1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:35 PM 17,377 active 1,443 known exploited

Catalog summary

17,377

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:35 PM 17,377 active 1,443 known exploited

Catalog summary

17,377

Active CVEs

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,051–8,100 of 17,377 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-46625High
    JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
    CVSS 7.5
    js-cookie, js-cookie/js-cookiegeneric · npm
    PublishedJun 10, 2026First seen at HOL Jun 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  2. CVE-2026-0274Critical
    Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
    CVSS 9.1
    Palo Alto Networks/Cortex XSIAM CommvaultSecurityIQ Marketplace, Palo Alto Networks/Cortex XSOAR CommvaultSecurityIQ Marketplacegeneric
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  3. CVE-2026-0273High
    PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
    CVSS 7.2
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  4. CVE-2026-0272High
    PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
    CVSS 7.2
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  5. CVE-2026-0271High
    Prisma Access Agent: Local Privilege Escalation by Authorized Users
    CVSS 7.8
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-0270High
    Cortex XSOAR: Path Traversal Vulnerability
    CVSS 7.5
    Palo Alto Networks/Cortex XSOARgeneric
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-0269Medium
    PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
    CVSS 5.7
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-0268Medium
    Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
    CVSS 4.4
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJun 10, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  9. CVE-2026-0267Medium
    GlobalProtect App: Information Exposure Vulnerability on macOS
    CVSS 5.5
    Palo Alto Networks/GlobalProtect Appgeneric
    PublishedJun 10, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-0266Medium
    PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
    CVSS 4.8
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 13, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  11. CVE-2026-10143High
    kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py
    CVSS 7.5
    Dana Powers/kafka-pythongeneric
    PublishedJun 10, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-46529High
    PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
    CVSS 7.8
    mate-desktop/atrilgeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jul 28, 2026View HOL analysis
  13. CVE-2026-20253High
    Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
    Not scored Known exploited
    Splunk/Splunk Enterprisegeneric
    PublishedJun 10, 2026First seen at HOL Jun 19, 2026Updated Jun 21, 2026 Fix availableView HOL analysis
  14. CVE-2026-53694High
    Potential local privileges escalation through argument injection in the nxchmod.sh script
    CVSS 7.3
    NoMachine/NoMachinegeneric
    PublishedJun 10, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-11884Medium
    389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  16. CVE-2026-11837High
    Ansible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chown
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedJun 10, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-24719High
    QTS, QuTS hero
    CVSS 7.2
    QNAP Systems Inc./QTS, QNAP Systems Inc./QuTS herogeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  18. CVE-2026-24717Medium
    QTS, QuTS hero
    CVSS 6.5
    QNAP Systems Inc./QTS, QNAP Systems Inc./QuTS herogeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  19. CVE-2026-24716High
    QTS, QuTS hero
    CVSS 7.2
    QNAP Systems Inc./QTS, QNAP Systems Inc./QuTS herogeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  20. CVE-2026-46546Medium
    Frappe LMS: HTML injection in user-controlled metadata
    CVSS 5.4
    frappe/lmsgeneric
    PublishedJun 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-41837Medium
    Spring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keys
    CVSS 5.3
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  22. CVE-2026-41732High
    In Spring for Apache Pulsar, overly broad trusted-package matching in header mapper exposes JDK classes to deserialization
    CVSS 8.1
    Spring/Spring for Apache Pulsargeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  23. CVE-2026-41730Medium
    Spring Data REST exposes persistence-layer internals in error responses
    CVSS 5.3
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  24. CVE-2026-41729High
    Spring Data REST SpEL Injection via Map Key in JSON Patch
    CVSS 8.1
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-41728High
    Spring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collections
    CVSS 7.5
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-41727Medium
    In Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behavior
    CVSS 6.5
    Spring/Spring for Apache Kafkageneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  27. CVE-2026-41721Medium
    Spring Data Commons Denial of Service via Data Binding
    CVSS 5.9
    Spring/Spring Data Commonsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  28. CVE-2026-41719Medium
    Spring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparator
    CVSS 6.4
    Spring/Spring Data KeyValue, Spring/Spring Data Redisgeneric
    PublishedJun 9, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  29. CVE-2026-41717High
    Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding
    CVSS 8.1
    Spring/Spring Data MongoDBgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  30. CVE-2026-41716High
    Spring Data web support unbounded negative-result cache keyed on attacker-supplied property names
    CVSS 7.5
    Spring/Spring Data Commonsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  31. CVE-2026-41714Medium
    In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager
    CVSS 4.0
    Spring/Spring AMQPgeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-41711Medium
    Potential Denial of Service through crafted Sort Parameters
    CVSS 5.9
    Spring/Spring Data Commonsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  33. CVE-2026-41706Medium
    Open Redirect When Using CookieRequestCache
    CVSS 6.1
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  34. CVE-2026-41701Medium
    In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues
    CVSS 4.4
    Spring/Spring AMQPgeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  35. CVE-2026-41697Medium
    Spring Data Relational Parameter not Escaped for Query By Example LIKE Pattern
    CVSS 4.8
    Spring/Spring Data JDBC, Spring/Spring Data R2DBC +1generic
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  36. CVE-2026-41696Medium
    Spring Data MongoDB Bind Parameter Literal Quoting Breakout
    CVSS 5.9
    Spring/Spring Data MongoDBgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-41694Low
    SAML Payloads Decrypted Without Valid Signature
    CVSS 3.7
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-41008Medium
    Spring Security Authorization Server Open Redirect via request_uri
    CVSS 6.1
    Spring/Spring Authorization Server, Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  39. CVE-2026-41003High
    Unencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting
    CVSS 7.6
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-40993High
    Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry
    CVSS 7.3
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  41. CVE-2026-40991Medium
    XML External Entity (XXE) injection when documenting untrusted XML content
    CVSS 5.9
    Spring/Spring REST Docsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-40988High
    Unbounded DEFLATE Inflation in SAML 2.0 Service Provider
    CVSS 7.5
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  43. CVE-2026-47929High
    ColdFusion | Incorrect Authorization (CWE-863)
    CVSS 8.4
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-47932High
    ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
    CVSS 8.8
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-47928Critical
    ColdFusion | Improper Input Validation (CWE-20)
    CVSS 9.6
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-47931High
    ColdFusion | Improper Input Validation (CWE-20)
    CVSS 8.4
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-47933Medium
    ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
    CVSS 4.8
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-47937High
    Acrobat Reader | Uncontrolled Search Path Element (CWE-427)
    CVSS 7.7
    Adobe/Acrobat Readergeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2026-47907High
    Dreamweaver Desktop | Improper Access Control (CWE-284)
    CVSS 8.6
    Adobe/Dreamweaver Desktopgeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 29, 2026View HOL analysis
  50. CVE-2026-34694Medium
    Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
    CVSS 4.8
    Adobe/Adobe Experience Manager Forms JEEgeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 29, 2026View HOL analysis
Page 162 of 348
Previous160161162163164Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,711

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,051–8,100 of 17,377 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-46625High
    JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
    CVSS 7.5
    js-cookie, js-cookie/js-cookiegeneric · npm
    PublishedJun 10, 2026First seen at HOL Jun 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  2. CVE-2026-0274Critical
    Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
    CVSS 9.1
    Palo Alto Networks/Cortex XSIAM CommvaultSecurityIQ Marketplace, Palo Alto Networks/Cortex XSOAR CommvaultSecurityIQ Marketplacegeneric
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  3. CVE-2026-0273High
    PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
    CVSS 7.2
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  4. CVE-2026-0272High
    PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
    CVSS 7.2
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  5. CVE-2026-0271High
    Prisma Access Agent: Local Privilege Escalation by Authorized Users
    CVSS 7.8
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-0270High
    Cortex XSOAR: Path Traversal Vulnerability
    CVSS 7.5
    Palo Alto Networks/Cortex XSOARgeneric
    PublishedJun 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-0269Medium
    PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
    CVSS 5.7
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-0268Medium
    Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
    CVSS 4.4
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJun 10, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  9. CVE-2026-0267Medium
    GlobalProtect App: Information Exposure Vulnerability on macOS
    CVSS 5.5
    Palo Alto Networks/GlobalProtect Appgeneric
    PublishedJun 10, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-0266Medium
    PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
    CVSS 4.8
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2026First seen at HOL Jul 13, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  11. CVE-2026-10143High
    kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py
    CVSS 7.5
    Dana Powers/kafka-pythongeneric
    PublishedJun 10, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-46529High
    PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
    CVSS 7.8
    mate-desktop/atrilgeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jul 28, 2026View HOL analysis
  13. CVE-2026-20253High
    Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
    Not scored Known exploited
    Splunk/Splunk Enterprisegeneric
    PublishedJun 10, 2026First seen at HOL Jun 19, 2026Updated Jun 21, 2026 Fix availableView HOL analysis
  14. CVE-2026-53694High
    Potential local privileges escalation through argument injection in the nxchmod.sh script
    CVSS 7.3
    NoMachine/NoMachinegeneric
    PublishedJun 10, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-11884Medium
    389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  16. CVE-2026-11837High
    Ansible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chown
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedJun 10, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-24719High
    QTS, QuTS hero
    CVSS 7.2
    QNAP Systems Inc./QTS, QNAP Systems Inc./QuTS herogeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  18. CVE-2026-24717Medium
    QTS, QuTS hero
    CVSS 6.5
    QNAP Systems Inc./QTS, QNAP Systems Inc./QuTS herogeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  19. CVE-2026-24716High
    QTS, QuTS hero
    CVSS 7.2
    QNAP Systems Inc./QTS, QNAP Systems Inc./QuTS herogeneric
    PublishedJun 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  20. CVE-2026-46546Medium
    Frappe LMS: HTML injection in user-controlled metadata
    CVSS 5.4
    frappe/lmsgeneric
    PublishedJun 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-41837Medium
    Spring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keys
    CVSS 5.3
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  22. CVE-2026-41732High
    In Spring for Apache Pulsar, overly broad trusted-package matching in header mapper exposes JDK classes to deserialization
    CVSS 8.1
    Spring/Spring for Apache Pulsargeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  23. CVE-2026-41730Medium
    Spring Data REST exposes persistence-layer internals in error responses
    CVSS 5.3
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  24. CVE-2026-41729High
    Spring Data REST SpEL Injection via Map Key in JSON Patch
    CVSS 8.1
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-41728High
    Spring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collections
    CVSS 7.5
    Spring/Spring Data RESTgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-41727Medium
    In Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behavior
    CVSS 6.5
    Spring/Spring for Apache Kafkageneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  27. CVE-2026-41721Medium
    Spring Data Commons Denial of Service via Data Binding
    CVSS 5.9
    Spring/Spring Data Commonsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  28. CVE-2026-41719Medium
    Spring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparator
    CVSS 6.4
    Spring/Spring Data KeyValue, Spring/Spring Data Redisgeneric
    PublishedJun 9, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  29. CVE-2026-41717High
    Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding
    CVSS 8.1
    Spring/Spring Data MongoDBgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  30. CVE-2026-41716High
    Spring Data web support unbounded negative-result cache keyed on attacker-supplied property names
    CVSS 7.5
    Spring/Spring Data Commonsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 30, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  31. CVE-2026-41714Medium
    In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager
    CVSS 4.0
    Spring/Spring AMQPgeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-41711Medium
    Potential Denial of Service through crafted Sort Parameters
    CVSS 5.9
    Spring/Spring Data Commonsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  33. CVE-2026-41706Medium
    Open Redirect When Using CookieRequestCache
    CVSS 6.1
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  34. CVE-2026-41701Medium
    In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues
    CVSS 4.4
    Spring/Spring AMQPgeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  35. CVE-2026-41697Medium
    Spring Data Relational Parameter not Escaped for Query By Example LIKE Pattern
    CVSS 4.8
    Spring/Spring Data JDBC, Spring/Spring Data R2DBC +1generic
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  36. CVE-2026-41696Medium
    Spring Data MongoDB Bind Parameter Literal Quoting Breakout
    CVSS 5.9
    Spring/Spring Data MongoDBgeneric
    PublishedJun 9, 2026First seen at HOL Jun 22, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-41694Low
    SAML Payloads Decrypted Without Valid Signature
    CVSS 3.7
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-41008Medium
    Spring Security Authorization Server Open Redirect via request_uri
    CVSS 6.1
    Spring/Spring Authorization Server, Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  39. CVE-2026-41003High
    Unencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting
    CVSS 7.6
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-40993High
    Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry
    CVSS 7.3
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  41. CVE-2026-40991Medium
    XML External Entity (XXE) injection when documenting untrusted XML content
    CVSS 5.9
    Spring/Spring REST Docsgeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-40988High
    Unbounded DEFLATE Inflation in SAML 2.0 Service Provider
    CVSS 7.5
    Spring/Spring Securitygeneric
    PublishedJun 9, 2026First seen at HOL Jun 27, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  43. CVE-2026-47929High
    ColdFusion | Incorrect Authorization (CWE-863)
    CVSS 8.4
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-47932High
    ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
    CVSS 8.8
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-47928Critical
    ColdFusion | Improper Input Validation (CWE-20)
    CVSS 9.6
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-47931High
    ColdFusion | Improper Input Validation (CWE-20)
    CVSS 8.4
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-47933Medium
    ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
    CVSS 4.8
    Adobe/ColdFusiongeneric
    PublishedJun 9, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-47937High
    Acrobat Reader | Uncontrolled Search Path Element (CWE-427)
    CVSS 7.7
    Adobe/Acrobat Readergeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2026-47907High
    Dreamweaver Desktop | Improper Access Control (CWE-284)
    CVSS 8.6
    Adobe/Dreamweaver Desktopgeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 29, 2026View HOL analysis
  50. CVE-2026-34694Medium
    Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
    CVSS 4.8
    Adobe/Adobe Experience Manager Forms JEEgeneric
    PublishedJun 9, 2026First seen at HOL Jun 23, 2026Updated Jun 29, 2026View HOL analysis
Page 162 of 348
Previous160161162163164Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard