HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 29, 2026, 5:18 AM 40,845 active 1,504 known exploited

Catalog summary

40,845

Active CVEs

21,026

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,651–5,700 of 40,845 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-89774High
    Bluetooth: SCO: hold sk properly in sco_conn_ready
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-89186Medium
    mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches
    CVSS 6.3
    ZenHive/mppgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-73454High
    Security Advisory 0165
    CVSS 8.1
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  4. CVE-2026-73439High
    Security Advisory 0164
    CVSS 7.5
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026View HOL analysis
  5. CVE-2026-73461High
    Security Advisory 0163
    CVSS 8.0
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  6. CVE-2026-89207Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Siemens/WTV676-HB6035 Web Interface, Siemens/WTV776-HB6035 Web Interfacegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  7. CVE-2026-86341Medium
    Access Control Check Implemented After Asset is Accessed in GitLab
    CVSS 4.4
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-27565Critical
    Remote code execution via uploading a malicious IODD file
    CVSS 9.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  9. CVE-2026-27564High
    Command Injection via PUT in /api/datastorage/data
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  10. CVE-2026-27563High
    Command Injection via GET in /api/datastorage/data
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  11. CVE-2026-27562High
    Command Injection via PUT in /api/iodd/config
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  12. CVE-2026-27561High
    Command Injection via GET in /api/iodd/config
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-27560High
    Command Injection via DELETE in /api/status/data
    CVSS 7.2
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  14. CVE-2026-27559High
    Command Injection via GET in /api/status/data
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  15. CVE-2026-27558High
    Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  16. CVE-2026-27557High
    Path Traversal in /index.php/view_uploaded_iodd_file
    CVSS 7.5
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-27556High
    Local File Inclusion in /index.php/ajax/save_iodd_parameters
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-27555High
    Local File Inclusion in /index.php/ajax/get_iodd_port_info
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-27554High
    Command Injection in /index.php/ajax/save_iodd_parameters
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  20. CVE-2026-27553Medium
    Information Disclosure via Schema Path Manipulation
    CVSS 6.5
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  21. CVE-2026-27552High
    Unauthorized IODD File Upload due to Improper Authorization
    CVSS 8.1
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  22. CVE-2026-27551High
    Command Injection in /index.php/ajax/parameterManage
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-27550High
    Command Injection in Field_Shadow_Password Class
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  24. CVE-2026-27549High
    Command Injection in /index.php/attached_devices_tab/do_upload
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  25. CVE-2026-27548High
    Command Injection in /index.php/ajax/get_iodd_port_info
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  26. CVE-2026-27547High
    Command Injection in /index.php/ajax/get_iodd_menu_info
    CVSS 8.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  27. CVE-2026-27546Critical
    Authentication Bypass in _account_log
    CVSS 9.8
    Carlo Gavazzi Automation/YL212CEI8M1IO, Carlo Gavazzi Automation/YL212CPN8M1IO +13generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  28. CVE-2026-92091Medium
    Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  29. CVE-2026-84408High
    CISA ADP Vulnrichment
    CVSS 8.7
    QualitySoft Corporation/QND Advance, QualitySoft Corporation/QND Premium +1generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  30. CVE-2026-81326Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    QualitySoft Corporation/QND Advance, QualitySoft Corporation/QND Premium +1generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  31. CVE-2026-92355High
    CISA ADP Vulnrichment
    CVSS 8.7
    Octopus Deploy/Octopus Servergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-88263High
    CISA ADP Vulnrichment
    CVSS 8.7
    XikeStor/SKS8300-12E2T2X, XikeStor/SKS8300-8T +1generic
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  33. CVE-2026-19248High
    Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt
    CVSS 7.1
    qt/qtgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  34. CVE-2024-11222Medium
    Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
    CVSS 6.4
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  35. CVE-2025-14871High
    Allocation of Resources Without Limits or Throttling in GitLab
    CVSS 7.5
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-1168High
    Allocation of Resources Without Limits or Throttling in GitLab
    CVSS 7.5
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  37. CVE-2026-3855Low
    Improper Control of Resource Identifiers ('Resource Injection') in GitLab
    CVSS 3.1
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  38. CVE-2026-7514Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  39. CVE-2026-8030Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  40. CVE-2026-16794Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-19619Medium
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 4.7
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  42. CVE-2026-78252High
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 8.2
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  43. CVE-2026-79708High
    Incorrect Authorization in GitLab
    CVSS 8.5
    GitLab/GitLabgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  44. CVE-2026-86475Medium
    Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission
    CVSS 5.3
    Unknown/Appointment Hour Bookinggeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-84906Medium
    Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay
    CVSS 5.3
    Unknown/Eventingeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  46. CVE-2026-19857Medium
    Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Custom HTML Token
    CVSS 4.8
    Unknown/Formidable Formsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-13407Medium
    Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notification Emails
    CVSS 5.4
    Unknown/Royal Addons for Elementorgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-73447Critical
    Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request
    CVSS 9.1
    Arista Networks/EOSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  49. CVE-2026-89328Low
    FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modification
    CVSS 3.8
    Unknown/FluentBoardsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  50. CVE-2026-89327Low
    FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' Parameter
    CVSS 3.8
    Unknown/FluentBoardsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
Page 114 of 817
Previous112113114115116Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard