1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 1:15 PM 16,240 active 1,443 known exploited

Catalog summary

16,240

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 1:15 PM 16,240 active 1,443 known exploited

Catalog summary

16,240

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 601–650 of 16,240 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-5158Medium
    PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block
    CVSS 6.4
    wpxpo/Post Grid Gutenberg Blocks – PostXgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-57818High
    Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
    CVSS 8.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-61466Critical
    Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-63687Critical
    Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  5. CVE-2026-65583Critical
    Apache CXF: Self-issued ID token claims validation skipped
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-68079Critical
    Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-68481High
    Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  8. CVE-2026-19034High
    Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection
    CVSS 7.2
    Shibby/Tomatogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-65432High
    Apache CXF: XXE via WSDL/XSD import parsing
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-57817Critical
    Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-66909Critical
    Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-64958High
    Apache CXF: Denial of service via message header attachments
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  13. CVE-2026-57819High
    Apache CXF: No default restriction on the amount of form parameters per message
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-54225High
    Apache CXF: Denial of Service attack via large attachments
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-55980Medium
    Denial-of-service vulnerability in CatchPulse
    CVSS 5.5
    SecureAge/CatchPulsegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-55979Medium
    Improper access control check in CatchPulse's named pipe communication interface
    CVSS 5.2
    SecureAge/CatchPulsegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-55978High
    Improper access control vulnerability in CatchPulse
    CVSS 8.4
    SecureAge/CatchPulsegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-64640Medium
    Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
    CVSS 5.3
    Apache Software Foundation/Apache Polarisgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-19022Medium
    OpenHands send_pull_request.py initialize_repo command injection
    CVSS 6.3
    n/a/OpenHandsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-19021High
    SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection
    CVSS 7.3
    SourceCodester/Computer Repair Shop Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-19020Medium
    itsourcecode Hospital Management System servicetype.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-18597High
    Blind SSRF on Foxit PDF Services API
    CVSS 8.5
    Foxit Software Inc./Foxit PDF Services APIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-5430Critical
    Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
    CVSS 10.0
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +3generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-1728Critical
    Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
    CVSS 9.8
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +4generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  25. CVE-2025-15039Critical
    Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
    CVSS 9.4
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +8generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-0637Medium
    Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
    CVSS 4.4
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +7generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2025-13394Medium
    Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
    CVSS 5.4
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +45generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  28. CVE-2026-18915Medium
    Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
    CVSS 5.0
    TÜBİTAK BİLGEM Software Technologies Research Institute/eta-otp-lockgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  29. CVE-2025-13909Medium
    Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure
    CVSS 4.3
    WSO2/Email OTP Authenticator, WSO2/WSO2 Carbon Abstract OTP Authenticator +3generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2025-12627Low
    Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions
    CVSS 2.4
    WSO2/WSO2 Carbon OAuth, WSO2/WSO2 Identity Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2025-14779Low
    Improper Access Control via Secret Type Management API in WSO2 Identity Server
    CVSS 3.8
    WSO2/WSO2 Carbon Identity API Server Secret Management Common, WSO2/WSO2 Carbon Identity API Server Secret Management V1 +1generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2025-11850Medium
    Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]
    CVSS 4.3
    WSO2/WSO2 Identity Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2025-13736Low
    Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
    CVSS 3.7
    WSO2/WSO2 API Manager, WSO2/WSO2 Identity Server +3generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2024-10302Medium
    Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
    CVSS 4.0
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +6generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2024-6832Medium
    Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks
    CVSS 5.9
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +8generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2024-8995Medium
    Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
    CVSS 4.9
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +7generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-19019Medium
    poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
    CVSS 4.8
    poco-ai/poco-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-19011Medium
    TinyAGI agents.ts buildSystemPrompt file inclusion
    CVSS 5.3
    n/a/TinyAGIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-64604Unknown severity
    KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  40. CVE-2026-64603Unknown severity
    platform/x86: intel-hid: Protect ACPI notify handler against recursion
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-64602Unknown severity
    iio: adc: spear: Initialize completion before requesting IRQ
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  42. CVE-2026-64601Unknown severity
    ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  43. CVE-2026-64599Unknown severity
    crypto: amlogic - avoid double cleanup in meson_crypto_probe()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  44. CVE-2026-64598Unknown severity
    smb/client: Fix error code in smb2_aead_req_alloc()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-64597Unknown severity
    smb: client: fix double-free in SMB2_close() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  46. CVE-2026-64596Unknown severity
    libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-64595Unknown severity
    HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  48. CVE-2026-64594Unknown severity
    usb: gadget: f_fs: initialize reset_work at allocation time
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-64593Unknown severity
    btrfs: do not trim a device which is not writeable
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  50. CVE-2026-64592Unknown severity
    riscv: mm: Unconditionally sfence.vma for spurious fault
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
Page 13 of 325
Previous1112131415Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 601–650 of 16,240 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-5158Medium
    PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block
    CVSS 6.4
    wpxpo/Post Grid Gutenberg Blocks – PostXgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-57818High
    Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
    CVSS 8.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-61466Critical
    Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-63687Critical
    Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  5. CVE-2026-65583Critical
    Apache CXF: Self-issued ID token claims validation skipped
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-68079Critical
    Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-68481High
    Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  8. CVE-2026-19034High
    Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection
    CVSS 7.2
    Shibby/Tomatogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-65432High
    Apache CXF: XXE via WSDL/XSD import parsing
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-57817Critical
    Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-66909Critical
    Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-64958High
    Apache CXF: Denial of service via message header attachments
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  13. CVE-2026-57819High
    Apache CXF: No default restriction on the amount of form parameters per message
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-54225High
    Apache CXF: Denial of Service attack via large attachments
    CVSS 7.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-55980Medium
    Denial-of-service vulnerability in CatchPulse
    CVSS 5.5
    SecureAge/CatchPulsegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-55979Medium
    Improper access control check in CatchPulse's named pipe communication interface
    CVSS 5.2
    SecureAge/CatchPulsegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-55978High
    Improper access control vulnerability in CatchPulse
    CVSS 8.4
    SecureAge/CatchPulsegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-64640Medium
    Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
    CVSS 5.3
    Apache Software Foundation/Apache Polarisgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-19022Medium
    OpenHands send_pull_request.py initialize_repo command injection
    CVSS 6.3
    n/a/OpenHandsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-19021High
    SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection
    CVSS 7.3
    SourceCodester/Computer Repair Shop Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-19020Medium
    itsourcecode Hospital Management System servicetype.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-18597High
    Blind SSRF on Foxit PDF Services API
    CVSS 8.5
    Foxit Software Inc./Foxit PDF Services APIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-5430Critical
    Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
    CVSS 10.0
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +3generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-1728Critical
    Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
    CVSS 9.8
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +4generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  25. CVE-2025-15039Critical
    Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
    CVSS 9.4
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +8generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-0637Medium
    Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
    CVSS 4.4
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +7generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2025-13394Medium
    Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
    CVSS 5.4
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +45generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  28. CVE-2026-18915Medium
    Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
    CVSS 5.0
    TÜBİTAK BİLGEM Software Technologies Research Institute/eta-otp-lockgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  29. CVE-2025-13909Medium
    Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure
    CVSS 4.3
    WSO2/Email OTP Authenticator, WSO2/WSO2 Carbon Abstract OTP Authenticator +3generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2025-12627Low
    Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions
    CVSS 2.4
    WSO2/WSO2 Carbon OAuth, WSO2/WSO2 Identity Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2025-14779Low
    Improper Access Control via Secret Type Management API in WSO2 Identity Server
    CVSS 3.8
    WSO2/WSO2 Carbon Identity API Server Secret Management Common, WSO2/WSO2 Carbon Identity API Server Secret Management V1 +1generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2025-11850Medium
    Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]
    CVSS 4.3
    WSO2/WSO2 Identity Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2025-13736Low
    Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
    CVSS 3.7
    WSO2/WSO2 API Manager, WSO2/WSO2 Identity Server +3generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2024-10302Medium
    Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
    CVSS 4.0
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +6generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2024-6832Medium
    Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks
    CVSS 5.9
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +8generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2024-8995Medium
    Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
    CVSS 4.9
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +7generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-19019Medium
    poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
    CVSS 4.8
    poco-ai/poco-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-19011Medium
    TinyAGI agents.ts buildSystemPrompt file inclusion
    CVSS 5.3
    n/a/TinyAGIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-64604Unknown severity
    KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  40. CVE-2026-64603Unknown severity
    platform/x86: intel-hid: Protect ACPI notify handler against recursion
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-64602Unknown severity
    iio: adc: spear: Initialize completion before requesting IRQ
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  42. CVE-2026-64601Unknown severity
    ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  43. CVE-2026-64599Unknown severity
    crypto: amlogic - avoid double cleanup in meson_crypto_probe()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  44. CVE-2026-64598Unknown severity
    smb/client: Fix error code in smb2_aead_req_alloc()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-64597Unknown severity
    smb: client: fix double-free in SMB2_close() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  46. CVE-2026-64596Unknown severity
    libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-64595Unknown severity
    HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  48. CVE-2026-64594Unknown severity
    usb: gadget: f_fs: initialize reset_work at allocation time
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-64593Unknown severity
    btrfs: do not trim a device which is not writeable
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  50. CVE-2026-64592Unknown severity
    riscv: mm: Unconditionally sfence.vma for spurious fault
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
Page 13 of 325
Previous1112131415Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard