HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 30, 2026, 3:48 AM 41,407 active 1,505 known exploited

Catalog summary

41,407

Active CVEs

21,348

Critical + high

1,505

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,401–8,450 of 41,407 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-89539Unknown severity
    SUNRPC: reject duplicate CREDS_VALUE options
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  2. CVE-2026-89538Critical
    SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-89537Critical
    SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  4. CVE-2026-89536Critical
    SUNRPC: wait for in-flight client TLS handshake callback
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-89535High
    svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
    CVSS 8.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  6. CVE-2026-89534High
    svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-89533Critical
    svcrdma: Fix offset arithmetic in read_chunk_range
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-89532Critical
    svcrdma: Fix pcl_for_each_segment for empty chunks
    CVSS 9.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-89531Unknown severity
    svcrdma: Reject connection when transport allocation fails
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  10. CVE-2026-89530Critical
    svcrdma: Reject inline replies that overflow the pull-up buffer
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  11. CVE-2026-89529Unknown severity
    svcrdma: Reject oversized Read segments at decode time
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  12. CVE-2026-89528High
    svcrdma: Reject Read lists that exceed the page budget
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  13. CVE-2026-89527Unknown severity
    svcrdma: Use svc_xprt_put to free listener on create failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  14. CVE-2026-89526Critical
    svcrdma: Validate Read chunk positions before reconstruction
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  15. CVE-2026-89525Unknown severity
    udf: reject VAT indexes equal to the entry count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-89524High
    wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
    CVSS 8.1
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-89523High
    wifi: mt76: mt7925: cancel pending mlo_pm_work
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  18. CVE-2026-89522High
    media: staging/ipu7: fix async notifier UAF on probe error path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  19. CVE-2026-89521High
    sched/core: Handle pick_task() releasing the rq lock
    CVSS 7.3
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  20. CVE-2026-89520High
    sched/core: Make core-sched flips wait for in-flight selections
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  21. CVE-2026-89519Unknown severity
    sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  22. CVE-2026-89518Unknown severity
    sched_ext: Fix this_rq() assumptions in dispatch kfuncs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  23. CVE-2026-89517Unknown severity
    sched_ext: Fix rq->core_pick corruption under core scheduling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  24. CVE-2026-89516Unknown severity
    sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  25. CVE-2026-89515Unknown severity
    scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  26. CVE-2026-89514Unknown severity
    scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  27. CVE-2026-89513High
    RISC-V: KVM: Fix PMU event info array size overflow
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  28. CVE-2026-89512Unknown severity
    remoteproc: scp: Fix device reference leak on failed lookup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  29. CVE-2026-89511High
    qede: Fix NULL pointer dereference in TPA fragment processing
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  30. CVE-2026-89510High
    RDMA/cxgb4: Cancel reg_work before freeing device on remove
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  31. CVE-2026-89509Unknown severity
    RDMA/ionic: Embed counter driver data in rdma_counter allocation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-89508High
    RDMA/ucma: Lock the handler in ucma_set_ib_path()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  33. CVE-2026-89507High
    RDMA/ucma: Lock the handler in ucma_write_cm_event()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  34. CVE-2026-89506Unknown severity
    RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  35. CVE-2026-89505Unknown severity
    RDMA/uverbs: Guard legacy bundles without method_elm
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  36. CVE-2026-89504High
    regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  37. CVE-2026-89503High
    ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-89502Unknown severity
    ring-buffer: Free cpu_buffer::free_page with subbuf_order
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  39. CVE-2026-89501High
    ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  40. CVE-2026-89500High
    ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  41. CVE-2026-89499High
    ring-buffer: Stop remote reader update when page swap fails
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 13, 2026 Fix availableView HOL analysis
  42. CVE-2026-89498Unknown severity
    orangefs: fix double-free of trailer_buf on readdir copy failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-89497High
    orangefs: skip leading spaces before parsing client debug masks
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-89496Unknown severity
    ocfs2: always run deallocs on copy-on-write completion
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-89495Critical
    ocfs2: bound namelen in dlm_migrate_request_handler
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-89494Critical
    ocfs2: validate lengths in dlm_mig_lockres_handler
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-89493High
    ocfs2: validate rl_used against rl_count in refcount block validator
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-89492Critical
    ocfs2: validate directory-index entry counts when reading metadata
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  49. CVE-2026-89491Unknown severity
    ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  50. CVE-2026-89490Unknown severity
    ocfs2: fix readdir position truncation on 32-bit kernels
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 11, 2026First seen at HOL Sep 11, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
Page 169 of 829
Previous167168169170171Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard