1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 12:50 PM 17,376 active 1,443 known exploited

Catalog summary

17,376

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 12:50 PM 17,376 active 1,443 known exploited

Catalog summary

17,376

Active CVEs

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,951–8,000 of 17,376 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12290High
    Memory safety bug fixed in Firefox 152
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-12289High
    Privilege escalation in the Graphics: WebRender component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-12225High
    syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent
    CVSS 8.7
    syracom AG/Secure Login (2FA) for Bitbucket, syracom AG/Secure Login (2FA) for Confluence +1generic
    PublishedJun 16, 2026First seen at HOL Jun 21, 2026Updated Jun 21, 2026 Fix availableView HOL analysis
  4. CVE-2026-46331High
    net/sched: fix pedit partial COW leading to page cache corruption
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 16, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-42014Medium
    Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  6. CVE-2026-49763Critical
    WordPress Integration for Contact Form 7 HubSpot plugin <= 1.3.7 - PHP Object Injection vulnerability
    CVSS 9.8
    CRM Perks/Integration for Contact Form 7 HubSpotgeneric
    PublishedJun 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-47825High
    Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations
    CVSS 8.6
    Spring/Spring Cloud Gatewaygeneric
    PublishedJun 15, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  8. CVE-2026-53704High
    Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parser
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJun 15, 2026First seen at HOL Jul 8, 2026Updated Aug 5, 2026View HOL analysis
  9. CVE-2026-53703High
    Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parser
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJun 15, 2026First seen at HOL Jul 8, 2026Updated Aug 5, 2026View HOL analysis
  10. CVE-2026-20262High
    Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
    Not scored Known exploited
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedJun 15, 2026First seen at HOL Jun 19, 2026Updated Jun 29, 2026View HOL analysis
  11. CVE-2026-10634Medium
    Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback
    CVSS 4.8
    zephyrproject/zephyrgeneric
    PublishedJun 15, 2026First seen at HOL Jul 1, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-12188Medium
    Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
    CVSS 6.3
    Grit42/Gritgeneric
    PublishedJun 14, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  13. CVE-2026-54413High
    iso14229 Integer Underflow and Out-of-Bounds Read in Handle_0x27_SecurityAccess()
    CVSS 8.2
    driftregion/iso14229generic
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  14. CVE-2026-54412High
    MQTT-C Heap Out-of-Bounds Read and Integer Underflow in mqtt_unpack_publish_response()
    CVSS 8.2
    LiamBindle/MQTT-Cgeneric
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  15. CVE-2026-54411Medium
    Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison
    CVSS 5.9
    Linux-PAM/Linux-PAMgeneric
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  16. CVE-2026-54410High
    nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field
    CVSS 8.6
    debevv/nanoMODBUSgeneric
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2026-11527High
    Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle
    CVSS 8.6
    SHLOMIF/Config::IniFilesgeneric
    PublishedJun 14, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  18. CVE-2026-11526Critical
    GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
    CVSS 9.8
    RURBAN/GDgeneric
    PublishedJun 14, 2026First seen at HOL Jun 21, 2026Updated Jun 21, 2026 Fix availableView HOL analysis
  19. CVE-2025-15546Medium
    Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition
    CVSS 5.4
    Unknown/Iptanus File Uploadgeneric
    PublishedJun 14, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-12183Critical
    Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
    CVSS 9.8
    Nefteprodukttekhnika LLC/BUK TS-G Gas Station Automation Systemgeneric
    PublishedJun 13, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  21. CVE-2026-6428High
    Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter
    CVSS 7.6
    Koha Community/Kohageneric
    PublishedJun 13, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-11769High
    Operator - Namespaced User Path Traversal
    CVSS 8.8
    Grafana/Grafana Operator, github.com/grafana/grafana-operator +1generic · go
    PublishedJun 13, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2026-44990Critical
    Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
    CVSS 9.3
    apostrophecms/sanitize-html, sanitize-htmlgeneric · npm
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  24. CVE-2026-10715Medium
    Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint
    CVSS 5.1
    Camaleon CMS/Camaleon CMSgeneric
    PublishedJun 12, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  25. CVE-2026-12143High
    form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
    CVSS 7.5
    form-data, form-data/form-datageneric · npm
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-48165High
    MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side
    CVSS 8.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2026-48163High
    MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)
    CVSS 8.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  28. CVE-2026-44173Medium
    MariaDB: FILE privilege was not checked for subqueries in the FROM clause
    CVSS 5.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-44172Critical
    MariaDB: mysql_real_escape_string() incorrectly handled big5
    CVSS 9.8
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  30. CVE-2026-44168High
    MariaDB: wsrep SST unsafe parameter handling on the donor side
    CVSS 8.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  31. CVE-2026-44170Critical
    MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL
    CVSS 9.8
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-45833High
    CISA ADP Vulnrichment
    CVSS 8.8
    Chroma/ChromaDBgeneric
    PublishedJun 12, 2026First seen at HOL Jul 15, 2026Updated Jul 31, 2026View HOL analysis
  33. CVE-2026-45832High
    CISA ADP Vulnrichment
    CVSS 8.8
    Chroma/ChromaDBgeneric
    PublishedJun 12, 2026First seen at HOL Jul 15, 2026Updated Jul 31, 2026View HOL analysis
  34. CVE-2026-50010High
    Netty's wrapping plain trust manager silently disables hostname verification
    CVSS 7.5
    io.netty:netty-handler, netty/nettygeneric · maven
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-45830High
    CISA ADP Vulnrichment
    CVSS 8.8
    Chroma/ChromaDBgeneric
    PublishedJun 12, 2026First seen at HOL Jul 15, 2026Updated Jul 31, 2026View HOL analysis
  36. CVE-2026-48748High
    Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
    CVSS 7.5
    io.netty:netty-codec-http3, netty/nettygeneric · maven
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  37. CVE-2026-45416High
    Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
    CVSS 7.5
    io.netty:netty-handler, netty/nettygeneric · maven
    PublishedJun 12, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  38. CVE-2026-50645High
    Apache CXF: No restriction on attachment headers per message
    CVSS 7.5
    Apache Software Foundation/Apache CXF, org.apache.cxf:cxf-coregeneric · maven
    PublishedJun 12, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-50634Medium
    Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
    CVSS 6.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-50633High
    Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
    CVSS 8.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 10, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-50632High
    Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory
    CVSS 8.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 2, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-50631High
    Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing
    CVSS 7.4
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-50630Medium
    Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection
    CVSS 6.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-50629Medium
    Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier
    CVSS 5.3
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  45. CVE-2026-50628Critical
    Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-50627Critical
    Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-49875Critical
    Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 9, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-50623Medium
    Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService
    CVSS 4.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-45169High
    Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing
    CVSS 8.6
    CyberArk Software, a Palo Alto Networks Company/PAM SH Vaultgeneric
    PublishedJun 12, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-11933High
    Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
    CVSS 8.8
    MongoDB/MongoDBgeneric
    PublishedJun 12, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
Page 160 of 348
Previous158159160161162Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,951–8,000 of 17,376 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12290High
    Memory safety bug fixed in Firefox 152
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-12289High
    Privilege escalation in the Graphics: WebRender component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-12225High
    syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent
    CVSS 8.7
    syracom AG/Secure Login (2FA) for Bitbucket, syracom AG/Secure Login (2FA) for Confluence +1generic
    PublishedJun 16, 2026First seen at HOL Jun 21, 2026Updated Jun 21, 2026 Fix availableView HOL analysis
  4. CVE-2026-46331High
    net/sched: fix pedit partial COW leading to page cache corruption
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 16, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-42014Medium
    Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedJun 16, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  6. CVE-2026-49763Critical
    WordPress Integration for Contact Form 7 HubSpot plugin <= 1.3.7 - PHP Object Injection vulnerability
    CVSS 9.8
    CRM Perks/Integration for Contact Form 7 HubSpotgeneric
    PublishedJun 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-47825High
    Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations
    CVSS 8.6
    Spring/Spring Cloud Gatewaygeneric
    PublishedJun 15, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  8. CVE-2026-53704High
    Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parser
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJun 15, 2026First seen at HOL Jul 8, 2026Updated Aug 5, 2026View HOL analysis
  9. CVE-2026-53703High
    Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parser
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJun 15, 2026First seen at HOL Jul 8, 2026Updated Aug 5, 2026View HOL analysis
  10. CVE-2026-20262High
    Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
    Not scored Known exploited
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedJun 15, 2026First seen at HOL Jun 19, 2026Updated Jun 29, 2026View HOL analysis
  11. CVE-2026-10634Medium
    Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback
    CVSS 4.8
    zephyrproject/zephyrgeneric
    PublishedJun 15, 2026First seen at HOL Jul 1, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-12188Medium
    Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
    CVSS 6.3
    Grit42/Gritgeneric
    PublishedJun 14, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  13. CVE-2026-54413High
    iso14229 Integer Underflow and Out-of-Bounds Read in Handle_0x27_SecurityAccess()
    CVSS 8.2
    driftregion/iso14229generic
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  14. CVE-2026-54412High
    MQTT-C Heap Out-of-Bounds Read and Integer Underflow in mqtt_unpack_publish_response()
    CVSS 8.2
    LiamBindle/MQTT-Cgeneric
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  15. CVE-2026-54411Medium
    Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison
    CVSS 5.9
    Linux-PAM/Linux-PAMgeneric
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  16. CVE-2026-54410High
    nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field
    CVSS 8.6
    debevv/nanoMODBUSgeneric
    PublishedJun 14, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2026-11527High
    Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle
    CVSS 8.6
    SHLOMIF/Config::IniFilesgeneric
    PublishedJun 14, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  18. CVE-2026-11526Critical
    GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
    CVSS 9.8
    RURBAN/GDgeneric
    PublishedJun 14, 2026First seen at HOL Jun 21, 2026Updated Jun 21, 2026 Fix availableView HOL analysis
  19. CVE-2025-15546Medium
    Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition
    CVSS 5.4
    Unknown/Iptanus File Uploadgeneric
    PublishedJun 14, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-12183Critical
    Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
    CVSS 9.8
    Nefteprodukttekhnika LLC/BUK TS-G Gas Station Automation Systemgeneric
    PublishedJun 13, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  21. CVE-2026-6428High
    Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter
    CVSS 7.6
    Koha Community/Kohageneric
    PublishedJun 13, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-11769High
    Operator - Namespaced User Path Traversal
    CVSS 8.8
    Grafana/Grafana Operator, github.com/grafana/grafana-operator +1generic · go
    PublishedJun 13, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2026-44990Critical
    Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
    CVSS 9.3
    apostrophecms/sanitize-html, sanitize-htmlgeneric · npm
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  24. CVE-2026-10715Medium
    Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint
    CVSS 5.1
    Camaleon CMS/Camaleon CMSgeneric
    PublishedJun 12, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  25. CVE-2026-12143High
    form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
    CVSS 7.5
    form-data, form-data/form-datageneric · npm
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-48165High
    MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side
    CVSS 8.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2026-48163High
    MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)
    CVSS 8.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  28. CVE-2026-44173Medium
    MariaDB: FILE privilege was not checked for subqueries in the FROM clause
    CVSS 5.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-44172Critical
    MariaDB: mysql_real_escape_string() incorrectly handled big5
    CVSS 9.8
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Jul 30, 2026View HOL analysis
  30. CVE-2026-44168High
    MariaDB: wsrep SST unsafe parameter handling on the donor side
    CVSS 8.0
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  31. CVE-2026-44170Critical
    MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL
    CVSS 9.8
    MariaDB/servergeneric
    PublishedJun 12, 2026First seen at HOL Jun 30, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-45833High
    CISA ADP Vulnrichment
    CVSS 8.8
    Chroma/ChromaDBgeneric
    PublishedJun 12, 2026First seen at HOL Jul 15, 2026Updated Jul 31, 2026View HOL analysis
  33. CVE-2026-45832High
    CISA ADP Vulnrichment
    CVSS 8.8
    Chroma/ChromaDBgeneric
    PublishedJun 12, 2026First seen at HOL Jul 15, 2026Updated Jul 31, 2026View HOL analysis
  34. CVE-2026-50010High
    Netty's wrapping plain trust manager silently disables hostname verification
    CVSS 7.5
    io.netty:netty-handler, netty/nettygeneric · maven
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-45830High
    CISA ADP Vulnrichment
    CVSS 8.8
    Chroma/ChromaDBgeneric
    PublishedJun 12, 2026First seen at HOL Jul 15, 2026Updated Jul 31, 2026View HOL analysis
  36. CVE-2026-48748High
    Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
    CVSS 7.5
    io.netty:netty-codec-http3, netty/nettygeneric · maven
    PublishedJun 12, 2026First seen at HOL Jun 19, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  37. CVE-2026-45416High
    Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
    CVSS 7.5
    io.netty:netty-handler, netty/nettygeneric · maven
    PublishedJun 12, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  38. CVE-2026-50645High
    Apache CXF: No restriction on attachment headers per message
    CVSS 7.5
    Apache Software Foundation/Apache CXF, org.apache.cxf:cxf-coregeneric · maven
    PublishedJun 12, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-50634Medium
    Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
    CVSS 6.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-50633High
    Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
    CVSS 8.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 10, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-50632High
    Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory
    CVSS 8.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 2, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-50631High
    Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing
    CVSS 7.4
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-50630Medium
    Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection
    CVSS 6.5
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-50629Medium
    Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier
    CVSS 5.3
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  45. CVE-2026-50628Critical
    Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-50627Critical
    Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
    CVSS 9.1
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-49875Critical
    Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils
    CVSS 9.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Jul 9, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-50623Medium
    Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService
    CVSS 4.8
    Apache Software Foundation/Apache CXFgeneric
    PublishedJun 12, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-45169High
    Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing
    CVSS 8.6
    CyberArk Software, a Palo Alto Networks Company/PAM SH Vaultgeneric
    PublishedJun 12, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-11933High
    Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
    CVSS 8.8
    MongoDB/MongoDBgeneric
    PublishedJun 12, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
Page 160 of 348
Previous158159160161162Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard