HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 29, 2026, 5:19 AM 40,845 active 1,504 known exploited

Catalog summary

40,845

Active CVEs

21,026

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,601–5,650 of 40,845 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-84439Medium
    Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
    CVSS 5.3
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  2. CVE-2026-79993High
    Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  3. CVE-2026-59969High
    Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  4. CVE-2026-59739High
    Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeepergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  5. CVE-2026-73436Medium
    Security Advisory 0171
    CVSS 6.5
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  6. CVE-2026-73435High
    Security Advisory 0171
    CVSS 8.2
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-86466High
    Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
    CVSS 8.1
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  8. CVE-2026-86443Medium
    Cleartext Storage of Sensitive Information Vulnerability
    CVSS 6.9
    Fermax Electronica S.A.U./DuoxMegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  9. CVE-2026-19640Medium
    Security Advisory 0170
    CVSS 4.2
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  10. CVE-2026-76187Critical
    Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT
    CVSS 9.8
    Apache Software Foundation/Apache Airflow Keycloak providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  11. CVE-2026-76186Critical
    Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
    CVSS 9.1
    Apache Software Foundation/Apache Airflow Keycloak providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  12. CVE-2026-82310High
    Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
    CVSS 7.2
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  13. CVE-2026-86792High
    Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration
    CVSS 8.8
    Apache Software Foundation/Apache Airflow Apache Kafka provider, apache-airflow-providers-apache-kafkageneric · pypi
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  14. CVE-2026-86462Critical
    Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
    CVSS 9.1
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  15. CVE-2026-73463Medium
    Security Advisory 0169
    CVSS 5.3
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  16. CVE-2026-82311Critical
    Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false
    CVSS 9.8
    Apache Software Foundation/Apache Airflow FAB providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  17. CVE-2026-73445Medium
    Security Advisory 0167
    CVSS 4.9
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-86465Medium
    Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key
    CVSS 6.5
    Apache Software Foundation/Apache Airflow Akeyless providergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  19. CVE-2026-92081Medium
    fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
    CVSS 5.9
    fastify/fastifygeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  20. CVE-2026-89792High
    ksmbd: prevent out-of-bounds reads in share config responses
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  21. CVE-2026-2380High
    Security Advisory 0168
    CVSS 7.4
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  22. CVE-2026-89791High
    perf: Fix use-after-free when perf mmap() revival races with the last munmap()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-89790Unknown severity
    ipv6: avoid divide by zero in rt6_multipath_rebalance
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  24. CVE-2026-89789High
    gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  25. CVE-2026-89788Critical
    ksmbd: fix tree connection use-after-free in smb2_tree_connect()
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  26. CVE-2026-89787Unknown severity
    ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  27. CVE-2026-89786Critical
    ext4: fix out-of-bounds read in ext4_read_inline_dir()
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  28. CVE-2026-89785Unknown severity
    fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  29. CVE-2026-89784Unknown severity
    SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  30. CVE-2026-89783Critical
    xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-89782High
    fs/ntfs3: reject restart table growth beyond U16_MAX entries
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-89781High
    fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  33. CVE-2026-89780Unknown severity
    net: qualcomm: rmnet: restore skb->dev on deaggregated frames
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  34. CVE-2026-89779Critical
    fs/ntfs3: validate ef->size covers the record's name and value
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  35. CVE-2026-89778Critical
    isofs: fix out-of-bounds page array access on empty zisofs block
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-89777High
    vfio/pci: clear vdev->msi_perm after freeing it on init failure
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  37. CVE-2026-89776Unknown severity
    vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  38. CVE-2026-89775Critical
    KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
    CVSS 9.3
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  39. CVE-2026-73464High
    Security Advisory 0166
    CVSS 8.8
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-85501Medium
    Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-82720Medium
    Use-after-free in DoH stream cleanup code path
    CVSS 5.9
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  42. CVE-2026-82717High
    CNAME synthesis could lead to heap corruption
    CVSS 8.4
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  43. CVE-2026-81642Critical
    Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
    CVSS 9.1
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  44. CVE-2026-81634High
    Possible heap buffer overflow during DNSSEC canonicalization
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-80225Medium
    Possible degradation of service from continuous queries on the same TCP/DoT connection
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  46. CVE-2026-78227Medium
    Use-after-free in DoQ stream output buffer on reset re-transmission
    CVSS 6.5
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-77955Medium
    Possible ZONEMD verification bypass window
    CVSS 4.4
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-77860Low
    'serve-expired' can bypass Unbound 'wait-limit'
    CVSS 3.7
    NLnet Labs/Unboundgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  49. CVE-2026-86338Medium
    Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
    CVSS 6.0
    ash-project/ashgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-88255Medium
    mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot
    CVSS 6.3
    ZenHive/mppgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
Page 113 of 817
Previous111112113114115Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard