HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 30, 2026, 1:32 AM 41,398 active 1,505 known exploited

Catalog summary

41,398

Active CVEs

21,347

Critical + high

1,505

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,151–8,200 of 41,398 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-81907Medium
    Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity records
    CVSS 6.1
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 15, 2026View HOL analysis
  2. CVE-2026-81918Medium
    Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
    CVSS 4.8
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 18, 2026View HOL analysis
  3. CVE-2026-81917Medium
    Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
    CVSS 5.4
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 18, 2026View HOL analysis
  4. CVE-2026-68535Medium
    Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions
    CVSS 5.1
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 15, 2026View HOL analysis
  5. CVE-2026-81916Medium
    Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
    CVSS 4.3
    Concrete CMS/Concrete CMSgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 18, 2026View HOL analysis
  6. CVE-2026-49462Medium
    nl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by default
    CVSS 5.3
    nl-portal/nl.nl-portal:appgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026View HOL analysis
  7. CVE-2026-89773Unknown severity
    drm/amd/display: Skip Update HDCP Config In Transition State
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  8. CVE-2026-89772Unknown severity
    btrfs: write-protect folios during data writeback
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  9. CVE-2026-89771High
    ring-buffer: Fix subbuf resize race with ring buffer readers
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  10. CVE-2026-89770Unknown severity
    iomap: don't free integrity payload that doesn't exist
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  11. CVE-2026-89769High
    clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
    CVSS 7.4
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  12. CVE-2026-89768Unknown severity
    fs: fix user path of nested backing files
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  13. CVE-2026-89767High
    ovl: fix double end_creating() on the casefold-mismatch path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  14. CVE-2026-89766Unknown severity
    pidfd: hold exec_update_lock around namespace ioctl
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  15. CVE-2026-89765Unknown severity
    timers/itimer: Zero-init old itimerval before copy to userspace
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-89764High
    rust: devres: fix race between concurrent revokers
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  17. CVE-2026-89763High
    KEYS: trusted: Fix TPM teardown ordering
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  18. CVE-2026-89762High
    apparmor: fix cred UAF caused by begin_current_label_crit_section()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  19. CVE-2026-89761High
    apparmor: fix out-of-bounds write when null terminating a label vec
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  20. CVE-2026-89760High
    mm, swap: don't free a hibernation slot that is in the swap cache
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  21. CVE-2026-89759Unknown severity
    mm/kmemleak: avoid soft lockup when scanning task stacks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  22. CVE-2026-89758High
    mm/mempolicy: skip non-present PMDs when queueing folios
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  23. CVE-2026-89757Unknown severity
    mm/mglru: fix and remove redundant unevictable folio handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  24. CVE-2026-89756Unknown severity
    mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-89755High
    mm/migrate_device: clear stale mapping after freeing swapcache
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  26. CVE-2026-89754High
    mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-89753Unknown severity
    mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  28. CVE-2026-89752Unknown severity
    mm: memcg: stop reclaim when a limit update is superseded
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  29. CVE-2026-89751Unknown severity
    x86/tdx: Fix off-by-one in port I/O handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  30. CVE-2026-89750High
    tracing/user_events: Clear copied tracing state before fork duplication
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  31. CVE-2026-89749Unknown severity
    tracing: Fix crash passing ERR_PTR to kthread_stop()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  32. CVE-2026-89748High
    tracing: Fix retry exhaustion in simple ring buffer reader swap
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  33. CVE-2026-89747High
    tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  34. CVE-2026-89746High
    tracing: Fix use-after-free with same-name named triggers
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  35. CVE-2026-89745Unknown severity
    debugfs: Fix lockdown check for mmap_prepare
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  36. CVE-2026-89744High
    device property: fix infinite loop in fwnode_for_each_child_node()
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  37. CVE-2026-89743High
    misc: nsm: bound the device-reported response length
    CVSS 7.7
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-89742High
    rapidio: mport_cdev: fix use-after-free in dma_req_free()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-89741High
    Revert "media: v4l2-dev: fix error handling in __video_register_device()"
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-89740Unknown severity
    serial: imx: serialize imx_uart_ports[] lifetime
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  41. CVE-2026-89739Unknown severity
    usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  42. CVE-2026-89738High
    usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  43. CVE-2026-89737Unknown severity
    usb: typec: thunderbolt: Disable work before freeing tbt on remove
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  44. CVE-2026-89736High
    usb: gadget: u_audio: Fix use-after-free on sound card disconnect
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-89735Unknown severity
    usb: gadget: midi2: remove default configfs groups on teardown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-89734Unknown severity
    usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-89733High
    usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-89732Unknown severity
    usb: gadget: f_fs: Prevent deadlock during ep0 read loop
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-89731High
    cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  50. CVE-2026-89730Unknown severity
    fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
Page 164 of 828
Previous162163164165166Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard