1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 5:43 AM 17,206 active 1,443 known exploited

Catalog summary

17,206

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 5:43 AM 17,206 active 1,443 known exploited

Catalog summary

17,206

Active CVEs

8,684

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,151–7,200 of 17,206 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-37452High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  2. CVE-2026-37453High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  3. CVE-2026-37454High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  4. CVE-2026-38637High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  5. CVE-2026-38640High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  6. CVE-2026-40079Critical
    Cacti: Command Injection via escape_command() no-op in RRDtool execution
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  7. CVE-2026-39951High
    Cacti: Stored SQL Injection via graph_name_regexp in Reports feature
    CVSS 7.6
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  8. CVE-2026-39948Critical
    Cacti has SQL Injection via rfilter parameter in RLIKE clauses
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  9. CVE-2026-39955Critical
    Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2026-39938Critical
    Cacti: Unauthenticated RCE on Graph Image
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2026-39900Medium
    Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context
    CVSS 6.1
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  12. CVE-2026-39899Medium
    Cacti: Path Traversal via filename parameter in package_import.php
    CVSS 6.9
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  13. CVE-2026-39897Medium
    Cacti has a Reflected XSS Vulnerability via html_auth_footer
    CVSS 6.1
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  14. CVE-2026-39894Low
    Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting
    CVSS 2.9
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  15. CVE-2026-39893Critical
    Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  16. CVE-2026-2050High
    GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-10043Unknown severity
    MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    MosaicML/Composergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  18. CVE-2026-10642Medium
    Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-47110Medium
    Tiptap for PHP < 2.1.1 DoS via Malformed href Attribute
    CVSS 6.5
    ueberdosis/tiptap-phpgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-45757Low
    Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens
    CVSS 2.3
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  21. CVE-2026-33543Critical
    FOSSBilling: Authentication bypass allows unauthenticated administrator creation
    CVSS 9.3
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  22. CVE-2026-46423Critical
    Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty
    CVSS 9.3
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  23. CVE-2026-45689Critical
    Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO
    CVSS 9.1
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  24. CVE-2026-45688Critical
    Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack
    CVSS 9.1
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  25. CVE-2026-45687High
    Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage
    CVSS 8.5
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  26. CVE-2026-45677High
    Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS
    CVSS 8.7
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  27. CVE-2026-33235High
    AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating features
    CVSS 7.7
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  28. CVE-2026-47733Medium
    Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images
    CVSS 4.4
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  29. CVE-2026-13208Medium
    Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 6, 2026View HOL analysis
  30. CVE-2026-13201High
    Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-1840High
    Missing authentication for critical function in Hubbell Aclara Metrum Cellular Web Interface
    CVSS 7.5
    Hubbell/Aclara Metrum Cellular Web Interfacegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  32. CVE-2026-48028Medium
    Mastodon: Removal of integrity-protected JSON entries from signed activities
    CVSS 6.5
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  33. CVE-2026-47389High
    Mastodon: SSRF protection bypass on older Ruby versions
    CVSS 8.6
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  34. CVE-2026-46349Medium
    Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring
    CVSS 5.3
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  35. CVE-2026-46348High
    Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)
    CVSS 8.7
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  36. CVE-2026-27708High
    FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
    CVSS 7.1
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  37. CVE-2026-13037High
    CISA ADP Vulnrichment
    CVSS 7.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  38. CVE-2026-13036High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  39. CVE-2026-13035High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  40. CVE-2026-13034Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  41. CVE-2026-13031High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  42. CVE-2026-13030Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  43. CVE-2026-13029High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  44. CVE-2026-13027High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  45. CVE-2026-13026High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  46. CVE-2026-13025High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  47. CVE-2026-13024Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  48. CVE-2026-13023Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  49. CVE-2026-13022Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  50. CVE-2026-13021Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
Page 144 of 345
Previous142143144145146Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,684

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,151–7,200 of 17,206 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-37452High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  2. CVE-2026-37453High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  3. CVE-2026-37454High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  4. CVE-2026-38637High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  5. CVE-2026-38640High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 25, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  6. CVE-2026-40079Critical
    Cacti: Command Injection via escape_command() no-op in RRDtool execution
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  7. CVE-2026-39951High
    Cacti: Stored SQL Injection via graph_name_regexp in Reports feature
    CVSS 7.6
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  8. CVE-2026-39948Critical
    Cacti has SQL Injection via rfilter parameter in RLIKE clauses
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  9. CVE-2026-39955Critical
    Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2026-39938Critical
    Cacti: Unauthenticated RCE on Graph Image
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2026-39900Medium
    Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context
    CVSS 6.1
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  12. CVE-2026-39899Medium
    Cacti: Path Traversal via filename parameter in package_import.php
    CVSS 6.9
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 26, 2026View HOL analysis
  13. CVE-2026-39897Medium
    Cacti has a Reflected XSS Vulnerability via html_auth_footer
    CVSS 6.1
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  14. CVE-2026-39894Low
    Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting
    CVSS 2.9
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  15. CVE-2026-39893Critical
    Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php
    CVSS 9.8
    Cacti/cactigeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  16. CVE-2026-2050High
    GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-10043Unknown severity
    MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    MosaicML/Composergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  18. CVE-2026-10642Medium
    Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-47110Medium
    Tiptap for PHP < 2.1.1 DoS via Malformed href Attribute
    CVSS 6.5
    ueberdosis/tiptap-phpgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-45757Low
    Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens
    CVSS 2.3
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  21. CVE-2026-33543Critical
    FOSSBilling: Authentication bypass allows unauthenticated administrator creation
    CVSS 9.3
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  22. CVE-2026-46423Critical
    Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty
    CVSS 9.3
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  23. CVE-2026-45689Critical
    Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO
    CVSS 9.1
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  24. CVE-2026-45688Critical
    Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack
    CVSS 9.1
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  25. CVE-2026-45687High
    Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage
    CVSS 8.5
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  26. CVE-2026-45677High
    Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS
    CVSS 8.7
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  27. CVE-2026-33235High
    AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating features
    CVSS 7.7
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  28. CVE-2026-47733Medium
    Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images
    CVSS 4.4
    RocketChat/Rocket.Chatgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  29. CVE-2026-13208Medium
    Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 6, 2026View HOL analysis
  30. CVE-2026-13201High
    Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-1840High
    Missing authentication for critical function in Hubbell Aclara Metrum Cellular Web Interface
    CVSS 7.5
    Hubbell/Aclara Metrum Cellular Web Interfacegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  32. CVE-2026-48028Medium
    Mastodon: Removal of integrity-protected JSON entries from signed activities
    CVSS 6.5
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  33. CVE-2026-47389High
    Mastodon: SSRF protection bypass on older Ruby versions
    CVSS 8.6
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  34. CVE-2026-46349Medium
    Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring
    CVSS 5.3
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  35. CVE-2026-46348High
    Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)
    CVSS 8.7
    mastodon/mastodongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  36. CVE-2026-27708High
    FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
    CVSS 7.1
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  37. CVE-2026-13037High
    CISA ADP Vulnrichment
    CVSS 7.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  38. CVE-2026-13036High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  39. CVE-2026-13035High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  40. CVE-2026-13034Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  41. CVE-2026-13031High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  42. CVE-2026-13030Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  43. CVE-2026-13029High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  44. CVE-2026-13027High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  45. CVE-2026-13026High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  46. CVE-2026-13025High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  47. CVE-2026-13024Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  48. CVE-2026-13023Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  49. CVE-2026-13022Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  50. CVE-2026-13021Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Google/Chromegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
Page 144 of 345
Previous142143144145146Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard