1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:25 AM 17,239 active 1,443 known exploited

Catalog summary

17,239

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:25 AM 17,239 active 1,443 known exploited

Catalog summary

17,239

Active CVEs

8,700

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,501–7,550 of 17,239 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-41048High
    Caching of Authentication allows Authentication Bypass in qSnapper
    CVSS 8.4
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-11943Medium
    Akaunting 3.1.21 - Authenticated stored XSS in document timeline
    CVSS 4.8
    Akaunting/Akauntinggeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-41047Medium
    Information leak via “diff” methods in qSnapper
    CVSS 6.9
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-12479Medium
    Path Traversal in keras-team/keras
    CVSS 6.1
    keras, keras-team/keras-team/kerasgeneric · pip · pypi
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  5. CVE-2026-41046High
    path traversal via `config` parameter in qSnapper
    CVSS 7.3
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 28, 2026 Fix availableView HOL analysis
  6. CVE-2026-11942Medium
    Akaunting 3.1.21 - Stored XSS in delete confirmation modal
    CVSS 4.8
    Akaunting/Akauntinggeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  7. CVE-2026-41045High
    Weak polkit authentication check in qSnapper
    CVSS 8.1
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 28, 2026 Fix availableView HOL analysis
  8. CVE-2026-10845High
    IBM WebSphere Application Server is affected by an authentication bypass vulnerability
    CVSS 7.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  9. CVE-2024-51454Medium
    IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed
    CVSS 6.5
    IBM/Engineering Workflow Managementgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2023-33854Medium
    Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
    CVSS 5.3
    IBM/Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  11. CVE-2026-9072High
    WebSphere Application Server Remote Code Execution
    CVSS 8.1
    IBM/WebSphere Application Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-8858High
    WebSphere Application Server Remote Code Execution
    CVSS 7.5
    IBM/WebSphere Application Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-11372Medium
    IBM TRIRIGA Cross-Site Scripting Vulnerability
    CVSS 5.4
    IBM/TRIRIGA Application Platformgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  14. CVE-2026-12549Medium
    Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
    CVSS 4.8
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026View HOL analysis
  15. CVE-2026-12725Medium
    Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026View HOL analysis
  16. CVE-2026-12628Critical
    Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system
    CVSS 9.1
    IBM/Storage Protect Client, IBM/Storage Protect Snapshot For Windowsgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  17. CVE-2026-10561Critical
    Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
    CVSS 10.0
    IBM/Langflow OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  18. CVE-2026-28381Critical
    Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT
    CVSS 9.6
    Grafana/Snowflake Datasourcegeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  19. CVE-2025-33128Medium
    IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed
    CVSS 5.4
    IBM/Engineering Workflow Managementgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  20. CVE-2025-2669Medium
    Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
    CVSS 6.0
    IBM/Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  21. CVE-2026-9029High
    Stored XSS in the Geomap panel tile-layer attribution
    CVSS 7.3
    Grafana/Grafana OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026View HOL analysis
  22. CVE-2026-10601Medium
    Path traversal in the Tempo and Loki data source plugins
    CVSS 5.4
    Grafana/Grafana OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026View HOL analysis
  23. CVE-2026-42129High
    Path traversal in the Loki data source plugin
    CVSS 7.7
    Grafana/Grafana OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026View HOL analysis
  24. CVE-2024-54178Medium
    Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
    CVSS 6.5
    IBM/Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  25. CVE-2026-12888Low
    HTML injection in the Canarytoken Google Chat notification
    CVSS 2.0
    Thinkst Applied Research/Canarytokensgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  26. CVE-2026-12602High
    Incorrect permissions in ArubaSign by Aruba
    CVSS 8.8
    Aruba/ArubaSigngeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  27. CVE-2026-11373Critical
    Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
    CVSS 9.1
    JASEI/Net::Statsite::Clientgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  28. CVE-2026-12581High
    Digiwin|EasyFlow .NET - Session Fixation
    CVSS 7.5
    Digiwin/EasyFlow .NETgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  29. CVE-2026-12580Medium
    Digiwin|EasyFlow .NET - Stored Cross-Site Scripting
    CVSS 5.4
    Digiwin/EasyFlow .NETgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  30. CVE-2023-45795High
    Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx
    CVSS 7.8
    Pilz/PASvisu, Pilz/PMI v8xxgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  31. CVE-2023-45796High
    XSS vulnerability in Pilz PASvisu and PMI v8xx
    CVSS 8.1
    Pilz/PASvisu, Pilz/PMI v8xxgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  32. CVE-2026-12863Medium
    Open redirect
    CVSS 5.1
    pretix/Venuelessgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  33. CVE-2026-12862Medium
    XLSX formula injection in exports
    CVSS 5.1
    pretix/Venuelessgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  34. CVE-2025-4994High
    Authentication Bypass for SafeLine SL6 and SL6+
    CVSS 8.7
    SafeLine/SafeLine SL6/SL6+generic
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  35. CVE-2025-62198Medium
    Apache Atlas: Stored XSS in Create Entity page
    CVSS 5.4
    Apache Software Foundation/Apache Atlasgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  36. CVE-2026-44914High
    Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents
    CVSS 7.5
    Apache Software Foundation/Apache NiFigeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 24, 2026View HOL analysis
  37. CVE-2026-44911Medium
    Apache NiFi: Incorrect Authorization for Configuration Verification Requests
    CVSS 6.3
    Apache Software Foundation/Apache NiFigeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  38. CVE-2026-44913High
    Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
    CVSS 7.2
    Apache Software Foundation/Apache NiFigeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  39. CVE-2025-66336High
    Apache Doris MCP Server: SQL injection leading the authentication bypass
    CVSS 8.1
    Apache Software Foundation/Apache Doris MCP Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  40. CVE-2026-4259High
    Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
    CVSS 7.1
    Unknown/ultimate-woocommerce-auction-progeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  41. CVE-2026-4110Medium
    Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
    CVSS 6.1
    Unknown/ultimate-woocommerce-auction-progeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  42. CVE-2026-10530Medium
    Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
    CVSS 5.3
    Unknown/Pie Registergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  43. CVE-2026-11748Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  44. CVE-2026-11746Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2026-11745High
    CISA ADP Vulnrichment
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  46. CVE-2025-66389High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  47. CVE-2026-12823Low
    Browserbase Skills Autobrowse Trace Artifact default permission
    CVSS 3.3
    Browserbase/Skillsgeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jul 3, 2026View HOL analysis
  48. CVE-2026-12822Medium
    langflow-ai langflow Bundle URL Loader code injection
    CVSS 5.3
    langflow-ai/langflowgeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  49. CVE-2026-12821Medium
    FlowiseAI Flowise S3 Document Loader S3.ts path traversal
    CVSS 6.3
    FlowiseAI/Flowisegeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  50. CVE-2026-12815Medium
    coollabsio coolify Image Name os command injection
    CVSS 6.3
    coollabsio/coolifygeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
Page 151 of 345
Previous149150151152153Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,700

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,501–7,550 of 17,239 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-41048High
    Caching of Authentication allows Authentication Bypass in qSnapper
    CVSS 8.4
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-11943Medium
    Akaunting 3.1.21 - Authenticated stored XSS in document timeline
    CVSS 4.8
    Akaunting/Akauntinggeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-41047Medium
    Information leak via “diff” methods in qSnapper
    CVSS 6.9
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-12479Medium
    Path Traversal in keras-team/keras
    CVSS 6.1
    keras, keras-team/keras-team/kerasgeneric · pip · pypi
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  5. CVE-2026-41046High
    path traversal via `config` parameter in qSnapper
    CVSS 7.3
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 28, 2026 Fix availableView HOL analysis
  6. CVE-2026-11942Medium
    Akaunting 3.1.21 - Stored XSS in delete confirmation modal
    CVSS 4.8
    Akaunting/Akauntinggeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  7. CVE-2026-41045High
    Weak polkit authentication check in qSnapper
    CVSS 8.1
    presire/qSnappergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 28, 2026 Fix availableView HOL analysis
  8. CVE-2026-10845High
    IBM WebSphere Application Server is affected by an authentication bypass vulnerability
    CVSS 7.3
    IBM/WebSphere Application Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  9. CVE-2024-51454Medium
    IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed
    CVSS 6.5
    IBM/Engineering Workflow Managementgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2023-33854Medium
    Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
    CVSS 5.3
    IBM/Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  11. CVE-2026-9072High
    WebSphere Application Server Remote Code Execution
    CVSS 8.1
    IBM/WebSphere Application Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-8858High
    WebSphere Application Server Remote Code Execution
    CVSS 7.5
    IBM/WebSphere Application Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-11372Medium
    IBM TRIRIGA Cross-Site Scripting Vulnerability
    CVSS 5.4
    IBM/TRIRIGA Application Platformgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  14. CVE-2026-12549Medium
    Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
    CVSS 4.8
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026View HOL analysis
  15. CVE-2026-12725Medium
    Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026View HOL analysis
  16. CVE-2026-12628Critical
    Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system
    CVSS 9.1
    IBM/Storage Protect Client, IBM/Storage Protect Snapshot For Windowsgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  17. CVE-2026-10561Critical
    Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
    CVSS 10.0
    IBM/Langflow OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  18. CVE-2026-28381Critical
    Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT
    CVSS 9.6
    Grafana/Snowflake Datasourcegeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  19. CVE-2025-33128Medium
    IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed
    CVSS 5.4
    IBM/Engineering Workflow Managementgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  20. CVE-2025-2669Medium
    Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
    CVSS 6.0
    IBM/Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  21. CVE-2026-9029High
    Stored XSS in the Geomap panel tile-layer attribution
    CVSS 7.3
    Grafana/Grafana OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026View HOL analysis
  22. CVE-2026-10601Medium
    Path traversal in the Tempo and Loki data source plugins
    CVSS 5.4
    Grafana/Grafana OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026View HOL analysis
  23. CVE-2026-42129High
    Path traversal in the Loki data source plugin
    CVSS 7.7
    Grafana/Grafana OSSgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026View HOL analysis
  24. CVE-2024-54178Medium
    Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
    CVSS 6.5
    IBM/Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  25. CVE-2026-12888Low
    HTML injection in the Canarytoken Google Chat notification
    CVSS 2.0
    Thinkst Applied Research/Canarytokensgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  26. CVE-2026-12602High
    Incorrect permissions in ArubaSign by Aruba
    CVSS 8.8
    Aruba/ArubaSigngeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  27. CVE-2026-11373Critical
    Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
    CVSS 9.1
    JASEI/Net::Statsite::Clientgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  28. CVE-2026-12581High
    Digiwin|EasyFlow .NET - Session Fixation
    CVSS 7.5
    Digiwin/EasyFlow .NETgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  29. CVE-2026-12580Medium
    Digiwin|EasyFlow .NET - Stored Cross-Site Scripting
    CVSS 5.4
    Digiwin/EasyFlow .NETgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  30. CVE-2023-45795High
    Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx
    CVSS 7.8
    Pilz/PASvisu, Pilz/PMI v8xxgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  31. CVE-2023-45796High
    XSS vulnerability in Pilz PASvisu and PMI v8xx
    CVSS 8.1
    Pilz/PASvisu, Pilz/PMI v8xxgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  32. CVE-2026-12863Medium
    Open redirect
    CVSS 5.1
    pretix/Venuelessgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  33. CVE-2026-12862Medium
    XLSX formula injection in exports
    CVSS 5.1
    pretix/Venuelessgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  34. CVE-2025-4994High
    Authentication Bypass for SafeLine SL6 and SL6+
    CVSS 8.7
    SafeLine/SafeLine SL6/SL6+generic
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  35. CVE-2025-62198Medium
    Apache Atlas: Stored XSS in Create Entity page
    CVSS 5.4
    Apache Software Foundation/Apache Atlasgeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  36. CVE-2026-44914High
    Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents
    CVSS 7.5
    Apache Software Foundation/Apache NiFigeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 24, 2026View HOL analysis
  37. CVE-2026-44911Medium
    Apache NiFi: Incorrect Authorization for Configuration Verification Requests
    CVSS 6.3
    Apache Software Foundation/Apache NiFigeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  38. CVE-2026-44913High
    Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
    CVSS 7.2
    Apache Software Foundation/Apache NiFigeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  39. CVE-2025-66336High
    Apache Doris MCP Server: SQL injection leading the authentication bypass
    CVSS 8.1
    Apache Software Foundation/Apache Doris MCP Servergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  40. CVE-2026-4259High
    Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
    CVSS 7.1
    Unknown/ultimate-woocommerce-auction-progeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  41. CVE-2026-4110Medium
    Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
    CVSS 6.1
    Unknown/ultimate-woocommerce-auction-progeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  42. CVE-2026-10530Medium
    Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
    CVSS 5.3
    Unknown/Pie Registergeneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  43. CVE-2026-11748Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  44. CVE-2026-11746Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2026-11745High
    CISA ADP Vulnrichment
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  46. CVE-2025-66389High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 22, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  47. CVE-2026-12823Low
    Browserbase Skills Autobrowse Trace Artifact default permission
    CVSS 3.3
    Browserbase/Skillsgeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jul 3, 2026View HOL analysis
  48. CVE-2026-12822Medium
    langflow-ai langflow Bundle URL Loader code injection
    CVSS 5.3
    langflow-ai/langflowgeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  49. CVE-2026-12821Medium
    FlowiseAI Flowise S3 Document Loader S3.ts path traversal
    CVSS 6.3
    FlowiseAI/Flowisegeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  50. CVE-2026-12815Medium
    coollabsio coolify Image Name os command injection
    CVSS 6.3
    coollabsio/coolifygeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
Page 151 of 345
Previous149150151152153Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard