1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 3:43 AM 17,172 active 1,443 known exploited

Catalog summary

17,172

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 3:43 AM 17,172 active 1,443 known exploited

Catalog summary

17,172

Active CVEs

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,951–7,000 of 17,172 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-40941High
    Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
    CVSS 7.1
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-40084Medium
    Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter
    CVSS 6.5
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-40083High
    Cacti: SQL Injection in managers.php
    CVSS 7.2
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 30, 2026View HOL analysis
  4. CVE-2026-40082Medium
    Cacti: Session Fixation via missing session_regenerate_id() after login
    CVSS 5.4
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-40080Medium
    Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect
    CVSS 6.1
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13283High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  7. CVE-2026-13282Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Google/Chromegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2026-13281High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  9. CVE-2026-22879High
    CVE Program Container
    CVSS 8.1
    vtk/vtkgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2025-71340High
    picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.runcode
    CVSS 8.1
    picklescan/picklescangeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2025-71338Critical
    Flowise - Arbitrary File Write to Remote Code Execution via document-store API
    CVSS 10.0
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026View HOL analysis
  12. CVE-2025-71336Critical
    Flowise - Unsandboxed Remote Code Execution via Custom MCP
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  13. CVE-2025-71335High
    Flowise - Session Invalidation Failure After Password Change
    CVSS 8.1
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  14. CVE-2025-71334Critical
    Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  15. CVE-2025-71333Critical
    Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2025-71328High
    Flowise - Unverified Password Change via Account Settings
    CVSS 8.3
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  17. CVE-2025-71327Critical
    Flowise - Authentication Bypass via Unprotected Registration Endpoint
    CVSS 9.1
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2025-71324High
    Flowise - Arbitrary File Read via chatId Parameter
    CVSS 7.5
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  19. CVE-2021-47987High
    Parse Server - Arbitrary Code Execution via Malicious Version Tags
    CVSS 7.5
    parse-community/parse-servergeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  20. CVE-2021-47986High
    Parse Server - Unreviewed Code Execution via Malicious Version Tags
    CVSS 7.5
    parse-community/parse-servergeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  21. CVE-2020-37256Medium
    Grav - Cross-Site Scripting in Admin Plugin Page Editor
    CVSS 5.4
    Grav/Gravgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  22. CVE-2026-10098Medium
    OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
    CVSS 6.3
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026View HOL analysis
  23. CVE-2026-12992High
    Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-11703High
    Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026View HOL analysis
  25. CVE-2026-12975High
    Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in content-type detection leads to blind xxe / ssrf / billion-laughs dos
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-40702Critical
    EVoke Systems EVoke CSMS Missing Authentication for Critical Function
    CVSS 9.4
    EVoke/EVoke CSMSgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  27. CVE-2026-11800High
    Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-44622Medium
    EVoke Systems EVoke CSMS Insufficiently Protected Credentials
    CVSS 6.5
    EVoke/EVoke CSMSgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  29. CVE-2026-12473High
    OHIF Viewers DICOM Server-Side request forgery
    CVSS 8.2
    Open Health Imaging Foundation (OHIF)/DICOM Web Viewer Frameworkgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  30. CVE-2026-10097High
    ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  31. CVE-2026-10512High
    X25519 x86_64 assembly final reduction leaves non-canonical field element
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  32. CVE-2026-46602High
    Lack of limit on tile sizes in x/image/tiff in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/tiffgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  33. CVE-2026-46601High
    Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/webpgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  34. CVE-2026-10592Medium
    Wildcard DNS SAN bypasses CA name-constraint checks
    CVSS 6.3
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  35. CVE-2026-11310High
    X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
    CVSS 8.7
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  36. CVE-2026-12340High
    Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  37. CVE-2026-2299Medium
    Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
    CVSS 4.2
    Mattermost/Mattermost Google Drive Plugingeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-12921High
    Use after free in AzeoTech DAQFactory
    CVSS 8.4
    AzeoTech/DAQFactorygeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 16, 2026View HOL analysis
  39. CVE-2026-12897High
    Out-of-bounds read in Horner Automation Cscape
    CVSS 8.4
    Horner Automation/Cscapegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  40. CVE-2026-47770Medium
    jq: stack overflow in deep structural equality
    CVSS 6.8
    jqlang/jqgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  41. CVE-2026-11999High
    X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
    CVSS 8.2
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  42. CVE-2026-13351High
    net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets
    CVSS 7.5
    zephyrproject-rtos/Zephyrgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2026-9800High
    Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-13350Low
    CISA ADP Vulnrichment
    CVSS 2.3
    pretix/Venuelessgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  45. CVE-2026-45233High
    HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave
    CVSS 8.1
    danpros/htmlygeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 28, 2026View HOL analysis
  46. CVE-2026-4522Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    HYPR/Passwordlessgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  47. CVE-2026-12844High
    List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function
    CVSS 7.5
    DROLSKY/List::SomeUtils::XSgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  48. CVE-2026-13225Medium
    Stored XSS in ticket confirmation page
    CVSS 5.3
    pretix/pretixgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  49. CVE-2026-13222Medium
    Insufficient validation of payment status in pretix-oppwa
    CVSS 6.3
    pretix/pretix-oppwageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  50. CVE-2026-13223Medium
    Insufficient validation of payment status in pretix-computop
    CVSS 6.3
    pretix/pretix-computopgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
Page 140 of 344
Previous138139140141142Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,951–7,000 of 17,172 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-40941High
    Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
    CVSS 7.1
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-40084Medium
    Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter
    CVSS 6.5
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-40083High
    Cacti: SQL Injection in managers.php
    CVSS 7.2
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 30, 2026View HOL analysis
  4. CVE-2026-40082Medium
    Cacti: Session Fixation via missing session_regenerate_id() after login
    CVSS 5.4
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-40080Medium
    Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect
    CVSS 6.1
    Cacti/cactigeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13283High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  7. CVE-2026-13282Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Google/Chromegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2026-13281High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  9. CVE-2026-22879High
    CVE Program Container
    CVSS 8.1
    vtk/vtkgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2025-71340High
    picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.runcode
    CVSS 8.1
    picklescan/picklescangeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2025-71338Critical
    Flowise - Arbitrary File Write to Remote Code Execution via document-store API
    CVSS 10.0
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026View HOL analysis
  12. CVE-2025-71336Critical
    Flowise - Unsandboxed Remote Code Execution via Custom MCP
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  13. CVE-2025-71335High
    Flowise - Session Invalidation Failure After Password Change
    CVSS 8.1
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  14. CVE-2025-71334Critical
    Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  15. CVE-2025-71333Critical
    Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2025-71328High
    Flowise - Unverified Password Change via Account Settings
    CVSS 8.3
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  17. CVE-2025-71327Critical
    Flowise - Authentication Bypass via Unprotected Registration Endpoint
    CVSS 9.1
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2025-71324High
    Flowise - Arbitrary File Read via chatId Parameter
    CVSS 7.5
    Flowise/Flowisegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  19. CVE-2021-47987High
    Parse Server - Arbitrary Code Execution via Malicious Version Tags
    CVSS 7.5
    parse-community/parse-servergeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  20. CVE-2021-47986High
    Parse Server - Unreviewed Code Execution via Malicious Version Tags
    CVSS 7.5
    parse-community/parse-servergeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  21. CVE-2020-37256Medium
    Grav - Cross-Site Scripting in Admin Plugin Page Editor
    CVSS 5.4
    Grav/Gravgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  22. CVE-2026-10098Medium
    OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
    CVSS 6.3
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026View HOL analysis
  23. CVE-2026-12992High
    Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-11703High
    Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 27, 2026View HOL analysis
  25. CVE-2026-12975High
    Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in content-type detection leads to blind xxe / ssrf / billion-laughs dos
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-40702Critical
    EVoke Systems EVoke CSMS Missing Authentication for Critical Function
    CVSS 9.4
    EVoke/EVoke CSMSgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  27. CVE-2026-11800High
    Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-44622Medium
    EVoke Systems EVoke CSMS Insufficiently Protected Credentials
    CVSS 6.5
    EVoke/EVoke CSMSgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  29. CVE-2026-12473High
    OHIF Viewers DICOM Server-Side request forgery
    CVSS 8.2
    Open Health Imaging Foundation (OHIF)/DICOM Web Viewer Frameworkgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  30. CVE-2026-10097High
    ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  31. CVE-2026-10512High
    X25519 x86_64 assembly final reduction leaves non-canonical field element
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  32. CVE-2026-46602High
    Lack of limit on tile sizes in x/image/tiff in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/tiffgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  33. CVE-2026-46601High
    Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/webpgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  34. CVE-2026-10592Medium
    Wildcard DNS SAN bypasses CA name-constraint checks
    CVSS 6.3
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  35. CVE-2026-11310High
    X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
    CVSS 8.7
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  36. CVE-2026-12340High
    Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation
    CVSS 7.5
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  37. CVE-2026-2299Medium
    Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
    CVSS 4.2
    Mattermost/Mattermost Google Drive Plugingeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-12921High
    Use after free in AzeoTech DAQFactory
    CVSS 8.4
    AzeoTech/DAQFactorygeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 16, 2026View HOL analysis
  39. CVE-2026-12897High
    Out-of-bounds read in Horner Automation Cscape
    CVSS 8.4
    Horner Automation/Cscapegeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  40. CVE-2026-47770Medium
    jq: stack overflow in deep structural equality
    CVSS 6.8
    jqlang/jqgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  41. CVE-2026-11999High
    X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
    CVSS 8.2
    wolfSSL/wolfSSLgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  42. CVE-2026-13351High
    net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets
    CVSS 7.5
    zephyrproject-rtos/Zephyrgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2026-9800High
    Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-13350Low
    CISA ADP Vulnrichment
    CVSS 2.3
    pretix/Venuelessgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  45. CVE-2026-45233High
    HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave
    CVSS 8.1
    danpros/htmlygeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jul 28, 2026View HOL analysis
  46. CVE-2026-4522Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    HYPR/Passwordlessgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  47. CVE-2026-12844High
    List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function
    CVSS 7.5
    DROLSKY/List::SomeUtils::XSgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  48. CVE-2026-13225Medium
    Stored XSS in ticket confirmation page
    CVSS 5.3
    pretix/pretixgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  49. CVE-2026-13222Medium
    Insufficient validation of payment status in pretix-oppwa
    CVSS 6.3
    pretix/pretix-oppwageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  50. CVE-2026-13223Medium
    Insufficient validation of payment status in pretix-computop
    CVSS 6.3
    pretix/pretix-computopgeneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
Page 140 of 344
Previous138139140141142Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard