HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright ยฉ 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 29, 2026, 8:20 AM 40,854 active 1,504 known exploited

Catalog summary

40,854

Active CVEs

21,031

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,051โ€“6,100 of 40,854 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-56879Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  2. CVE-2026-55366Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  3. CVE-2026-55365Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  4. CVE-2026-55359High
    CISA ADP Vulnrichment
    CVSS 7.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  5. CVE-2026-55351High
    CISA ADP Vulnrichment
    CVSS 7.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  6. CVE-2026-55343High
    CISA ADP Vulnrichment
    CVSS 8.0
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  7. CVE-2026-55332Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  8. CVE-2026-55331High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  9. CVE-2026-55323High
    CISA ADP Vulnrichment
    CVSS 7.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  10. CVE-2026-55318High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  11. CVE-2026-55317Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  12. CVE-2026-55306High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  13. CVE-2026-55304Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  14. CVE-2026-55302Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  15. CVE-2026-55301High
    CISA ADP Vulnrichment
    CVSS 8.4
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  16. CVE-2026-0200High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  17. CVE-2026-0199High
    CISA ADP Vulnrichment
    CVSS 7.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  18. CVE-2026-0197Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  19. CVE-2026-0194High
    CISA ADP Vulnrichment
    CVSS 8.4
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  20. CVE-2026-0192Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  21. CVE-2026-0189High
    CISA ADP Vulnrichment
    CVSS 8.4
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  22. CVE-2026-0187Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  23. CVE-2026-0186Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  24. CVE-2026-0183Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  25. CVE-2026-0179Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  26. CVE-2026-0177Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  27. CVE-2026-0171High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  28. CVE-2026-0170High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  29. CVE-2026-0159High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Androidgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  30. CVE-2026-68533Low
    Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add Message Attachments Permission
    CVSS 2.3
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  31. CVE-2026-68534Low
    Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in association selectors
    CVSS 2.3
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  32. CVE-2026-81919Medium
    Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint
    CVSS 4.3
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  33. CVE-2026-19641Medium
    On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit
    CVSS 5.3
    Arista Networks/EOSgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  34. CVE-2026-73451Medium
    On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can
    CVSS 4.8
    Arista Networks/EOSgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  35. CVE-2026-92176Unknown severity
    pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    pdfforge/PDF Architectgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  36. CVE-2026-92177Unknown severity
    pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    pdfforge/PDF Architectgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  37. CVE-2026-92178Unknown severity
    pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    pdfforge/PDF Architectgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  38. CVE-2026-92179Unknown severity
    pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    pdfforge/PDF Architectgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  39. CVE-2026-92180Unknown severity
    pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    Not scoredSource severity not reported
    pdfforge/PDF Architectgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  40. CVE-2026-19781Unknown severity
    Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    Ashlar-Vellum/Cobaltgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  41. CVE-2026-19886Unknown severity
    OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    OriginLab/Origin Viewergeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  42. CVE-2026-19885Unknown severity
    OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    OriginLab/Origin Viewergeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  43. CVE-2026-19774Unknown severity
    BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    BlueZ/BlueZgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  44. CVE-2026-19773Unknown severity
    libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    libwebsockets/libwebsocketsgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  45. CVE-2026-19504Unknown severity
    Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability
    Not scoredSource severity not reported
    Fabric.js/Fabric.jsgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  46. CVE-2026-85234High
    Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  47. CVE-2026-81899High
    Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members > Groups dashboard
    CVSS 7.3
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  48. CVE-2026-57442Medium
    MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
    CVSS 6.9
    bitbonsai/mcpvaultgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  49. CVE-2026-57441High
    MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
    CVSS 8.4
    bitbonsai/mcpvaultgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-58483High
    mcp-searxng: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
    CVSS 7.5
    ihor-sokoliuk/mcp-searxng, mcp-searxnggeneric ยท npm
    PublishedSep 15, 2026First seen at HOL Jun 19, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
Page 122 of 818
Previous120121122123124Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard