1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 11:10 AM 17,243 active 1,443 known exploited

Catalog summary

17,243

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 11:10 AM 17,243 active 1,443 known exploited

Catalog summary

17,243

Active CVEs

8,703

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,751–7,800 of 17,243 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-42490Medium
    domctl lock open to abuse
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-42489Medium
    domctl lock open to abuse
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-42487High
    x86 HVM I/O port list traversal
    CVSS 7.9
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  4. CVE-2026-11958High
    Local privilege escalation in ANSSI’s DFIR-ORC
    CVSS 7.3
    ANSSI/DFIR-ORCgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  5. CVE-2026-40457Low
    Reflected XSS in LMS
    CVSS 2.1
    LMS/LMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  6. CVE-2026-40456High
    OS Command Injection in LMS
    CVSS 8.6
    LMS/LMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  7. CVE-2026-40455High
    SQL Injection in LMS
    CVSS 8.6
    LMS/LMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  8. CVE-2026-54419Critical
    PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query
    CVSS 9.8
    claudiopizzillo/PIAF-HMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  9. CVE-2026-44942Medium
    libzypp .repo files can have an optional path which can lead to path traversal attacks
    CVSS 6.5
    SUSE/libzyppgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  10. CVE-2025-10560Critical
    Hardcoded cloud credentials in Worksnaps client application binaries expose production cloud resources
    CVSS 9.3
    Silver Leaf Technologies, Inc./Worksnaps.net Worksnapsgeneric
    PublishedJun 18, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  11. CVE-2026-55746High
    Cotonti stored XSS via PFS folder title
    CVSS 7.6
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  12. CVE-2026-28573Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Google/Androidgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  13. CVE-2026-55745Medium
    Cotonti CSRF in PFS folder edit allows unauthorized folder modification
    CVSS 5.4
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  14. CVE-2026-55744High
    Cotonti CSRF in PFS allows forced arbitrary file upload
    CVSS 8.1
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  15. CVE-2026-55742Critical
    Cotonti CSRF in admin.rights.php allows privilege escalation
    CVSS 9.6
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  16. CVE-2026-55741High
    Cotonti CSRF in admin.config.php allows unauthorized configuration changes
    CVSS 8.8
    Cotonti/Cotontigeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2026-55740Critical
    SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter
    CVSS 9.8
    Nur-Alam39/bus-ticketgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  18. CVE-2026-12505High
    Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 29, 2026View HOL analysis
  19. CVE-2026-12569Critical
    Remote Code Execution (RCE) vulnerability in Windchill PDMlink
    CVSS 9.8 Known exploited
    PTC/FlexPLM, PTC/Windchill PDMLinkgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 1, 2026View HOL analysis
  20. CVE-2026-38714Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  21. CVE-2026-38715Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  22. CVE-2026-38716Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2026-38717Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2026-38718High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-32682Medium
    NGINX Gateway Fabric vulnerability
    CVSS 6.5
    F5/NGINX Gateway Fabricgeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  26. CVE-2026-10741Medium
    Nexus Repository Manager - Incorrect Authorization allows credential disclosure via proxy repository configuration
    CVSS 5.9
    Sonatype/Nexus Repository Managergeneric
    PublishedJun 17, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  27. CVE-2026-10696High
    CISA ADP Vulnrichment
    CVSS 7.5
    Devolutions/UniGetUIgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 24, 2026View HOL analysis
  28. CVE-2026-48818High
    Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
    CVSS 7.5
    Kludex/starlette, starlettegeneric · pip
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  29. CVE-2026-2674High
    Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers.
    CVSS 8.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-30803Critical
    Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.
    CVSS 9.1
    RTI/Connext Microgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-30802High
    Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.
    CVSS 8.8
    RTI/Connext Microgeneric
    PublishedJun 17, 2026First seen at HOL Jun 25, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-30799High
    Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.
    CVSS 8.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-3894Critical
    Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
    CVSS 9.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  34. CVE-2026-2675Medium
    Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.
    CVSS 6.5
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-2467High
    Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.
    CVSS 8.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-20266Critical
    OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit
    CVSS 9.1
    Splunk/Splunk AI Toolkitgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  37. CVE-2026-20265Medium
    Insecure Default Domain Allowlist in Splunk AI Toolkit
    CVSS 4.3
    Splunk/Splunk AI Toolkitgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  38. CVE-2026-47774High
    Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 17, 2026First seen at HOL Jun 23, 2026Updated Jul 20, 2026View HOL analysis
  39. CVE-2026-9697High
    undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
    CVSS 7.4
    undici, undici/undicigeneric · npm
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  40. CVE-2026-20178Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Cisco/Cisco Webex Appgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  41. CVE-2026-20246Medium
    Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
    CVSS 6.0
    Cisco/Cisco Umbrella Insights Virtual Appliancegeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  42. CVE-2026-20220Medium
    Cisco Crosswork Network Controller Remote Code Execution Vulnerability
    CVSS 6.3
    Cisco/Cisco Crosswork Network Change Automationgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  43. CVE-2026-20190High
    Cisco Identity Services Engine Information Disclosure Vulnerability
    CVSS 7.5
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  44. CVE-2026-20181Critical
    Cisco Identity Services Engine Remote Code Execution Vulnerability
    CVSS 9.1
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2026-12151High
    undici WebSocket client vulnerable to denial of service via fragment count bypass
    CVSS 7.5
    undici, undici/undicigeneric · npm
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-12515Medium
    Katello: missing repository authorization in content_uploads exposes cross-product content existence
    CVSS 4.3
    katellorubygems
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-32652High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/AIOpsgeneric
    PublishedJun 17, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  48. CVE-2026-1288Medium
    RFA File Parsing Vulnerability in Autodesk Revit
    CVSS 5.5
    Autodesk/Revitgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  49. CVE-2025-32748Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Dell/PowerFlex rackgeneric
    PublishedJun 17, 2026First seen at HOL Jun 25, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-35069Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    Dell/PowerFlexgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
Page 156 of 345
Previous154155156157158Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,703

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,751–7,800 of 17,243 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-42490Medium
    domctl lock open to abuse
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-42489Medium
    domctl lock open to abuse
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-42487High
    x86 HVM I/O port list traversal
    CVSS 7.9
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  4. CVE-2026-11958High
    Local privilege escalation in ANSSI’s DFIR-ORC
    CVSS 7.3
    ANSSI/DFIR-ORCgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  5. CVE-2026-40457Low
    Reflected XSS in LMS
    CVSS 2.1
    LMS/LMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  6. CVE-2026-40456High
    OS Command Injection in LMS
    CVSS 8.6
    LMS/LMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  7. CVE-2026-40455High
    SQL Injection in LMS
    CVSS 8.6
    LMS/LMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  8. CVE-2026-54419Critical
    PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query
    CVSS 9.8
    claudiopizzillo/PIAF-HMSgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  9. CVE-2026-44942Medium
    libzypp .repo files can have an optional path which can lead to path traversal attacks
    CVSS 6.5
    SUSE/libzyppgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  10. CVE-2025-10560Critical
    Hardcoded cloud credentials in Worksnaps client application binaries expose production cloud resources
    CVSS 9.3
    Silver Leaf Technologies, Inc./Worksnaps.net Worksnapsgeneric
    PublishedJun 18, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  11. CVE-2026-55746High
    Cotonti stored XSS via PFS folder title
    CVSS 7.6
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  12. CVE-2026-28573Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Google/Androidgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  13. CVE-2026-55745Medium
    Cotonti CSRF in PFS folder edit allows unauthorized folder modification
    CVSS 5.4
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  14. CVE-2026-55744High
    Cotonti CSRF in PFS allows forced arbitrary file upload
    CVSS 8.1
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  15. CVE-2026-55742Critical
    Cotonti CSRF in admin.rights.php allows privilege escalation
    CVSS 9.6
    Cotonti/Cotonti, cotonti/cotonticomposer · generic
    PublishedJun 18, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026View HOL analysis
  16. CVE-2026-55741High
    Cotonti CSRF in admin.config.php allows unauthorized configuration changes
    CVSS 8.8
    Cotonti/Cotontigeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2026-55740Critical
    SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter
    CVSS 9.8
    Nur-Alam39/bus-ticketgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  18. CVE-2026-12505High
    Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 29, 2026View HOL analysis
  19. CVE-2026-12569Critical
    Remote Code Execution (RCE) vulnerability in Windchill PDMlink
    CVSS 9.8 Known exploited
    PTC/FlexPLM, PTC/Windchill PDMLinkgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Aug 1, 2026View HOL analysis
  20. CVE-2026-38714Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  21. CVE-2026-38715Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  22. CVE-2026-38716Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2026-38717Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2026-38718High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-32682Medium
    NGINX Gateway Fabric vulnerability
    CVSS 6.5
    F5/NGINX Gateway Fabricgeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  26. CVE-2026-10741Medium
    Nexus Repository Manager - Incorrect Authorization allows credential disclosure via proxy repository configuration
    CVSS 5.9
    Sonatype/Nexus Repository Managergeneric
    PublishedJun 17, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  27. CVE-2026-10696High
    CISA ADP Vulnrichment
    CVSS 7.5
    Devolutions/UniGetUIgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 24, 2026View HOL analysis
  28. CVE-2026-48818High
    Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
    CVSS 7.5
    Kludex/starlette, starlettegeneric · pip
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  29. CVE-2026-2674High
    Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers.
    CVSS 8.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-30803Critical
    Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.
    CVSS 9.1
    RTI/Connext Microgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-30802High
    Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.
    CVSS 8.8
    RTI/Connext Microgeneric
    PublishedJun 17, 2026First seen at HOL Jun 25, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-30799High
    Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.
    CVSS 8.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-3894Critical
    Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
    CVSS 9.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  34. CVE-2026-2675Medium
    Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.
    CVSS 6.5
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-2467High
    Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.
    CVSS 8.1
    RTI/Connext Professionalgeneric
    PublishedJun 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-20266Critical
    OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit
    CVSS 9.1
    Splunk/Splunk AI Toolkitgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  37. CVE-2026-20265Medium
    Insecure Default Domain Allowlist in Splunk AI Toolkit
    CVSS 4.3
    Splunk/Splunk AI Toolkitgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  38. CVE-2026-47774High
    Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedJun 17, 2026First seen at HOL Jun 23, 2026Updated Jul 20, 2026View HOL analysis
  39. CVE-2026-9697High
    undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
    CVSS 7.4
    undici, undici/undicigeneric · npm
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  40. CVE-2026-20178Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Cisco/Cisco Webex Appgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  41. CVE-2026-20246Medium
    Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
    CVSS 6.0
    Cisco/Cisco Umbrella Insights Virtual Appliancegeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  42. CVE-2026-20220Medium
    Cisco Crosswork Network Controller Remote Code Execution Vulnerability
    CVSS 6.3
    Cisco/Cisco Crosswork Network Change Automationgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  43. CVE-2026-20190High
    Cisco Identity Services Engine Information Disclosure Vulnerability
    CVSS 7.5
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  44. CVE-2026-20181Critical
    Cisco Identity Services Engine Remote Code Execution Vulnerability
    CVSS 9.1
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2026-12151High
    undici WebSocket client vulnerable to denial of service via fragment count bypass
    CVSS 7.5
    undici, undici/undicigeneric · npm
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-12515Medium
    Katello: missing repository authorization in content_uploads exposes cross-product content existence
    CVSS 4.3
    katellorubygems
    PublishedJun 17, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-32652High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/AIOpsgeneric
    PublishedJun 17, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  48. CVE-2026-1288Medium
    RFA File Parsing Vulnerability in Autodesk Revit
    CVSS 5.5
    Autodesk/Revitgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  49. CVE-2025-32748Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Dell/PowerFlex rackgeneric
    PublishedJun 17, 2026First seen at HOL Jun 25, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-35069Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    Dell/PowerFlexgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
Page 156 of 345
Previous154155156157158Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard