1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 3:05 PM 16,243 active 1,443 known exploited

Catalog summary

16,243

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 3:05 PM 16,243 active 1,443 known exploited

Catalog summary

16,243

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 751–800 of 16,243 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-66298High
    JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
    CVSS 8.6
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  2. CVE-2026-66297Medium
    Unescaped deployment environment variables in generated setup commands
    CVSS 4.9
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  3. CVE-2026-66881High
    Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
    CVSS 7.0
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  4. CVE-2026-68746High
    Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
    CVSS 7.7
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-70616Medium
    boringproxy 0.10.0 Resource Exhaustion DoS via GET /loading endpoint
    CVSS 6.5
    boringproxy/boringproxygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-70615Critical
    boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation
    CVSS 9.9
    boringproxy/boringproxygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-18953High
    Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
    CVSS 8.6
    AWS/aws-transform-mcp-servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-55523High
    PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets
    CVSS 7.7
    MervinPraison/PraisonAIgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-69111High
    Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
    CVSS 7.5
    milvus-io/milvusgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-55522High
    PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
    CVSS 7.8
    MervinPraison/PraisonAI, MervinPraison/praisonaiagentsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-18485High
    Local Privilege Escalation in NI-PAL
    CVSS 7.8
    NI/NI-PALgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-17624High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-17633High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-17632High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-48168Critical
    PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name
    CVSS 10.0
    MervinPraison/PraisonAIgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-9196High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-8182High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-9201High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-8478High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-8183High
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 7.7
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-7658Medium
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-9130High
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 7.1
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-10547Medium
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 5.9
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-7869Medium
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 5.4
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-8470High
    Langflow is affected by weaknesses in secret handling and sensitive configuration access
    CVSS 7.4
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-63457Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Hewlett Packard Enterprise (HPE)/HPE Integrated Lights-Out 6 (iLO 6)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2026-9205High
    Langflow is affected by weaknesses in secret handling and sensitive configuration access
    CVSS 7.4
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-70612Medium
    Electron: Sandboxed iframes can launch external protocol handlers
    CVSS 5.4
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-70611Medium
    Electron: DevTools embedder handler executes arbitrary files via shell open
    CVSS 6.9
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-10128Medium
    Langflow is affected by weaknesses in secret handling and sensitive configuration access
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-70610Medium
    Electron: contextBridge object copy honors prototype setters
    CVSS 5.4
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-70448High
    CISA ADP Vulnrichment
    CVSS 7.1
    Jenkins Project/Jenkins Ivy Report Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-70447Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins AWS CodeBuild Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-70446Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins CodeSonar Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-70445Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Sauce OnDemand Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-70444Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Violation Comments to GitLab Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-70443Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Horreum Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-70442Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Google Chat Notification Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-70441Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Jenkins Project/Jenkins Summary Display Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-70440Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Jenkins Project/Jenkins Qualys Container Scanning Connector Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  41. CVE-2026-70439Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Jenkins Project/Jenkins XML Job to Job DSL Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-70438Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Parameterized Remote Trigger Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-70437Low
    CISA ADP Vulnrichment
    CVSS 3.7
    Jenkins Project/Jenkins Webhook Secret Credentials Provider Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-70436Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins External Workspace Manager Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-70435Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Jenkins Project/Jenkins SCM-Manager Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-70434Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Jenkins Project/Jenkins SCM-Manager Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-70433Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins HCL AppScan Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-70432High
    CISA ADP Vulnrichment
    CVSS 8.8
    Jenkins Project/Jenkins Multijob Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-70431High
    CISA ADP Vulnrichment
    CVSS 8.8
    Jenkins Project/Jenkins Multijob Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-70430Low
    CISA ADP Vulnrichment
    CVSS 2.7
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
Page 16 of 325
Previous1415161718Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 751–800 of 16,243 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-66298High
    JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
    CVSS 8.6
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  2. CVE-2026-66297Medium
    Unescaped deployment environment variables in generated setup commands
    CVSS 4.9
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  3. CVE-2026-66881High
    Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
    CVSS 7.0
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  4. CVE-2026-68746High
    Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
    CVSS 7.7
    livebook-dev/livebookgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-70616Medium
    boringproxy 0.10.0 Resource Exhaustion DoS via GET /loading endpoint
    CVSS 6.5
    boringproxy/boringproxygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-70615Critical
    boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation
    CVSS 9.9
    boringproxy/boringproxygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-18953High
    Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
    CVSS 8.6
    AWS/aws-transform-mcp-servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-55523High
    PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets
    CVSS 7.7
    MervinPraison/PraisonAIgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-69111High
    Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
    CVSS 7.5
    milvus-io/milvusgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-55522High
    PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
    CVSS 7.8
    MervinPraison/PraisonAI, MervinPraison/praisonaiagentsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-18485High
    Local Privilege Escalation in NI-PAL
    CVSS 7.8
    NI/NI-PALgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-17624High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-17633High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-17632High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-48168Critical
    PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name
    CVSS 10.0
    MervinPraison/PraisonAIgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-9196High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-8182High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-9201High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-8478High
    Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-8183High
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 7.7
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-7658Medium
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-9130High
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 7.1
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-10547Medium
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 5.9
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-7869Medium
    Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
    CVSS 5.4
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-8470High
    Langflow is affected by weaknesses in secret handling and sensitive configuration access
    CVSS 7.4
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-63457Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Hewlett Packard Enterprise (HPE)/HPE Integrated Lights-Out 6 (iLO 6)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2026-9205High
    Langflow is affected by weaknesses in secret handling and sensitive configuration access
    CVSS 7.4
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-70612Medium
    Electron: Sandboxed iframes can launch external protocol handlers
    CVSS 5.4
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-70611Medium
    Electron: DevTools embedder handler executes arbitrary files via shell open
    CVSS 6.9
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-10128Medium
    Langflow is affected by weaknesses in secret handling and sensitive configuration access
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-70610Medium
    Electron: contextBridge object copy honors prototype setters
    CVSS 5.4
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-70448High
    CISA ADP Vulnrichment
    CVSS 7.1
    Jenkins Project/Jenkins Ivy Report Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-70447Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins AWS CodeBuild Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-70446Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins CodeSonar Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-70445Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Sauce OnDemand Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-70444Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Violation Comments to GitLab Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-70443Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Horreum Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-70442Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Google Chat Notification Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-70441Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Jenkins Project/Jenkins Summary Display Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-70440Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Jenkins Project/Jenkins Qualys Container Scanning Connector Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  41. CVE-2026-70439Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Jenkins Project/Jenkins XML Job to Job DSL Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-70438Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins Parameterized Remote Trigger Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-70437Low
    CISA ADP Vulnrichment
    CVSS 3.7
    Jenkins Project/Jenkins Webhook Secret Credentials Provider Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-70436Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins External Workspace Manager Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-70435Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Jenkins Project/Jenkins SCM-Manager Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-70434Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Jenkins Project/Jenkins SCM-Manager Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-70433Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Jenkins Project/Jenkins HCL AppScan Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-70432High
    CISA ADP Vulnrichment
    CVSS 8.8
    Jenkins Project/Jenkins Multijob Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-70431High
    CISA ADP Vulnrichment
    CVSS 8.8
    Jenkins Project/Jenkins Multijob Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-70430Low
    CISA ADP Vulnrichment
    CVSS 2.7
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
Page 16 of 325
Previous1415161718Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard