HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 29, 2026, 11:19 AM 40,898 active 1,504 known exploited

Catalog summary

40,898

Active CVEs

21,044

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,401–6,450 of 40,898 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-92054High
    Privilege escalation in the Memory component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  2. CVE-2026-92053High
    Privilege escalation in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  3. CVE-2026-92052High
    Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  4. CVE-2026-92051Critical
    Spoofing issue due to invalid pointer in the Graphics component
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  5. CVE-2026-92050Critical
    Sandbox escape due to race condition in the XPConnect component
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  6. CVE-2026-92049High
    Use-after-free in the Widget: Win32 component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  7. CVE-2026-92048Critical
    Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
    CVSS 9.0
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  8. CVE-2026-92047High
    Privilege escalation in the Crash Reporting component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  9. CVE-2026-92046High
    Use-after-free in the Graphics component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  10. CVE-2026-92045Critical
    Sandbox escape due to incorrect boundary conditions in the WebRTC component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  11. CVE-2026-92044High
    Information disclosure in the Networking: HTTP component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  12. CVE-2026-92043High
    Privilege escalation due to incorrect boundary conditions in the Audio/Video component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  13. CVE-2026-92042High
    Race condition in the DOM: Content Processes component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  14. CVE-2026-92041Critical
    Mitigation bypass in the DOM: Networking component
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  15. CVE-2026-92040High
    Use-after-free in the JavaScript: WebAssembly component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  16. CVE-2026-92039Medium
    Mitigation bypass in the DOM: Notifications component
    CVSS 6.3
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  17. CVE-2026-92038Critical
    Mitigation bypass in the Remote Settings Client component
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  18. CVE-2026-92037Critical
    Incorrect boundary conditions in the DOM: Animation component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  19. CVE-2026-92036Critical
    Incorrect boundary conditions in the Networking: HTTP component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  20. CVE-2026-92035Critical
    Sandbox escape due to incorrect boundary conditions in the Graphics component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  21. CVE-2026-92034Critical
    Site isolation issue in the Graphics component
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  22. CVE-2026-92033High
    Privilege escalation in Firefox for Android
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  23. CVE-2026-92032Critical
    Sandbox escape due to invalid pointer in the Graphics component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  24. CVE-2026-92031Medium
    Information disclosure in the Graphics: ImageLib component
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  25. CVE-2026-92030Medium
    Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  26. CVE-2026-92029High
    Use-after-free in the SVG component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  27. CVE-2026-92028High
    Use-after-free in the DOM: Core & HTML component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  28. CVE-2026-92027High
    Use-after-free in the DOM: Streams component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  29. CVE-2026-92026High
    Use-after-free in the Networking component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  30. CVE-2026-92025High
    Use-after-free in the DOM: Navigation component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 18, 2026View HOL analysis
  31. CVE-2026-92024High
    Use-after-free in the SVG component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  32. CVE-2026-92023High
    Use-after-free in the XML component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  33. CVE-2026-92022High
    Use-after-free in the DOM: HTML Parser component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  34. CVE-2026-92021High
    Use-after-free in the JavaScript Engine: JIT component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  35. CVE-2026-92020High
    Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  36. CVE-2026-92019High
    Mitigation bypass in the Remote Settings Client component
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 21, 2026View HOL analysis
  37. CVE-2026-92018Critical
    Sandbox escape in the DOM: Core & HTML component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  38. CVE-2026-92017High
    Privilege escalation in the DOM: Service Workers component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  39. CVE-2026-92016High
    Use-after-free in the Disability Access APIs component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 20, 2026View HOL analysis
  40. CVE-2026-92015High
    Privilege escalation in the WebExtensions component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  41. CVE-2026-92014High
    Privilege escalation due to incorrect boundary conditions in the Graphics component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  42. CVE-2026-92013High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  43. CVE-2026-92012High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  44. CVE-2026-92011High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  45. CVE-2026-92010High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  46. CVE-2026-92009High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  47. CVE-2026-92008High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  48. CVE-2026-92007High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  49. CVE-2026-92006High
    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 16, 2026View HOL analysis
  50. CVE-2026-92005Medium
    Use-after-free in the Audio/Video: Web Codecs component
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedSep 15, 2026First seen at HOL Sep 15, 2026Updated Sep 17, 2026View HOL analysis
Page 129 of 818
Previous127128129130131Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard