HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 30, 2026, 3:04 AM 41,406 active 1,505 known exploited

Catalog summary

41,406

Active CVEs

21,348

Critical + high

1,505

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,301–8,350 of 41,406 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-89637Critical
    smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  2. CVE-2026-89636Critical
    smb: client: clear ce->tgthint in free_tgts()
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-89635Critical
    ksmbd: only rebind the reopened file's own oplock on durable reconnect
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  4. CVE-2026-89634Critical
    smb: client: fix ALIGN() overflow in symlink_data() error context loop
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-89633Critical
    smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-89632High
    smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
    CVSS 8.2
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-89631Critical
    smb: client: reject a tree connect response whose byte count is too small
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  8. CVE-2026-89630Critical
    smb: client: restore the data_offset bound in is_valid_oplock_break()
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  9. CVE-2026-89629Unknown severity
    HID: corsair-void: Check size of status and firmware events before reading them
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  10. CVE-2026-89628Unknown severity
    HID: picolcd: clamp eeprom debugfs read to bytes actually received
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-89627Unknown severity
    HID: roccat: free buffered reports when destroying device
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  12. CVE-2026-89626High
    HID: sensor: custom: Fix field sysfs group cleanup on failure
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  13. CVE-2026-89625Unknown severity
    HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  14. CVE-2026-89624High
    HID: universal-pidff: stop the device when force-feedback init fails
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  15. CVE-2026-89623Unknown severity
    HID: mcp2221: stop device IO before hid_hw_stop
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-89622High
    HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  17. CVE-2026-89621Unknown severity
    HID: mcp2221: validate report size in mcp2221_raw_event()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-89620High
    HID: intel-thc-hid: intel-quickspi: validate report size before copy
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  19. CVE-2026-89619High
    HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  20. CVE-2026-89618Unknown severity
    eventfs: Initialize ei->children and ei->list in init_ei()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-89617High
    fs/ntfs3: validate dirty page table on log replay
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-89616High
    fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  23. CVE-2026-89615High
    fs/ntfs3: bound page_lcns[] index by the log record
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-89614Critical
    ntfs: bound the free-cluster bitmap scan to the volume
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  25. CVE-2026-89613Critical
    ntfs: reject invalid empty mapping pairs
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  26. CVE-2026-89612Critical
    ntfs: reject invalid MFT LCNs from boot sector
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-89611Critical
    ntfs: validate non-resident attribute offsets
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  28. CVE-2026-89610Critical
    ntfs: verify run length exceeding volume boundary
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  29. CVE-2026-89609High
    ecryptfs: hold msg ctx list lock when cleaning daemon queue
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  30. CVE-2026-89608High
    ecryptfs: pass packet set buffer size to parser
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  31. CVE-2026-89607High
    ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  32. CVE-2026-89606High
    ecryptfs: reject too-small tag 70 packets
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  33. CVE-2026-89605High
    ecryptfs: release message context on send failure
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  34. CVE-2026-89604Unknown severity
    efivarfs: Rate limit statfs() handler
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  35. CVE-2026-89603High
    entry: Fix seccomp bypass after ptrace with TSYNC
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  36. CVE-2026-89602High
    erofs: skip sufficiently large global buffers when resizing
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  37. CVE-2026-89601High
    ext2: Fix lost inode updates for IS_SYNC inodes
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-89600High
    fanotify: fix use-after-free of file range info
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  39. CVE-2026-89599High
    fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-89598Unknown severity
    fbdev: ssd1307fb: defer I2C transfers from damage callbacks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  41. CVE-2026-89597High
    fbdev: uvesafb: unregister connector callback on init failure
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-89596High
    forcedeth: fix off-by-one when saving/restoring non-PCI config space
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-89595Unknown severity
    fsnotify: Fix stale object mask after concurrent mark updates
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-89594High
    hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-89593High
    hugetlb: only adjust reservation during unmapping if mapcount is 0
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-89592Unknown severity
    accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-89591Unknown severity
    accel/rocket: initialize job domain before cleanup paths
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  48. CVE-2026-89590Unknown severity
    accel/rocket: Fix error path handling in rocket_job_run()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  49. CVE-2026-89589Unknown severity
    acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  50. CVE-2026-89588High
    ACPI: APEI: GHES: fix ARM section length accounting after header
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
Page 167 of 829
Previous165166167168169Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard