1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 4:25 PM 17,459 active 1,443 known exploited

Catalog summary

17,459

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 4:25 PM 17,459 active 1,443 known exploited

Catalog summary

17,459

Active CVEs

8,727

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,351–8,400 of 17,459 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-30652High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 4, 2026Updated Jul 4, 2026View HOL analysis
  2. CVE-2026-35716Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2026-35717Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2026-35718Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2019-25718High
    Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
    CVSS 8.4
    Dräger/Infinity Explorer C700generic
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2019-25716Medium
    Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet
    CVSS 6.5
    Dräger/Infinity Delta, Dräger/Infinity Delta XL +1generic
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2025-48595High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Androidgeneric
    PublishedJun 1, 2026First seen at HOL Jun 2, 2026Updated Jun 5, 2026View HOL analysis
  8. CVE-2026-43958High
    Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  9. CVE-2024-52011High
    launch-editor vulnerable to command injection via the crafted request on Windows
    CVSS 8.3
    vitejs/launch-editor, vitejs/vitegeneric
    PublishedJun 1, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-46243High
    smb: client: reject userspace cifs.spnego descriptions
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-10118High
    Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 1, 2026First seen at HOL Jun 22, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-8643Medium
    pip can extract console_scripts and gui_scripts outside installation directory
    CVSS 5.5
    Python Packaging Authority/pip, pipgeneric · pip
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  13. CVE-2025-70099High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 1, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-46242High
    eventpoll: fix ep_remove struct eventpoll / struct file UAF
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 30, 2026First seen at HOL Jul 9, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-46385High
    iskorotkov/avro: CPU Exhaustion in Avro Decoder
    CVSS 7.5
    github.com/iskorotkov/avro/v2, iskorotkov/avrogeneric · go
    PublishedMay 29, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-46384High
    iskorotkov/avro: Integer Overflow in Avro Decoder
    CVSS 7.5
    github.com/iskorotkov/avro/v2, iskorotkov/avrogeneric · go
    PublishedMay 29, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  17. CVE-2026-45700Critical
    Heap-buffer-overflow write in planar bitmap decoder
    CVSS 9.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 29, 2026View HOL analysis
  18. CVE-2026-44420High
    FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS
    CVSS 8.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026View HOL analysis
  19. CVE-2026-44422High
    FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026View HOL analysis
  20. CVE-2026-44421High
    FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass
    CVSS 8.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026View HOL analysis
  21. CVE-2026-10101Medium
    Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents to namespace view users
    CVSS 6.3
    Affected software not mappedEcosystem not listed
    PublishedMay 29, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2026-42965High
    Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypasses destination validation
    CVSS 7.7
    Affected software not mappedEcosystem not listed
    PublishedMay 29, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-46579High
    Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMay 29, 2026First seen at HOL Jun 23, 2026Updated Aug 11, 2026View HOL analysis
  24. CVE-2026-45292Medium
    opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
    CVSS 5.3
    io.opentelemetry/opentelemetry-api, io.opentelemetry/opentelemetry-extension-trace-propagators +3generic · maven
    PublishedMay 28, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  25. CVE-2026-48526High
    PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
    CVSS 7.4
    jpadilla/pyjwt, pyjwtgeneric · pip
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-46240Unknown severity
    media: iris: Fix use-after-free in iris_release_internal_buffers()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-46238Unknown severity
    batman-adv: stop caching unowned originator pointers in BAT IV
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-46232Unknown severity
    HID: playstation: Clamp num_touch_reports
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-46230Unknown severity
    drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-46227High
    sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-46218Unknown severity
    drm/amdgpu: Add bounds checking to ib_{get,set}_value
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-46215Unknown severity
    drm: Set old handle to NULL before prime swap in change_handle
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-46212Unknown severity
    batman-adv: bla: prevent use-after-free when deleting claims
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-46210Unknown severity
    media: iris: fix use-after-free of fmt_src during MBPF check
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-46209Unknown severity
    drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-46208High
    batman-adv: stop tp_meter sessions during mesh teardown
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-46206Unknown severity
    batman-adv: reject new tp_meter sessions during teardown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-46205Unknown severity
    staging: media: atomisp: Disallow all private IOCTLs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-46204Unknown severity
    drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-46203High
    spi: cadence-quadspi: fix unclocked access on unbind
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  41. CVE-2026-46201Unknown severity
    drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-46199Unknown severity
    drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-46198Unknown severity
    batman-adv: fix integer overflow on buff_pos
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-46197Unknown severity
    drm/amdkfd: validate SVM ioctl nattr against buffer size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-46196Medium
    tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  46. CVE-2026-46195Critical
    smb: client: validate dacloffset before building DACL pointers
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-46193Medium
    xfrm: ah: account for ESN high bits in async callbacks
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  48. CVE-2026-46191High
    fbcon: Avoid OOB font access if console rotation fails
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  49. CVE-2026-46190High
    mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-46189High
    RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jul 1, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
Page 168 of 350
Previous166167168169170Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,727

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,351–8,400 of 17,459 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-30652High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 4, 2026Updated Jul 4, 2026View HOL analysis
  2. CVE-2026-35716Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2026-35717Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2026-35718Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJun 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2019-25718High
    Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
    CVSS 8.4
    Dräger/Infinity Explorer C700generic
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2019-25716Medium
    Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet
    CVSS 6.5
    Dräger/Infinity Delta, Dräger/Infinity Delta XL +1generic
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2025-48595High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Androidgeneric
    PublishedJun 1, 2026First seen at HOL Jun 2, 2026Updated Jun 5, 2026View HOL analysis
  8. CVE-2026-43958High
    Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  9. CVE-2024-52011High
    launch-editor vulnerable to command injection via the crafted request on Windows
    CVSS 8.3
    vitejs/launch-editor, vitejs/vitegeneric
    PublishedJun 1, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-46243High
    smb: client: reject userspace cifs.spnego descriptions
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-10118High
    Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJun 1, 2026First seen at HOL Jun 22, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-8643Medium
    pip can extract console_scripts and gui_scripts outside installation directory
    CVSS 5.5
    Python Packaging Authority/pip, pipgeneric · pip
    PublishedJun 1, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  13. CVE-2025-70099High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 1, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-46242High
    eventpoll: fix ep_remove struct eventpoll / struct file UAF
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 30, 2026First seen at HOL Jul 9, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-46385High
    iskorotkov/avro: CPU Exhaustion in Avro Decoder
    CVSS 7.5
    github.com/iskorotkov/avro/v2, iskorotkov/avrogeneric · go
    PublishedMay 29, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-46384High
    iskorotkov/avro: Integer Overflow in Avro Decoder
    CVSS 7.5
    github.com/iskorotkov/avro/v2, iskorotkov/avrogeneric · go
    PublishedMay 29, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  17. CVE-2026-45700Critical
    Heap-buffer-overflow write in planar bitmap decoder
    CVSS 9.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 29, 2026View HOL analysis
  18. CVE-2026-44420High
    FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS
    CVSS 8.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026View HOL analysis
  19. CVE-2026-44422High
    FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026View HOL analysis
  20. CVE-2026-44421High
    FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass
    CVSS 8.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 29, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026View HOL analysis
  21. CVE-2026-10101Medium
    Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents to namespace view users
    CVSS 6.3
    Affected software not mappedEcosystem not listed
    PublishedMay 29, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2026-42965High
    Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypasses destination validation
    CVSS 7.7
    Affected software not mappedEcosystem not listed
    PublishedMay 29, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-46579High
    Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMay 29, 2026First seen at HOL Jun 23, 2026Updated Aug 11, 2026View HOL analysis
  24. CVE-2026-45292Medium
    opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
    CVSS 5.3
    io.opentelemetry/opentelemetry-api, io.opentelemetry/opentelemetry-extension-trace-propagators +3generic · maven
    PublishedMay 28, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  25. CVE-2026-48526High
    PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
    CVSS 7.4
    jpadilla/pyjwt, pyjwtgeneric · pip
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-46240Unknown severity
    media: iris: Fix use-after-free in iris_release_internal_buffers()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-46238Unknown severity
    batman-adv: stop caching unowned originator pointers in BAT IV
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-46232Unknown severity
    HID: playstation: Clamp num_touch_reports
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-46230Unknown severity
    drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-46227High
    sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-46218Unknown severity
    drm/amdgpu: Add bounds checking to ib_{get,set}_value
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-46215Unknown severity
    drm: Set old handle to NULL before prime swap in change_handle
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-46212Unknown severity
    batman-adv: bla: prevent use-after-free when deleting claims
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-46210Unknown severity
    media: iris: fix use-after-free of fmt_src during MBPF check
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-46209Unknown severity
    drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-46208High
    batman-adv: stop tp_meter sessions during mesh teardown
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-46206Unknown severity
    batman-adv: reject new tp_meter sessions during teardown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-46205Unknown severity
    staging: media: atomisp: Disallow all private IOCTLs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-46204Unknown severity
    drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-46203High
    spi: cadence-quadspi: fix unclocked access on unbind
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  41. CVE-2026-46201Unknown severity
    drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-46199Unknown severity
    drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-46198Unknown severity
    batman-adv: fix integer overflow on buff_pos
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-46197Unknown severity
    drm/amdkfd: validate SVM ioctl nattr against buffer size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-46196Medium
    tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  46. CVE-2026-46195Critical
    smb: client: validate dacloffset before building DACL pointers
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-46193Medium
    xfrm: ah: account for ESN high bits in async callbacks
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  48. CVE-2026-46191High
    fbcon: Avoid OOB font access if console rotation fails
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  49. CVE-2026-46190High
    mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-46189High
    RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 28, 2026First seen at HOL Jul 1, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
Page 168 of 350
Previous166167168169170Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard