1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 2:50 AM 17,170 active 1,443 known exploited

Catalog summary

17,170

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 2:50 AM 17,170 active 1,443 known exploited

Catalog summary

17,170

Active CVEs

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,851–6,900 of 17,170 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2024-23581Medium
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability
    CVSS 6.7
    HCLSoftware/Traveler for Microsoft Outlookgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  2. CVE-2026-46604High
    Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image
    CVSS 7.5
    golang.org/x/image, golang.org/x/image/golang.org/x/image/tiffgeneric · go
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  3. CVE-2026-46710High
    Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path
    CVSS 7.8
    notepad-plus-plus/notepad-plus-plusgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-32833High
    Cudy LT300 3.0 OS Command Injection via NTP Configuration
    CVSS 8.8
    Shenzhen Cudy Technology Co., Ltd./LT300 3.0generic
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  5. CVE-2026-44733Medium
    OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements
    CVSS 5.9
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-44731Medium
    OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosure
    CVSS 4.3
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  7. CVE-2026-53322High
    vfio/pci: Clean up DMABUFs before disabling function
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-53309Critical
    ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-53300High
    net: enetc: fix NTMP DMA use-after-free issue
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-53290High
    drm/xe/eustall: Fix drm_dev_put called before stream disable in close
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-53284High
    btrfs: only release the dirty pages io tree after successful writes
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-53281High
    iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-44732Medium
    OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources
    CVSS 4.3
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-44734Medium
    OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename
    CVSS 6.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  15. CVE-2026-44735Medium
    OpenProject: Shares API Information Disclosure
    CVSS 6.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-29509Medium
    Patool < 4.0.5 Path Traversal via safe_extract() Function
    CVSS 5.4
    wummel/patoolgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-44696Medium
    OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltration
    CVSS 5.7
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  18. CVE-2026-44736Medium
    OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
    CVSS 6.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  19. CVE-2026-46386Critical
    OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`
    CVSS 9.9
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  20. CVE-2026-47193High
    OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks
    CVSS 7.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  21. CVE-2026-13372High
    CISA ADP Vulnrichment
    CVSS 7.2
    Devolutions/Remote Desktop Managergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  22. CVE-2026-48090Medium
    Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)
    CVSS 5.9
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-47220High
    Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-47205Medium
    Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
    CVSS 5.9
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  25. CVE-2026-47692Medium
    Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
    CVSS 4.8
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  26. CVE-2026-47207Medium
    Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message
    CVSS 6.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  27. CVE-2026-47204Medium
    Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes
    CVSS 6.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-47221Medium
    Envoy: Null pointer deref in internal redirects
    CVSS 5.9
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  29. CVE-2026-48044High
    Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-48042High
    Envoy: Stack overflow in destructor of highly nested JSON
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-47778Medium
    Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
    CVSS 4.4
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-47775Medium
    Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
    CVSS 6.8
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-47206Low
    Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
    CVSS 2.3
    dragonflydb/dragonflygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  34. CVE-2026-28385Medium
    SSRF via image import from URL allows internal network probing by authenticated users
    CVSS 5.0
    Canonical/lxdgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-45405Critical
    Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and certs:add
    CVSS 9.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  36. CVE-2026-45406Critical
    Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Through eval
    CVSS 9.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  37. CVE-2026-45407Medium
    Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch
    CVSS 5.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-45408Critical
    Dokku: OS Command Injection via App Name in Git Pre-Receive Hook
    CVSS 9.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  39. CVE-2025-32394Medium
    AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock
    CVSS 5.3
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  40. CVE-2026-11779Medium
    PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
    CVSS 5.3
    PayloadCMS/PayloadCMSgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  41. CVE-2025-32423Medium
    AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock
    CVSS 5.3
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-13434Medium
    Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2023-20572Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  44. CVE-2026-0828High
    Kernel driver vulnerability in Safetica Endpoint Client
    CVSS 7.5
    Safetica/Endpoint Clientgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  45. CVE-2026-0685Critical
    Server side template inject (SSTI) in Edgewall Genshi Template Engine
    CVSS 9.8
    Edgewall *Genshi*/Genshigeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  46. CVE-2023-20540Low
    CISA ADP Vulnrichment
    CVSS 1.8
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  47. CVE-2026-44018Medium
    Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
    CVSS 5.5
    docling-project/doclinggeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  48. CVE-2025-11919Critical
    Unprotected temporary directories in Wolfram Cloud may result in privilege escalation
    CVSS 9.6
    Wolfram Research Inc./Cloudgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  49. CVE-2026-12411High
    Broken Access Control in Canonical LXD DevLXD API
    CVSS 8.4
    Canonical/lxdgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  50. CVE-2026-45195High
    GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
Page 138 of 344
Previous136137138139140Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,851–6,900 of 17,170 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2024-23581Medium
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability
    CVSS 6.7
    HCLSoftware/Traveler for Microsoft Outlookgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  2. CVE-2026-46604High
    Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image
    CVSS 7.5
    golang.org/x/image, golang.org/x/image/golang.org/x/image/tiffgeneric · go
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  3. CVE-2026-46710High
    Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path
    CVSS 7.8
    notepad-plus-plus/notepad-plus-plusgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-32833High
    Cudy LT300 3.0 OS Command Injection via NTP Configuration
    CVSS 8.8
    Shenzhen Cudy Technology Co., Ltd./LT300 3.0generic
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  5. CVE-2026-44733Medium
    OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements
    CVSS 5.9
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-44731Medium
    OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosure
    CVSS 4.3
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  7. CVE-2026-53322High
    vfio/pci: Clean up DMABUFs before disabling function
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-53309Critical
    ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-53300High
    net: enetc: fix NTMP DMA use-after-free issue
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-53290High
    drm/xe/eustall: Fix drm_dev_put called before stream disable in close
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-53284High
    btrfs: only release the dirty pages io tree after successful writes
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-53281High
    iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-44732Medium
    OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources
    CVSS 4.3
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-44734Medium
    OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename
    CVSS 6.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  15. CVE-2026-44735Medium
    OpenProject: Shares API Information Disclosure
    CVSS 6.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-29509Medium
    Patool < 4.0.5 Path Traversal via safe_extract() Function
    CVSS 5.4
    wummel/patoolgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-44696Medium
    OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltration
    CVSS 5.7
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  18. CVE-2026-44736Medium
    OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
    CVSS 6.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  19. CVE-2026-46386Critical
    OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`
    CVSS 9.9
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  20. CVE-2026-47193High
    OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks
    CVSS 7.5
    opf/openprojectgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  21. CVE-2026-13372High
    CISA ADP Vulnrichment
    CVSS 7.2
    Devolutions/Remote Desktop Managergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  22. CVE-2026-48090Medium
    Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)
    CVSS 5.9
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-47220High
    Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-47205Medium
    Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
    CVSS 5.9
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  25. CVE-2026-47692Medium
    Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
    CVSS 4.8
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  26. CVE-2026-47207Medium
    Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message
    CVSS 6.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  27. CVE-2026-47204Medium
    Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes
    CVSS 6.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-47221Medium
    Envoy: Null pointer deref in internal redirects
    CVSS 5.9
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  29. CVE-2026-48044High
    Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-48042High
    Envoy: Stack overflow in destructor of highly nested JSON
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-47778Medium
    Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
    CVSS 4.4
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-47775Medium
    Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
    CVSS 6.8
    envoyproxy/envoygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-47206Low
    Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
    CVSS 2.3
    dragonflydb/dragonflygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  34. CVE-2026-28385Medium
    SSRF via image import from URL allows internal network probing by authenticated users
    CVSS 5.0
    Canonical/lxdgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-45405Critical
    Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and certs:add
    CVSS 9.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  36. CVE-2026-45406Critical
    Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Through eval
    CVSS 9.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  37. CVE-2026-45407Medium
    Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch
    CVSS 5.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-45408Critical
    Dokku: OS Command Injection via App Name in Git Pre-Receive Hook
    CVSS 9.0
    dokku/dokkugeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  39. CVE-2025-32394Medium
    AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock
    CVSS 5.3
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  40. CVE-2026-11779Medium
    PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
    CVSS 5.3
    PayloadCMS/PayloadCMSgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  41. CVE-2025-32423Medium
    AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock
    CVSS 5.3
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-13434Medium
    Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2023-20572Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  44. CVE-2026-0828High
    Kernel driver vulnerability in Safetica Endpoint Client
    CVSS 7.5
    Safetica/Endpoint Clientgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  45. CVE-2026-0685Critical
    Server side template inject (SSTI) in Edgewall Genshi Template Engine
    CVSS 9.8
    Edgewall *Genshi*/Genshigeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  46. CVE-2023-20540Low
    CISA ADP Vulnrichment
    CVSS 1.8
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  47. CVE-2026-44018Medium
    Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
    CVSS 5.5
    docling-project/doclinggeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026View HOL analysis
  48. CVE-2025-11919Critical
    Unprotected temporary directories in Wolfram Cloud may result in privilege escalation
    CVSS 9.6
    Wolfram Research Inc./Cloudgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  49. CVE-2026-12411High
    Broken Access Control in Canonical LXD DevLXD API
    CVSS 8.4
    Canonical/lxdgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  50. CVE-2026-45195High
    GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
Page 138 of 344
Previous136137138139140Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard