1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 7:35 AM 17,214 active 1,443 known exploited

Catalog summary

17,214

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 7:35 AM 17,214 active 1,443 known exploited

Catalog summary

17,214

Active CVEs

8,692

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,351–7,400 of 17,214 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12850Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  2. CVE-2026-12849Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  3. CVE-2026-12486Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  4. CVE-2026-12848Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  5. CVE-2026-12847Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  6. CVE-2026-12846Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  7. CVE-2026-12485Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  8. CVE-2026-12488Medium
    GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability
    CVSS 6.2
    GeoVision Inc./GeoVisiongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  9. CVE-2026-3652High
    ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter
    CVSS 7.2
    n/a/ARformsgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  10. CVE-2026-11614Medium
    Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets
    CVSS 6.4
    xpro/Xpro Addons — 140+ Widgets for Elementorgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  11. CVE-2026-12681High
    CISA ADP Vulnrichment
    CVSS 8.9
    Google/go-attestation, github.com/google/go-attestationgeneric · go
    PublishedJun 24, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026View HOL analysis
  12. CVE-2025-60466Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  13. CVE-2025-60467High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2025-60468Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  15. CVE-2025-60471Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2025-60473Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  17. CVE-2025-60474High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-12164Medium
    Privilege Escalation in Fortra File Integrity Monitoring (FIM)
    CVSS 4.4
    Fortra/File Integrity Monitoring (FIM)generic
    PublishedJun 23, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  19. CVE-2026-12163Medium
    Stored XSS in Fortra File Integrity Monitoring (FIM)
    CVSS 5.5
    Fortra/File Integrity Monitoring (FIM)generic
    PublishedJun 23, 2026First seen at HOL Jun 24, 2026Updated Jun 28, 2026 Fix availableView HOL analysis
  20. CVE-2026-11972High
    tarfile opened in streaming mode mishandles EOF
    CVSS 8.2
    Python Software Foundation/CPythongeneric
    PublishedJun 23, 2026First seen at HOL Jun 24, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-41862High
    CISA ADP Vulnrichment
    CVSS 8.8
    Spring/Spring Statemachinegeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  22. CVE-2026-54513High
    jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
    CVSS 8.1
    FasterXML/jackson-databind, com.fasterxml.jackson.core:jackson-databind +1generic · maven
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-46547Medium
    NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
    CVSS 6.1
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  24. CVE-2026-46548Medium
    NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
    CVSS 4.3
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  25. CVE-2026-46549Low
    NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
    CVSS 2.0
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  26. CVE-2026-46550Medium
    NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags
    CVSS 5.4
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  27. CVE-2026-46552Medium
    NocoDB: Shared-base link access can invite arbitrary users as persistent base members
    CVSS 5.8
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  28. CVE-2026-46553Low
    NocoDB: Attachment Size Limit Bypass via Upload-by-URL
    CVSS 2.1
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  29. CVE-2026-46551Medium
    NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
    CVSS 6.5
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  30. CVE-2026-46554Low
    NocoDB: Stale Auth Cache After API Token Deletion
    CVSS 2.3
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  31. CVE-2026-23513High
    FOSSBilling: Broken Authorization in Client Transaction and Order Listings
    CVSS 7.1
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  32. CVE-2026-12892Medium
    Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 6, 2026View HOL analysis
  33. CVE-2026-12891Medium
    Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-11820Medium
    Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-11819Medium
    Community.general: community.general keyring_info — os keyring passphrase returned in plaintext
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 8, 2026View HOL analysis
  36. CVE-2025-64105Medium
    FOSSBilling: IDOR Vulnerability in Support Ticket Creation
    CVSS 5.1
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  37. CVE-2026-12112High
    Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-11807Critical
    Eda-server: websocket missing authorization allows credential theft via activation_id spoofing
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 16, 2026View HOL analysis
  39. CVE-2026-45792Medium
    RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
    CVSS 6.9
    rtk-ai/rtkgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-55736Medium
    Private action arguments can be set by user input in Ash
    CVSS 5.9
    ash-project/ashgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  41. CVE-2020-9695High
    Acrobat Reader | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Acrobat Readergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  42. CVE-2020-9711Medium
    Acrobat Reader | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/Acrobat Readergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  43. CVE-2026-45135High
    Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
    CVSS 8.1
    caddyserver/caddygeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  44. CVE-2026-45692Medium
    Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
    CVSS 5.4
    caddyserver/caddy, github.com/caddyserver/caddy/v2generic · go
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  45. CVE-2020-9713Medium
    Acrobat Reader | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/Acrobat Readergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  46. CVE-2026-0864Medium
    Configuration Injection via Carriage Return (\r) in write() method
    CVSS 4.1
    Python Software Foundation/CPythongeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-44726High
    Deno: TLS retry copies stale upgrade hook, risking plaintext traffic
    CVSS 7.4
    denoland/denogeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  48. CVE-2025-71382Medium
    MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering
    CVSS 6.5
    ArtifexSoftware/mupdfgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-55255Critical
    Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
    CVSS 9.9 Known exploited
    langflow, langflow-ai/langflowgeneric · pip
    PublishedJun 23, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  50. CVE-2026-34913Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Revive/Adservergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
Page 148 of 345
Previous146147148149150Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,692

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,351–7,400 of 17,214 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12850Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  2. CVE-2026-12849Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  3. CVE-2026-12486Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  4. CVE-2026-12848Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  5. CVE-2026-12847Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  6. CVE-2026-12846Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  7. CVE-2026-12485Critical
    GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
    CVSS 10.0
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  8. CVE-2026-12488Medium
    GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability
    CVSS 6.2
    GeoVision Inc./GeoVisiongeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  9. CVE-2026-3652High
    ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter
    CVSS 7.2
    n/a/ARformsgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  10. CVE-2026-11614Medium
    Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets
    CVSS 6.4
    xpro/Xpro Addons — 140+ Widgets for Elementorgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  11. CVE-2026-12681High
    CISA ADP Vulnrichment
    CVSS 8.9
    Google/go-attestation, github.com/google/go-attestationgeneric · go
    PublishedJun 24, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026View HOL analysis
  12. CVE-2025-60466Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  13. CVE-2025-60467High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2025-60468Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 26, 2026View HOL analysis
  15. CVE-2025-60471Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2025-60473Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  17. CVE-2025-60474High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 24, 2026First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-12164Medium
    Privilege Escalation in Fortra File Integrity Monitoring (FIM)
    CVSS 4.4
    Fortra/File Integrity Monitoring (FIM)generic
    PublishedJun 23, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  19. CVE-2026-12163Medium
    Stored XSS in Fortra File Integrity Monitoring (FIM)
    CVSS 5.5
    Fortra/File Integrity Monitoring (FIM)generic
    PublishedJun 23, 2026First seen at HOL Jun 24, 2026Updated Jun 28, 2026 Fix availableView HOL analysis
  20. CVE-2026-11972High
    tarfile opened in streaming mode mishandles EOF
    CVSS 8.2
    Python Software Foundation/CPythongeneric
    PublishedJun 23, 2026First seen at HOL Jun 24, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-41862High
    CISA ADP Vulnrichment
    CVSS 8.8
    Spring/Spring Statemachinegeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  22. CVE-2026-54513High
    jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
    CVSS 8.1
    FasterXML/jackson-databind, com.fasterxml.jackson.core:jackson-databind +1generic · maven
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-46547Medium
    NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
    CVSS 6.1
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  24. CVE-2026-46548Medium
    NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
    CVSS 4.3
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  25. CVE-2026-46549Low
    NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
    CVSS 2.0
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  26. CVE-2026-46550Medium
    NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags
    CVSS 5.4
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  27. CVE-2026-46552Medium
    NocoDB: Shared-base link access can invite arbitrary users as persistent base members
    CVSS 5.8
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  28. CVE-2026-46553Low
    NocoDB: Attachment Size Limit Bypass via Upload-by-URL
    CVSS 2.1
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  29. CVE-2026-46551Medium
    NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
    CVSS 6.5
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  30. CVE-2026-46554Low
    NocoDB: Stale Auth Cache After API Token Deletion
    CVSS 2.3
    nocodb/nocodbgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  31. CVE-2026-23513High
    FOSSBilling: Broken Authorization in Client Transaction and Order Listings
    CVSS 7.1
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  32. CVE-2026-12892Medium
    Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 6, 2026View HOL analysis
  33. CVE-2026-12891Medium
    Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-11820Medium
    Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-11819Medium
    Community.general: community.general keyring_info — os keyring passphrase returned in plaintext
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 8, 2026View HOL analysis
  36. CVE-2025-64105Medium
    FOSSBilling: IDOR Vulnerability in Support Ticket Creation
    CVSS 5.1
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 25, 2026View HOL analysis
  37. CVE-2026-12112High
    Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-11807Critical
    Eda-server: websocket missing authorization allows credential theft via activation_id spoofing
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 16, 2026View HOL analysis
  39. CVE-2026-45792Medium
    RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
    CVSS 6.9
    rtk-ai/rtkgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-55736Medium
    Private action arguments can be set by user input in Ash
    CVSS 5.9
    ash-project/ashgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  41. CVE-2020-9695High
    Acrobat Reader | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Acrobat Readergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  42. CVE-2020-9711Medium
    Acrobat Reader | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/Acrobat Readergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  43. CVE-2026-45135High
    Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
    CVSS 8.1
    caddyserver/caddygeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  44. CVE-2026-45692Medium
    Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
    CVSS 5.4
    caddyserver/caddy, github.com/caddyserver/caddy/v2generic · go
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  45. CVE-2020-9713Medium
    Acrobat Reader | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/Acrobat Readergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  46. CVE-2026-0864Medium
    Configuration Injection via Carriage Return (\r) in write() method
    CVSS 4.1
    Python Software Foundation/CPythongeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-44726High
    Deno: TLS retry copies stale upgrade hook, risking plaintext traffic
    CVSS 7.4
    denoland/denogeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026View HOL analysis
  48. CVE-2025-71382Medium
    MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering
    CVSS 6.5
    ArtifexSoftware/mupdfgeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-55255Critical
    Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
    CVSS 9.9 Known exploited
    langflow, langflow-ai/langflowgeneric · pip
    PublishedJun 23, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  50. CVE-2026-34913Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Revive/Adservergeneric
    PublishedJun 23, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
Page 148 of 345
Previous146147148149150Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard