1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:35 PM 17,377 active 1,443 known exploited

Catalog summary

17,377

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:35 PM 17,377 active 1,443 known exploited

Catalog summary

17,377

Active CVEs

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,001–8,050 of 17,377 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-11933High
    Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
    CVSS 8.8
    MongoDB/MongoDBgeneric
    PublishedJun 12, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-45170High
    Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation
    CVSS 8.8
    CyberArk Software, a Palo Alto Networks Company/Vendor PAMgeneric
    PublishedJun 12, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  3. CVE-2026-45171High
    Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input Validation
    CVSS 8.8
    CyberArk Software, a Palo Alto Networks Company/Privileged Session Manager, Vaultgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  4. CVE-2026-45172High
    Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS Command
    CVSS 8.8
    CyberArk Software, a Palo Alto Networks Company/PAM Self-Hosted, Privilege Cloudgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  5. CVE-2026-45173Medium
    Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure
    CVSS 6.5
    CyberArk Software, a Palo Alto Networks Company/Identity Browser Extensionsgeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  6. CVE-2026-45174High
    Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization
    CVSS 7.8
    CyberArk Software, a Palo Alto Networks Company/Idira Endpoint Privilege Managergeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  7. CVE-2026-12027Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  8. CVE-2026-12026Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  9. CVE-2026-12024Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  10. CVE-2026-12018High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  11. CVE-2026-12017Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  12. CVE-2026-12016High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  13. CVE-2026-12015Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  14. CVE-2026-12014High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  15. CVE-2026-12012High
    CISA ADP Vulnrichment
    CVSS 8.1
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  16. CVE-2026-12008High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  17. CVE-2026-44249High
    Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
    CVSS 8.1
    io.netty:netty-handler, netty/nettygeneric · maven
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-45175High
    Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes
    CVSS 7.8
    CyberArk Software, a Palo Alto Networks Company/Idira Endpoint Privilege Managergeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  19. CVE-2026-45176High
    Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation
    CVSS 7.8
    CyberArk Software, a Palo Alto Networks Company/Idira Endpoint Privilege Managergeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  20. CVE-2026-45177Critical
    Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism
    CVSS 9.1
    CyberArk Software, a Palo Alto Networks Company/Conjur Cloud (Edge Finding only)generic
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  21. CVE-2026-47162High
    Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name
    CVSS 8.8
    vim/vimgeneric
    PublishedJun 11, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  22. CVE-2026-45178High
    Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints
    CVSS 8.1
    CyberArk Software, a Palo Alto Networks Company/Conjur Enterprisegeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  23. CVE-2026-11774High
    389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow
    CVSS 7.6
    Affected software not mappedEcosystem not listed
    PublishedJun 11, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-49261Critical
    MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
    CVSS 10.0
    MariaDB/servergeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Aug 11, 2026View HOL analysis
  25. CVE-2026-11986Medium
    Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJun 11, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  26. CVE-2026-44486High
    Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  27. CVE-2026-44487High
    Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  28. CVE-2026-44488High
    Axios: Allocation of Resources Without Limits or Throttling in axios
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  29. CVE-2026-44496High
    Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  30. CVE-2026-44495High
    Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    CVSS 7.0
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  31. CVE-2026-44494High
    Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
    CVSS 8.7
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  32. CVE-2026-44492High
    Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
    CVSS 8.6
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  33. CVE-2026-11816High
    Path Traversal in keras-team/keras
    CVSS 8.1
    keras, keras-team/keras-team/kerasgeneric · pip · pypi
    PublishedJun 11, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-41856High
    Spring GraphQL Annotation Detection Vulnerability
    CVSS 7.5
    Spring/Spring for GraphQLgeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  35. CVE-2026-41700High
    Cross-Site WebSocket Hijacking in Spring for GraphQL
    CVSS 8.1
    Spring/Spring for GraphQLgeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  36. CVE-2026-41699High
    Unsafe Deserialization in Spring GraphQL
    CVSS 8.1
    Spring/Spring for GraphQLgeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-41001Medium
    Predictable Temp Directory in Artemis Auto-configuration
    CVSS 5.3
    Spring/Spring Bootgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  38. CVE-2026-41000Low
    WSS4J validation does not use configured replay cache
    CVSS 3.7
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  39. CVE-2026-40999High
    Spring WS SSRF via unvalidated WS-Addressing reply destinations
    CVSS 8.6
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  40. CVE-2026-40998High
    Jaxp13 XPath XXE via StreamSource and SAXSource
    CVSS 8.2
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  41. CVE-2026-40997Medium
    SOAP security faults leak Spring Security account state
    CVSS 5.3
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  42. CVE-2026-40996Medium
    Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
    CVSS 4.8
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  43. CVE-2026-40995Medium
    X.509 authentication bypasses Spring Security account checks
    CVSS 5.4
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  44. CVE-2026-40994High
    Wss4jSecurityInterceptor disables WS-I BSP validation by default
    CVSS 8.2
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  45. CVE-2026-40992Medium
    Mail Auto-Configuration Does Not Enable SSL Hostname Verification
    CVSS 5.0
    Spring/Spring Bootgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  46. CVE-2026-40987High
    Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization
    CVSS 7.1
    Spring/Spring Integration, org.springframework.integration:spring-integration-filegeneric · maven
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-40986Medium
    Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
    CVSS 4.8
    Spring/Spring Web Flowgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  48. CVE-2026-40985Medium
    Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
    CVSS 6.4
    Spring/Spring Web Flowgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  49. CVE-2026-35273High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Oracle Corporation/PeopleSoft Enterprise PeopleToolsgeneric
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 4, 2026View HOL analysis
  50. CVE-2026-2049High
    GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedJun 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
Page 161 of 348
Previous159160161162163Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,001–8,050 of 17,377 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-11933High
    Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
    CVSS 8.8
    MongoDB/MongoDBgeneric
    PublishedJun 12, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-45170High
    Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation
    CVSS 8.8
    CyberArk Software, a Palo Alto Networks Company/Vendor PAMgeneric
    PublishedJun 12, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  3. CVE-2026-45171High
    Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input Validation
    CVSS 8.8
    CyberArk Software, a Palo Alto Networks Company/Privileged Session Manager, Vaultgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  4. CVE-2026-45172High
    Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS Command
    CVSS 8.8
    CyberArk Software, a Palo Alto Networks Company/PAM Self-Hosted, Privilege Cloudgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  5. CVE-2026-45173Medium
    Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure
    CVSS 6.5
    CyberArk Software, a Palo Alto Networks Company/Identity Browser Extensionsgeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  6. CVE-2026-45174High
    Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization
    CVSS 7.8
    CyberArk Software, a Palo Alto Networks Company/Idira Endpoint Privilege Managergeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  7. CVE-2026-12027Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  8. CVE-2026-12026Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  9. CVE-2026-12024Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  10. CVE-2026-12018High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  11. CVE-2026-12017Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  12. CVE-2026-12016High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  13. CVE-2026-12015Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  14. CVE-2026-12014High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  15. CVE-2026-12012High
    CISA ADP Vulnrichment
    CVSS 8.1
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  16. CVE-2026-12008High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  17. CVE-2026-44249High
    Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
    CVSS 8.1
    io.netty:netty-handler, netty/nettygeneric · maven
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-45175High
    Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes
    CVSS 7.8
    CyberArk Software, a Palo Alto Networks Company/Idira Endpoint Privilege Managergeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  19. CVE-2026-45176High
    Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation
    CVSS 7.8
    CyberArk Software, a Palo Alto Networks Company/Idira Endpoint Privilege Managergeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  20. CVE-2026-45177Critical
    Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism
    CVSS 9.1
    CyberArk Software, a Palo Alto Networks Company/Conjur Cloud (Edge Finding only)generic
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  21. CVE-2026-47162High
    Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name
    CVSS 8.8
    vim/vimgeneric
    PublishedJun 11, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  22. CVE-2026-45178High
    Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints
    CVSS 8.1
    CyberArk Software, a Palo Alto Networks Company/Conjur Enterprisegeneric
    PublishedJun 11, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  23. CVE-2026-11774High
    389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow
    CVSS 7.6
    Affected software not mappedEcosystem not listed
    PublishedJun 11, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-49261Critical
    MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
    CVSS 10.0
    MariaDB/servergeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Aug 11, 2026View HOL analysis
  25. CVE-2026-11986Medium
    Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJun 11, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  26. CVE-2026-44486High
    Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  27. CVE-2026-44487High
    Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  28. CVE-2026-44488High
    Axios: Allocation of Resources Without Limits or Throttling in axios
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  29. CVE-2026-44496High
    Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  30. CVE-2026-44495High
    Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    CVSS 7.0
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  31. CVE-2026-44494High
    Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
    CVSS 8.7
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  32. CVE-2026-44492High
    Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
    CVSS 8.6
    axios, axios/axiosgeneric · npm
    PublishedJun 11, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  33. CVE-2026-11816High
    Path Traversal in keras-team/keras
    CVSS 8.1
    keras, keras-team/keras-team/kerasgeneric · pip · pypi
    PublishedJun 11, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-41856High
    Spring GraphQL Annotation Detection Vulnerability
    CVSS 7.5
    Spring/Spring for GraphQLgeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  35. CVE-2026-41700High
    Cross-Site WebSocket Hijacking in Spring for GraphQL
    CVSS 8.1
    Spring/Spring for GraphQLgeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  36. CVE-2026-41699High
    Unsafe Deserialization in Spring GraphQL
    CVSS 8.1
    Spring/Spring for GraphQLgeneric
    PublishedJun 11, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-41001Medium
    Predictable Temp Directory in Artemis Auto-configuration
    CVSS 5.3
    Spring/Spring Bootgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  38. CVE-2026-41000Low
    WSS4J validation does not use configured replay cache
    CVSS 3.7
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  39. CVE-2026-40999High
    Spring WS SSRF via unvalidated WS-Addressing reply destinations
    CVSS 8.6
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  40. CVE-2026-40998High
    Jaxp13 XPath XXE via StreamSource and SAXSource
    CVSS 8.2
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  41. CVE-2026-40997Medium
    SOAP security faults leak Spring Security account state
    CVSS 5.3
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  42. CVE-2026-40996Medium
    Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
    CVSS 4.8
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  43. CVE-2026-40995Medium
    X.509 authentication bypasses Spring Security account checks
    CVSS 5.4
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  44. CVE-2026-40994High
    Wss4jSecurityInterceptor disables WS-I BSP validation by default
    CVSS 8.2
    Spring/Spring Web Servicesgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  45. CVE-2026-40992Medium
    Mail Auto-Configuration Does Not Enable SSL Hostname Verification
    CVSS 5.0
    Spring/Spring Bootgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  46. CVE-2026-40987High
    Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization
    CVSS 7.1
    Spring/Spring Integration, org.springframework.integration:spring-integration-filegeneric · maven
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-40986Medium
    Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
    CVSS 4.8
    Spring/Spring Web Flowgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  48. CVE-2026-40985Medium
    Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
    CVSS 6.4
    Spring/Spring Web Flowgeneric
    PublishedJun 11, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  49. CVE-2026-35273High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Oracle Corporation/PeopleSoft Enterprise PeopleToolsgeneric
    PublishedJun 11, 2026First seen at HOL Jun 19, 2026Updated Aug 4, 2026View HOL analysis
  50. CVE-2026-2049High
    GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedJun 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
Page 161 of 348
Previous159160161162163Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard