1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 12:50 PM 17,376 active 1,443 known exploited

Catalog summary

17,376

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 12:50 PM 17,376 active 1,443 known exploited

Catalog summary

17,376

Active CVEs

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,901–7,950 of 17,376 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-55743Critical
    OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
    CVSS 9.6
    tinyhumansai/OpenHumangeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  2. CVE-2026-54415High
    Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
    CVSS 8.1
    Azuriom/Azuriom CMSgeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2026-11311High
    NGINX Gateway Fabric vulnerability
    CVSS 8.1
    F5/NGINX Gateway Fabricgeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  4. CVE-2026-48142Medium
    NGINX ngx_http_charset_module vulnerability
    CVSS 4.8
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  5. CVE-2026-42055High
    NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
    CVSS 8.1
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-42530High
    NGINX Open-Source ngx_http_v3_module vulnerability
    CVSS 8.1
    F5/NGINX Open Sourcegeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-55738High
    Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated TAR name field
    CVSS 8.8
    rxi/microtargeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  8. CVE-2026-54417High
    Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS
    CVSS 7.5
    rxi/microtargeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  9. CVE-2026-10641High
    Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)
    CVSS 7.1
    zephyrproject/zephyrgeneric
    PublishedJun 17, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2025-59872Medium
    HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
    CVSS 4.3
    HCL Software/ZIEgeneric
    PublishedJun 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2025-62340Low
    HCL iControl was affected by Inadequate Session Timeout vulnerability
    CVSS 3.1
    HCL Software/iControlgeneric
    PublishedJun 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  12. CVE-2026-27869Medium
    WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDAT
    CVSS 6.9
    Teldat/Regesta Smart HD-PLC - TLDPH16D2generic
    PublishedJun 17, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  13. CVE-2026-27870Medium
    CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC OF TELDAT
    CVSS 4.8
    Teldat/Regesta Smart HD-PLC - TLDPH16D2generic
    PublishedJun 17, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  14. CVE-2026-27868Medium
    PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT
    CVSS 6.9
    Teldat/Regesta Smart HD-PLC - TLDPH16D2generic
    PublishedJun 17, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  15. CVE-2026-36418Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  16. CVE-2026-39199Low
    CISA ADP Vulnrichment
    CVSS 2.9
    Snes9X team/Snes9Xgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2026-48779High
    ws: Memory exhaustion DoS from tiny fragments and data chunks
    CVSS 7.5
    websockets/ws, wsgeneric · npm
    PublishedJun 16, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  18. CVE-2026-0156High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Androidgeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Jul 6, 2026View HOL analysis
  19. CVE-2026-0128Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Androidgeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Jul 6, 2026View HOL analysis
  20. CVE-2026-0126Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Google/Androidgeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Jun 24, 2026View HOL analysis
  21. CVE-2026-12425Medium
    Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10
    CVSS 6.1
    PowerSchool/Employee Access Centergeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  22. CVE-2026-47747High
    stable-diffusion.cpp has a Heap-based Buffer Overflow
    CVSS 7.8
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  23. CVE-2026-47750High
    stable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTorch checkpoint files
    CVSS 7.8
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  24. CVE-2026-47749High
    stable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files
    CVSS 7.8
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  25. CVE-2026-47748Medium
    stable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode parsing
    CVSS 5.5
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  26. CVE-2026-4367Medium
    Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jul 28, 2026View HOL analysis
  27. CVE-2026-47963Medium
    DNG SDK | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  28. CVE-2026-47934Medium
    DNG SDK | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  29. CVE-2026-47964High
    DNG SDK | Heap-based Buffer Overflow (CWE-122)
    CVSS 7.8
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jul 20, 2026View HOL analysis
  30. CVE-2026-47927Medium
    DNG SDK | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  31. CVE-2026-10649High
    Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jul 15, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-12003Medium
    CPython >3.11 Insecure Input Validation resulting in privilege escalation
    CVSS 5.3
    Python Software Foundation/CPythongeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2024-22451Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/Peripheral Managergeneric
    PublishedJun 16, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  34. CVE-2026-10640Medium
    Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)
    CVSS 4.2
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  35. CVE-2026-10639Medium
    Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`
    CVSS 4.8
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-10638Medium
    Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error
    CVSS 5.9
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-10637Medium
    Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query
    CVSS 5.9
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-10636Low
    Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)
    CVSS 3.7
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-12329Medium
    Memory safety bug fixed in Thunderbird ESR 140.12
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-12328High
    Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-12326High
    Memory safety bugs fixed in Firefox 152 and Thunderbird 152
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-12299Medium
    JIT miscompilation in the DOM: Core & HTML component
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-12298Medium
    Memory safety bug fixed in Firefox 152
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-12297Critical
    Sandbox escape due to incorrect boundary conditions in the Networking component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-12296Critical
    Sandbox escape in the Security: Process Sandboxing component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-12295Critical
    Sandbox escape in the DOM: Navigation component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-12294Critical
    Sandbox escape in the DOM: Workers component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-12293Critical
    Use-after-free in the Graphics: WebGPU component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-12292High
    Incorrect boundary conditions in the Web Audio component
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-12291High
    Use-after-free in the Networking: HTTP component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
Page 159 of 348
Previous157158159160161Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,901–7,950 of 17,376 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-55743Critical
    OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
    CVSS 9.6
    tinyhumansai/OpenHumangeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  2. CVE-2026-54415High
    Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
    CVSS 8.1
    Azuriom/Azuriom CMSgeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2026-11311High
    NGINX Gateway Fabric vulnerability
    CVSS 8.1
    F5/NGINX Gateway Fabricgeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  4. CVE-2026-48142Medium
    NGINX ngx_http_charset_module vulnerability
    CVSS 4.8
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  5. CVE-2026-42055High
    NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
    CVSS 8.1
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-42530High
    NGINX Open-Source ngx_http_v3_module vulnerability
    CVSS 8.1
    F5/NGINX Open Sourcegeneric
    PublishedJun 17, 2026First seen at HOL Jul 2, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-55738High
    Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated TAR name field
    CVSS 8.8
    rxi/microtargeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  8. CVE-2026-54417High
    Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS
    CVSS 7.5
    rxi/microtargeneric
    PublishedJun 17, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  9. CVE-2026-10641High
    Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)
    CVSS 7.1
    zephyrproject/zephyrgeneric
    PublishedJun 17, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2025-59872Medium
    HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
    CVSS 4.3
    HCL Software/ZIEgeneric
    PublishedJun 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2025-62340Low
    HCL iControl was affected by Inadequate Session Timeout vulnerability
    CVSS 3.1
    HCL Software/iControlgeneric
    PublishedJun 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  12. CVE-2026-27869Medium
    WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDAT
    CVSS 6.9
    Teldat/Regesta Smart HD-PLC - TLDPH16D2generic
    PublishedJun 17, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  13. CVE-2026-27870Medium
    CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC OF TELDAT
    CVSS 4.8
    Teldat/Regesta Smart HD-PLC - TLDPH16D2generic
    PublishedJun 17, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  14. CVE-2026-27868Medium
    PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT
    CVSS 6.9
    Teldat/Regesta Smart HD-PLC - TLDPH16D2generic
    PublishedJun 17, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  15. CVE-2026-36418Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  16. CVE-2026-39199Low
    CISA ADP Vulnrichment
    CVSS 2.9
    Snes9X team/Snes9Xgeneric
    PublishedJun 17, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2026-48779High
    ws: Memory exhaustion DoS from tiny fragments and data chunks
    CVSS 7.5
    websockets/ws, wsgeneric · npm
    PublishedJun 16, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  18. CVE-2026-0156High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Androidgeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Jul 6, 2026View HOL analysis
  19. CVE-2026-0128Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Androidgeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Jul 6, 2026View HOL analysis
  20. CVE-2026-0126Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Google/Androidgeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Jun 24, 2026View HOL analysis
  21. CVE-2026-12425Medium
    Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10
    CVSS 6.1
    PowerSchool/Employee Access Centergeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  22. CVE-2026-47747High
    stable-diffusion.cpp has a Heap-based Buffer Overflow
    CVSS 7.8
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  23. CVE-2026-47750High
    stable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTorch checkpoint files
    CVSS 7.8
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  24. CVE-2026-47749High
    stable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files
    CVSS 7.8
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  25. CVE-2026-47748Medium
    stable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode parsing
    CVSS 5.5
    leejet/stable-diffusion.cppgeneric
    PublishedJun 16, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  26. CVE-2026-4367Medium
    Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jul 28, 2026View HOL analysis
  27. CVE-2026-47963Medium
    DNG SDK | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  28. CVE-2026-47934Medium
    DNG SDK | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  29. CVE-2026-47964High
    DNG SDK | Heap-based Buffer Overflow (CWE-122)
    CVSS 7.8
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jul 20, 2026View HOL analysis
  30. CVE-2026-47927Medium
    DNG SDK | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  31. CVE-2026-10649High
    Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jul 15, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-12003Medium
    CPython >3.11 Insecure Input Validation resulting in privilege escalation
    CVSS 5.3
    Python Software Foundation/CPythongeneric
    PublishedJun 16, 2026First seen at HOL Jun 22, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2024-22451Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/Peripheral Managergeneric
    PublishedJun 16, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  34. CVE-2026-10640Medium
    Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)
    CVSS 4.2
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  35. CVE-2026-10639Medium
    Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`
    CVSS 4.8
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-10638Medium
    Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error
    CVSS 5.9
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-10637Medium
    Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query
    CVSS 5.9
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-10636Low
    Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)
    CVSS 3.7
    zephyrproject/zephyrgeneric
    PublishedJun 16, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-12329Medium
    Memory safety bug fixed in Thunderbird ESR 140.12
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-12328High
    Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-12326High
    Memory safety bugs fixed in Firefox 152 and Thunderbird 152
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-12299Medium
    JIT miscompilation in the DOM: Core & HTML component
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-12298Medium
    Memory safety bug fixed in Firefox 152
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-12297Critical
    Sandbox escape due to incorrect boundary conditions in the Networking component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-12296Critical
    Sandbox escape in the Security: Process Sandboxing component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-12295Critical
    Sandbox escape in the DOM: Navigation component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-12294Critical
    Sandbox escape in the DOM: Workers component
    CVSS 9.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-12293Critical
    Use-after-free in the Graphics: WebGPU component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-12292High
    Incorrect boundary conditions in the Web Audio component
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-12291High
    Use-after-free in the Networking: HTTP component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
Page 159 of 348
Previous157158159160161Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard