1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 2:15 PM 16,242 active 1,443 known exploited

Catalog summary

16,242

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 2:15 PM 16,242 active 1,443 known exploited

Catalog summary

16,242

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 701–750 of 16,242 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-18992Medium
    zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization
    CVSS 6.3
    zhayujie/CowAgentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-18325High
    Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field
    CVSS 7.2
    wpmudev/Forminator Forms – Contact Form, Payment Form & Custom Form Buildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-15991High
    File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter
    CVSS 8.8
    bitpressadmin/File Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-16636High
    FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs
    CVSS 7.2
    wpmanageninja/FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-18991High
    nanocoai NanoClaw send_file core.ts path traversal
    CVSS 7.3
    nanocoai/NanoClawgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-18990High
    letta-ai LettaBot API Status Route server.ts missing authentication
    CVSS 7.3
    letta-ai/LettaBotgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-18980Medium
    nearai ironclaw shell.rs classify_command_risk command injection
    CVSS 6.3
    nearai/ironclawgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-18976Medium
    NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment
    CVSS 6.3
    NousResearch/hermes-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-18974Medium
    heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure
    CVSS 5.3
    heshengtao/super-agent-partygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-18973High
    heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery
    CVSS 7.3
    heshengtao/super-agent-partygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2024-39024High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-67687High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  13. CVE-2026-67688Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-67689Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-18970High
    Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection
    CVSS 7.3
    Rongzhitong/Visual Integrated Command and Dispatch Platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-18969High
    Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload
    CVSS 7.3
    Rongzhitong/Visual Integrated Command and Dispatch Platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-19028Medium
    HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read
    CVSS 6.8
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-19027Medium
    HDF5 out-of-bounds heap read in N-Bit filter decompression
    CVSS 6.9
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-18968Medium
    ttttonyhe OBlog tags.php cross site scripting
    CVSS 4.3
    ttttonyhe/OBloggeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-67531Critical
    FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool
    CVSS 9.3
    agentfront/frontmcpgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-19026Medium
    Nbit filter NULL/short parameter-array dereference
    CVSS 6.8
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-19025Medium
    HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open
    CVSS 6.8
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-19024High
    HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
    CVSS 8.2
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-19023Medium
    HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets
    CVSS 0.0
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-71321High
    Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
    CVSS 7.5
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-71320High
    Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
    CVSS 8.1
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-71319Critical
    Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution
    CVSS 9.6
    @nuxt/devtools, nuxt/devtoolsgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-71318Medium
    Nuxt: Unauthorized Component Instantiation via Server Island Props
    CVSS 4.8
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  29. CVE-2026-71316High
    Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
    CVSS 7.5
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-71315High
    Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
    CVSS 8.2
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2026-71314High
    Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
    CVSS 7.5
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-71313Medium
    rclone: Local Encoding Path Traversal
    CVSS 6.9
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-18839Low
    Popt-devel: popt-static: size_t underflow in singleoptionhelp
    CVSS 2.2
    rpm-software-management/poptgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-71312High
    rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
    CVSS 8.0
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-71311Medium
    rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
    CVSS 6.4
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-34966High
    Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass
    CVSS 7.6
    Gitea/Giteageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-17583High
    Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
    CVSS 8.4
    Thermo Fisher/ABI PRISM 310 Data Collection Software, Thermo Fisher/ABI PRISM 3100/3100-Avant Data Collection Software +6generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-71310Medium
    rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
    CVSS 5.9
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  39. CVE-2026-18959Medium
    yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal
    CVSS 5.4
    yushine/InnoShopgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-71309High
    rclone: Incomplete path validation allows backend root escape in serve restic
    CVSS 8.6
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-18411High
    Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100
    CVSS 8.1
    Acrisure/DR-100, Acrisure/KARR BTgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-15996Medium
    Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
    CVSS 6.6
    GitHub/Enterprise Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-21766Medium
    HCL Digital Experience and Digital Experience Compose insufficiently protects credentials
    CVSS 5.4
    HCLSoftware/HCL Digital Experience and Digital Experience Composegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-18954Medium
    Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
    CVSS 5.5
    AWS/documentdb-mcp-servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-17556High
    Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
    CVSS 8.8
    GitHub/Enterprise Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-18958High
    imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection
    CVSS 7.3
    imranrisal-dev/Student-Management-Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-55524High
    PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
    CVSS 7.5
    MervinPraison/PraisonAIgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-70618Medium
    Spacebar Server Missing Authorization via member-ids Endpoint
    CVSS 4.3
    Spacebar Server/Spacebar Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-70617High
    Spacebar Server Missing Authorization via Group DM Recipient Endpoint
    CVSS 8.1
    Spacebar Server/Spacebar Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-66885Medium
    Livebook Teams identity callback lacks state binding, allowing login CSRF
    CVSS 6.8
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
Page 15 of 325
Previous1314151617Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 701–750 of 16,242 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-18992Medium
    zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization
    CVSS 6.3
    zhayujie/CowAgentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-18325High
    Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field
    CVSS 7.2
    wpmudev/Forminator Forms – Contact Form, Payment Form & Custom Form Buildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-15991High
    File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter
    CVSS 8.8
    bitpressadmin/File Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-16636High
    FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs
    CVSS 7.2
    wpmanageninja/FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-18991High
    nanocoai NanoClaw send_file core.ts path traversal
    CVSS 7.3
    nanocoai/NanoClawgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-18990High
    letta-ai LettaBot API Status Route server.ts missing authentication
    CVSS 7.3
    letta-ai/LettaBotgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-18980Medium
    nearai ironclaw shell.rs classify_command_risk command injection
    CVSS 6.3
    nearai/ironclawgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-18976Medium
    NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment
    CVSS 6.3
    NousResearch/hermes-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-18974Medium
    heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure
    CVSS 5.3
    heshengtao/super-agent-partygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-18973High
    heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery
    CVSS 7.3
    heshengtao/super-agent-partygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2024-39024High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-67687High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  13. CVE-2026-67688Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-67689Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-18970High
    Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection
    CVSS 7.3
    Rongzhitong/Visual Integrated Command and Dispatch Platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-18969High
    Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload
    CVSS 7.3
    Rongzhitong/Visual Integrated Command and Dispatch Platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-19028Medium
    HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read
    CVSS 6.8
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-19027Medium
    HDF5 out-of-bounds heap read in N-Bit filter decompression
    CVSS 6.9
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-18968Medium
    ttttonyhe OBlog tags.php cross site scripting
    CVSS 4.3
    ttttonyhe/OBloggeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-67531Critical
    FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool
    CVSS 9.3
    agentfront/frontmcpgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-19026Medium
    Nbit filter NULL/short parameter-array dereference
    CVSS 6.8
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-19025Medium
    HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open
    CVSS 6.8
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-19024High
    HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
    CVSS 8.2
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-19023Medium
    HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets
    CVSS 0.0
    The HDF Group/HDF5generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-71321High
    Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
    CVSS 7.5
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-71320High
    Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
    CVSS 8.1
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-71319Critical
    Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution
    CVSS 9.6
    @nuxt/devtools, nuxt/devtoolsgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-71318Medium
    Nuxt: Unauthorized Component Instantiation via Server Island Props
    CVSS 4.8
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  29. CVE-2026-71316High
    Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
    CVSS 7.5
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-71315High
    Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
    CVSS 8.2
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2026-71314High
    Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
    CVSS 7.5
    nuxt, nuxt/nuxtgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-71313Medium
    rclone: Local Encoding Path Traversal
    CVSS 6.9
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-18839Low
    Popt-devel: popt-static: size_t underflow in singleoptionhelp
    CVSS 2.2
    rpm-software-management/poptgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-71312High
    rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
    CVSS 8.0
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-71311Medium
    rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
    CVSS 6.4
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-34966High
    Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass
    CVSS 7.6
    Gitea/Giteageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-17583High
    Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
    CVSS 8.4
    Thermo Fisher/ABI PRISM 310 Data Collection Software, Thermo Fisher/ABI PRISM 3100/3100-Avant Data Collection Software +6generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-71310Medium
    rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
    CVSS 5.9
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  39. CVE-2026-18959Medium
    yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal
    CVSS 5.4
    yushine/InnoShopgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-71309High
    rclone: Incomplete path validation allows backend root escape in serve restic
    CVSS 8.6
    github.com/rclone/rclone, rclone/rclonegeneric · go
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-18411High
    Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100
    CVSS 8.1
    Acrisure/DR-100, Acrisure/KARR BTgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-15996Medium
    Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
    CVSS 6.6
    GitHub/Enterprise Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-21766Medium
    HCL Digital Experience and Digital Experience Compose insufficiently protects credentials
    CVSS 5.4
    HCLSoftware/HCL Digital Experience and Digital Experience Composegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-18954Medium
    Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
    CVSS 5.5
    AWS/documentdb-mcp-servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-17556High
    Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
    CVSS 8.8
    GitHub/Enterprise Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-18958High
    imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection
    CVSS 7.3
    imranrisal-dev/Student-Management-Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-55524High
    PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
    CVSS 7.5
    MervinPraison/PraisonAIgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-70618Medium
    Spacebar Server Missing Authorization via member-ids Endpoint
    CVSS 4.3
    Spacebar Server/Spacebar Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-70617High
    Spacebar Server Missing Authorization via Group DM Recipient Endpoint
    CVSS 8.1
    Spacebar Server/Spacebar Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-66885Medium
    Livebook Teams identity callback lacks state binding, allowing login CSRF
    CVSS 6.8
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
Page 15 of 325
Previous1314151617Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard