HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 29, 2026, 9:47 AM 40,888 active 1,504 known exploited

Catalog summary

40,888

Active CVEs

21,039

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,251–6,300 of 40,888 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-89307Medium
    HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme
    CVSS 5.1
    Developers Italia/design-scuole-wordpress-themegeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  2. CVE-2026-19407High
    GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK
    CVSS 7.7
    Google Cloud/Gemini Enterprise Agent Platform SDK for Pythongeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  3. CVE-2026-87793Medium
    Reflected XSS in WordPress theme design-scuole-wordpress-theme
    CVSS 5.1
    Developers Italia/design-scuole-wordpress-themegeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  4. CVE-2026-87792High
    Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme
    CVSS 8.7
    Developers Italia/design-scuole-wordpress-themegeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  5. CVE-2026-91992Medium
    Tornado before 6.5.7 Credential Leak via Handle Reuse
    CVSS 5.9
    tornado, tornadoweb/tornadogeneric · pip · pypi
    PublishedSep 15, 2026First seen at HOL Jun 19, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  6. CVE-2026-91991Low
    Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs
    CVSS 5.4
    tornado, tornadoweb/tornadogeneric · pip · pypi
    PublishedSep 15, 2026First seen at HOL Sep 1, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  7. CVE-2026-65831High
    ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
    CVSS 7.7
    ArcadeData/arcadedb, com.arcadedb/arcadedb-server +1generic · maven
    PublishedSep 15, 2026First seen at HOL Jul 17, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-91990Medium
    Tornado before 6.5.8 Memory Amplification DoS via multipart
    CVSS 7.5
    tornado, tornadoweb/tornadogeneric · pip · pypi
    PublishedSep 15, 2026First seen at HOL Sep 1, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  9. CVE-2026-91989High
    atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py
    CVSS 7.5
    atomic-agents-stack, dep0we/atomic-agents-stackgeneric · pip · pypi
    PublishedSep 15, 2026First seen at HOL Aug 13, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  10. CVE-2026-91988High
    atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP
    CVSS 8.1
    atomic-agents-stack, dep0we/atomic-agents-stackgeneric · pip · pypi
    PublishedSep 15, 2026First seen at HOL Aug 17, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  11. CVE-2026-91987High
    atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model
    CVSS 6.5
    atomic-agents-stack, dep0we/atomic-agents-stackgeneric · pip · pypi
    PublishedSep 15, 2026First seen at HOL Aug 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  12. CVE-2026-91986Medium
    gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection
    CVSS 5.4
    GitoxideLabs/gitoxidegeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  13. CVE-2026-91985High
    Vikunja before 2.6.0 Privilege Escalation via Link Share Hash
    CVSS 7.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  14. CVE-2026-91984Medium
    Vikunja before 2.6.0 Broken Object-Level Authorization via task-position
    CVSS 4.3
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  15. CVE-2026-91983Medium
    Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter
    CVSS 4.3
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  16. CVE-2026-91982Medium
    Vikunja before 2.6.0 TOTP Secret Disclosure via API
    CVSS 4.3
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  17. CVE-2026-91981Medium
    Vikunja before 2.6.0 User Enumeration via v2 API
    CVSS 4.3
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  18. CVE-2026-91980Medium
    vikunja before 2.6.0 Team Enumeration via Project Share
    CVSS 4.3
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-91979Medium
    Vikunja before 2.6.0 Denial of Service via Decompression Bomb
    CVSS 6.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  20. CVE-2026-91973High
    Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth
    CVSS 7.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  21. CVE-2026-91972High
    Vikunja before 2.6.0 Authentication Bypass via Unthrottled API
    CVSS 7.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  22. CVE-2026-91971Medium
    Vikunja before 2.6.0 Denial of Service via Avatar Upload
    CVSS 6.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  23. CVE-2026-91970Medium
    Vikunja before 2.6.0 Resource Exhaustion via Planka Migration
    CVSS 6.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  24. CVE-2026-91969Medium
    vikunja before 2.6.0 Resource Exhaustion via CSV Migration
    CVSS 6.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-91968Medium
    vikunja before 2.6.0 Denial of Service via unbounded filter recursion
    CVSS 6.5
    go-vikunja/vikunjageneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  26. CVE-2026-91967Medium
    AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL
    CVSS 5.0
    WWBN/AVideogeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026View HOL analysis
  27. CVE-2026-91966Medium
    AVideo through 29.0 Unauthenticated SSRF via Host Header
    CVSS 5.8
    WWBN/AVideogeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  28. CVE-2026-91965High
    WWBN AVideo through 29.0 Broken Access Control via Live Endpoints
    CVSS 7.5
    WWBN/AVideogeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  29. CVE-2026-91964High
    FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken
    CVSS 8.8
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  30. CVE-2026-91963Medium
    FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-91962Medium
    FreeRDP before 3.31.0 Integer Overflow via audin Apple backends
    CVSS 6.3
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-91961Unknown severity
    FreeRDP before 3.31.0 Denial of Service via URBDRC
    Not scoredSource severity not reported
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  33. CVE-2026-91960Medium
    FreeRDP before 3.31.0 Integer Overflow Double Free
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  34. CVE-2026-91959Unknown severity
    FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway
    Not scoredSource severity not reported
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026 Fix availableView HOL analysis
  35. CVE-2026-91958Medium
    FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index
    CVSS 6.6
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-91957Low
    FreeRDP before 3.31.0 Use-After-Free via smartcard worker
    CVSS 3.1
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-91956Medium
    FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  38. CVE-2026-91955High
    FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  39. CVE-2026-91954Medium
    FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-91953Medium
    FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-91952Medium
    FreeRDP before 3.31.0 Denial of Service via pool_decode_rect
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-91951Unknown severity
    FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc
    Not scoredSource severity not reported
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026 Fix availableView HOL analysis
  43. CVE-2026-91950Medium
    FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  44. CVE-2026-91949Critical
    FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass
    CVSS 9.3
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  45. CVE-2026-91948High
    FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  46. CVE-2026-91947High
    FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-91946Unknown severity
    FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics
    Not scoredSource severity not reported
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  48. CVE-2026-91945Medium
    FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  49. CVE-2026-91944Medium
    crawl4ai before 0.9.3 DOM-based XSS via Playground UI
    CVSS 6.1
    unclecode/crawl4aigeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  50. CVE-2026-91943High
    Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy
    CVSS 7.7
    unclecode/crawl4aigeneric
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
Page 126 of 818
Previous124125126127128Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard