
    CVSS 7.5
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  46. CVE-2026-3855Low
    Improper Control of Resource Identifiers ('Resource Injection') in GitLab
    CVSS 3.1
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-7514Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-8030Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  49. CVE-2026-16794Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-19619Medium
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 4.7
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
Page 107 of 810
Previous105106107108109Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard