1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 11:50 PM 17,128 active 1,443 known exploited

Catalog summary

17,128

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 11:50 PM 17,128 active 1,443 known exploited

Catalog summary

17,128

Active CVEs

8,546

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,501–6,550 of 17,128 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-11594High
    IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities
    CVSS 8.5
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  2. CVE-2026-10562Medium
    Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface
    CVSS 5.9
    TP-Link Systems Inc./Archer AX20 V2.0generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  3. CVE-2025-12530Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 5.9
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  4. CVE-2026-13207High
    Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing
    CVSS 7.5
    Frangoteam/FUXA SCADA/HMIgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  5. CVE-2025-36319Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  6. CVE-2025-36320Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 6.4
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  7. CVE-2025-36321Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 5.7
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  8. CVE-2025-36323Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 5.4
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  9. CVE-2025-36324Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  10. CVE-2025-36327Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 6.5
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  11. CVE-2025-36328Medium
    Error Message Containing Sensitive Information found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  12. CVE-2025-36333Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  13. CVE-2025-36336Medium
    Cleartext Transmission of Sensitive Information in Watson Data Intelligence
    CVSS 5.9
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  14. CVE-2025-36359High
    IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability.
    CVSS 8.1
    IBM/DevOps Automation, IBM/DevOps Loopgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  15. CVE-2025-36372Medium
    IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
    CVSS 5.5
    IBM/Db2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  16. CVE-2026-10109Critical
    IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling
    CVSS 9.8
    IBM/Db2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  17. CVE-2026-10129High
    SSRF via HTTP Redirect Following in Langflow API Request Component
    CVSS 8.5
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  18. CVE-2026-10134Critical
    Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
    CVSS 10.0
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2026-10140Critical
    Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem
    CVSS 9.6
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  20. CVE-2026-10546High
    DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component
    CVSS 7.1
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  21. CVE-2026-10560High
    Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS
    CVSS 8.2
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2026-10564High
    SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection
    CVSS 8.2
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  23. CVE-2026-11546High
    IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability
    CVSS 7.1
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  24. CVE-2026-11595Medium
    IBM WebSphere Application Server is affected by a Path Traversal vulnerability
    CVSS 4.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  25. CVE-2026-11708Critical
    IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
    CVSS 9.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-11712Critical
    IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
    CVSS 9.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  27. CVE-2026-11714High
    IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability
    CVSS 8.5
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-11806High
    IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability
    CVSS 7.2
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  29. CVE-2026-11906Medium
    IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user
    CVSS 6.5
    IBM/Db2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  30. CVE-2026-12084Medium
    IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
    CVSS 5.4
    IBM/UCD - IBM DevOps Deploygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  31. CVE-2026-12085Medium
    IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability
    CVSS 6.5
    IBM/UCD - IBM DevOps Deploy, IBM/UCD - IBM UrbanCode Deploygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  32. CVE-2026-12086Medium
    IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability
    CVSS 6.2
    IBM/UCD - IBM DevOps Deploy, IBM/UCD - IBM UrbanCode Deploygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  33. CVE-2026-13449High
    XXE attack in IBM Business Automation Manager Open Editions
    CVSS 7.6
    IBM/Business Automation Manager Open Editionsgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  34. CVE-2026-13759High
    IBM WebSphere eXtreme Scale is affected by Insecure Deserilization
    CVSS 7.5
    IBM/WebSphere Extreme Scalegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 3, 2026View HOL analysis
  35. CVE-2026-13772High
    IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
    CVSS 7.5
    IBM/WebSphere Extreme Scalegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 3, 2026View HOL analysis
  36. CVE-2026-13773Medium
    IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol
    CVSS 6.0
    IBM/WebSphere Extreme Scalegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  37. CVE-2026-3602Medium
    IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection
    CVSS 4.7
    IBM/App Connect Enterprise, IBM/Integration Bus for z/OSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 20, 2026View HOL analysis
  38. CVE-2026-10513High
    Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties
    CVSS 7.2
    pfefferle/Webmentiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-10655Medium
    Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-10654Low
    RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic
    CVSS 3.1
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  41. CVE-2026-10653Medium
    Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref
    CVSS 6.4
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  42. CVE-2026-10652Medium
    Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)
    CVSS 4.8
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  43. CVE-2026-13455Medium
    PostgreSQL Anonymizer: Unrestricted function can leak the secret salt
    CVSS 4.3
    DALIBO/PostgreSQL Anonymizergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  44. CVE-2026-44948Medium
    Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
    CVSS 5.3
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  45. CVE-2026-48282Critical
    ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
    CVSS 10.0 Known exploited
    Adobe/ColdFusiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-4360Medium
    Tarfile.extract() doesn't fully respect filter parameter
    CVSS 5.3
    Python Software Foundation/CPythongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-44949High
    Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook
    CVSS 7.0
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  48. CVE-2026-27957High
    Coolify: Authenticated RCE via command injection in CA certificate management feature
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  49. CVE-2026-27956Medium
    Coolify: Cross-team application domain enumeration via domains_by_server endpoint
    CVSS 4.3
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  50. CVE-2026-27955Medium
    Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()`
    CVSS 6.6
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
Page 131 of 343
Previous129130131132133Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,546

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,501–6,550 of 17,128 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-11594High
    IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities
    CVSS 8.5
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  2. CVE-2026-10562Medium
    Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface
    CVSS 5.9
    TP-Link Systems Inc./Archer AX20 V2.0generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  3. CVE-2025-12530Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 5.9
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  4. CVE-2026-13207High
    Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing
    CVSS 7.5
    Frangoteam/FUXA SCADA/HMIgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  5. CVE-2025-36319Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  6. CVE-2025-36320Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 6.4
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  7. CVE-2025-36321Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 5.7
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  8. CVE-2025-36323Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 5.4
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  9. CVE-2025-36324Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  10. CVE-2025-36327Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 6.5
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  11. CVE-2025-36328Medium
    Error Message Containing Sensitive Information found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  12. CVE-2025-36333Medium
    Vulnerabilities found in Watson Data Intelligence
    CVSS 4.3
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  13. CVE-2025-36336Medium
    Cleartext Transmission of Sensitive Information in Watson Data Intelligence
    CVSS 5.9
    IBM/watsonx.data intelligencegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  14. CVE-2025-36359High
    IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability.
    CVSS 8.1
    IBM/DevOps Automation, IBM/DevOps Loopgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  15. CVE-2025-36372Medium
    IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
    CVSS 5.5
    IBM/Db2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  16. CVE-2026-10109Critical
    IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling
    CVSS 9.8
    IBM/Db2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  17. CVE-2026-10129High
    SSRF via HTTP Redirect Following in Langflow API Request Component
    CVSS 8.5
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  18. CVE-2026-10134Critical
    Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
    CVSS 10.0
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2026-10140Critical
    Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem
    CVSS 9.6
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  20. CVE-2026-10546High
    DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component
    CVSS 7.1
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  21. CVE-2026-10560High
    Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS
    CVSS 8.2
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2026-10564High
    SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection
    CVSS 8.2
    IBM/Langflow OSSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  23. CVE-2026-11546High
    IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability
    CVSS 7.1
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  24. CVE-2026-11595Medium
    IBM WebSphere Application Server is affected by a Path Traversal vulnerability
    CVSS 4.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  25. CVE-2026-11708Critical
    IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
    CVSS 9.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-11712Critical
    IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
    CVSS 9.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  27. CVE-2026-11714High
    IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability
    CVSS 8.5
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-11806High
    IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability
    CVSS 7.2
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  29. CVE-2026-11906Medium
    IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user
    CVSS 6.5
    IBM/Db2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  30. CVE-2026-12084Medium
    IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
    CVSS 5.4
    IBM/UCD - IBM DevOps Deploygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  31. CVE-2026-12085Medium
    IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability
    CVSS 6.5
    IBM/UCD - IBM DevOps Deploy, IBM/UCD - IBM UrbanCode Deploygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  32. CVE-2026-12086Medium
    IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability
    CVSS 6.2
    IBM/UCD - IBM DevOps Deploy, IBM/UCD - IBM UrbanCode Deploygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  33. CVE-2026-13449High
    XXE attack in IBM Business Automation Manager Open Editions
    CVSS 7.6
    IBM/Business Automation Manager Open Editionsgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  34. CVE-2026-13759High
    IBM WebSphere eXtreme Scale is affected by Insecure Deserilization
    CVSS 7.5
    IBM/WebSphere Extreme Scalegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 3, 2026View HOL analysis
  35. CVE-2026-13772High
    IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
    CVSS 7.5
    IBM/WebSphere Extreme Scalegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 3, 2026View HOL analysis
  36. CVE-2026-13773Medium
    IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol
    CVSS 6.0
    IBM/WebSphere Extreme Scalegeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026View HOL analysis
  37. CVE-2026-3602Medium
    IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection
    CVSS 4.7
    IBM/App Connect Enterprise, IBM/Integration Bus for z/OSgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 20, 2026View HOL analysis
  38. CVE-2026-10513High
    Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties
    CVSS 7.2
    pfefferle/Webmentiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-10655Medium
    Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-10654Low
    RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic
    CVSS 3.1
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  41. CVE-2026-10653Medium
    Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref
    CVSS 6.4
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  42. CVE-2026-10652Medium
    Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)
    CVSS 4.8
    zephyrproject/zephyrgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  43. CVE-2026-13455Medium
    PostgreSQL Anonymizer: Unrestricted function can leak the secret salt
    CVSS 4.3
    DALIBO/PostgreSQL Anonymizergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  44. CVE-2026-44948Medium
    Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
    CVSS 5.3
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  45. CVE-2026-48282Critical
    ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
    CVSS 10.0 Known exploited
    Adobe/ColdFusiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-4360Medium
    Tarfile.extract() doesn't fully respect filter parameter
    CVSS 5.3
    Python Software Foundation/CPythongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-44949High
    Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook
    CVSS 7.0
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  48. CVE-2026-27957High
    Coolify: Authenticated RCE via command injection in CA certificate management feature
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  49. CVE-2026-27956Medium
    Coolify: Cross-team application domain enumeration via domains_by_server endpoint
    CVSS 4.3
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  50. CVE-2026-27955Medium
    Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()`
    CVSS 6.6
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
Page 131 of 343
Previous129130131132133Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard