1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 8:43 PM 17,638 active 1,445 known exploited

Catalog summary

17,638

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 8:43 PM 17,638 active 1,445 known exploited

Catalog summary

17,638

Active CVEs

8,779

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,851–8,900 of 17,638 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-36538High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2026-36540High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2026-38930Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2026-38931Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-46740Medium
    Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections
    CVSS 5.3
    RRWO/Mojolicious::Plugin::Statsdgeneric
    PublishedMay 26, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026View HOL analysis
  6. CVE-2026-48710Medium
    Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
    CVSS 6.5
    Kludex/starlette, starlettegeneric · pip
    PublishedMay 26, 2026First seen at HOL Jun 23, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-42015Medium
    Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  8. CVE-2026-42013High
    Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  9. CVE-2026-42012High
    Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  10. CVE-2026-48864High
    Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Aug 11, 2026View HOL analysis
  11. CVE-2026-45836Medium
    Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  12. CVE-2026-45835Medium
    Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  13. CVE-2026-45834Medium
    Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  14. CVE-2026-45247High
    Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
    Not scored Known exploited
    Mirasvit/Full Page Cache Warmer for Magento 2generic
    PublishedMay 26, 2026First seen at HOL Jun 3, 2026Updated Jun 6, 2026 Fix availableView HOL analysis
  15. CVE-2026-40033High
    FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass
    CVSS 8.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 26, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  16. CVE-2026-4480Critical
    Samba: samba: remote code execution in printing subsystem via unescaped job description
    CVSS 9.0
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 23, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-7374Critical
    Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
    CVSS 9.9
    kubevirt.io/kubevirtgo
    PublishedMay 26, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-9496High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/org.webjars.npm:pacote, n/a/pacotegeneric
    PublishedMay 26, 2026First seen at HOL Jun 27, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-42496Critical
    Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
    CVSS 9.1
    BINGOS/Archive::Targeneric
    PublishedMay 26, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-36239Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedMay 26, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  21. CVE-2026-40127Medium
    Authorization Bypass Through User-Controlled Key in OutSystems Lifetime
    CVSS 5.3
    OutSystems/Lifetimegeneric
    PublishedMay 25, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  22. CVE-2026-46300High
    net: skbuff: preserve shared-frag marker during coalescing
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 23, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-43503High
    net: skbuff: propagate shared-frag marker through frag-transfer helpers
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 23, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-39821Critical
    Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
    CVSS 9.6
    golang.org/x/net, golang.org/x/net/golang.org/x/net/idnageneric · go
    PublishedMay 22, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  25. CVE-2026-9277Critical
    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
    CVSS 8.1
    shell-quotegeneric · npm
    PublishedMay 22, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-46595Critical
    Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
    CVSS 10.0
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  27. CVE-2026-42508Critical
    Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh/knownhosts +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  28. CVE-2026-39829High
    Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
    CVSS 7.5
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  29. CVE-2026-39830Critical
    Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  30. CVE-2026-39835Medium
    Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
    CVSS 5.3
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  31. CVE-2026-39828Medium
    Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
    CVSS 6.3
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-39832Critical
    Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh/agent +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-34911High
    CISA ADP Vulnrichment
    CVSS 7.7
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  34. CVE-2026-33000Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Ubiquiti Inc/UniFi OS Servergeneric
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  35. CVE-2026-34910Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  36. CVE-2026-34908Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  37. CVE-2026-34909Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +30generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  38. CVE-2025-45145High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2026-36227Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-36228High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2026-37470High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  42. CVE-2026-34926High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Trend Micro, Inc./TrendAI Apex One, Trend Micro, Inc./TrendAI Apex One as a Servicegeneric
    PublishedMay 21, 2026First seen at HOL May 24, 2026Updated Jun 4, 2026 Fix availableView HOL analysis
  43. CVE-2026-43502High
    net/rds: handle zerocopy send cleanup before the message is queued
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-43501Critical
    ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-43499High
    rtmutex: Use waiter::task instead of current in remove_waiter()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-43498High
    accel/ivpu: Disallow re-exporting imported GEM objects
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-43497High
    fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
    CVSS 7.3
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-43496Medium
    net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  49. CVE-2026-43495High
    net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-43494High
    net/rds: reset op_nents when zerocopy page pin fails
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 178 of 353
Previous176177178179180Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,779

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,851–8,900 of 17,638 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-36538High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2026-36540High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2026-38930Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2026-38931Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-46740Medium
    Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections
    CVSS 5.3
    RRWO/Mojolicious::Plugin::Statsdgeneric
    PublishedMay 26, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026View HOL analysis
  6. CVE-2026-48710Medium
    Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
    CVSS 6.5
    Kludex/starlette, starlettegeneric · pip
    PublishedMay 26, 2026First seen at HOL Jun 23, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-42015Medium
    Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  8. CVE-2026-42013High
    Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  9. CVE-2026-42012High
    Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  10. CVE-2026-48864High
    Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 24, 2026Updated Aug 11, 2026View HOL analysis
  11. CVE-2026-45836Medium
    Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  12. CVE-2026-45835Medium
    Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  13. CVE-2026-45834Medium
    Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  14. CVE-2026-45247High
    Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
    Not scored Known exploited
    Mirasvit/Full Page Cache Warmer for Magento 2generic
    PublishedMay 26, 2026First seen at HOL Jun 3, 2026Updated Jun 6, 2026 Fix availableView HOL analysis
  15. CVE-2026-40033High
    FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass
    CVSS 8.8
    FreeRDP/FreeRDPgeneric
    PublishedMay 26, 2026First seen at HOL Jul 8, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  16. CVE-2026-4480Critical
    Samba: samba: remote code execution in printing subsystem via unescaped job description
    CVSS 9.0
    Affected software not mappedEcosystem not listed
    PublishedMay 26, 2026First seen at HOL Jun 23, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-7374Critical
    Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
    CVSS 9.9
    kubevirt.io/kubevirtgo
    PublishedMay 26, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-9496High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/org.webjars.npm:pacote, n/a/pacotegeneric
    PublishedMay 26, 2026First seen at HOL Jun 27, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-42496Critical
    Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
    CVSS 9.1
    BINGOS/Archive::Targeneric
    PublishedMay 26, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-36239Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedMay 26, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  21. CVE-2026-40127Medium
    Authorization Bypass Through User-Controlled Key in OutSystems Lifetime
    CVSS 5.3
    OutSystems/Lifetimegeneric
    PublishedMay 25, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  22. CVE-2026-46300High
    net: skbuff: preserve shared-frag marker during coalescing
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 23, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-43503High
    net: skbuff: propagate shared-frag marker through frag-transfer helpers
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 23, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-39821Critical
    Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
    CVSS 9.6
    golang.org/x/net, golang.org/x/net/golang.org/x/net/idnageneric · go
    PublishedMay 22, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  25. CVE-2026-9277Critical
    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
    CVSS 8.1
    shell-quotegeneric · npm
    PublishedMay 22, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-46595Critical
    Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
    CVSS 10.0
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  27. CVE-2026-42508Critical
    Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh/knownhosts +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  28. CVE-2026-39829High
    Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
    CVSS 7.5
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  29. CVE-2026-39830Critical
    Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  30. CVE-2026-39835Medium
    Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
    CVSS 5.3
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  31. CVE-2026-39828Medium
    Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
    CVSS 6.3
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-39832Critical
    Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh/agent +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-34911High
    CISA ADP Vulnrichment
    CVSS 7.7
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  34. CVE-2026-33000Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Ubiquiti Inc/UniFi OS Servergeneric
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  35. CVE-2026-34910Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  36. CVE-2026-34908Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  37. CVE-2026-34909Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +30generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  38. CVE-2025-45145High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2026-36227Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-36228High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2026-37470High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  42. CVE-2026-34926High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Trend Micro, Inc./TrendAI Apex One, Trend Micro, Inc./TrendAI Apex One as a Servicegeneric
    PublishedMay 21, 2026First seen at HOL May 24, 2026Updated Jun 4, 2026 Fix availableView HOL analysis
  43. CVE-2026-43502High
    net/rds: handle zerocopy send cleanup before the message is queued
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-43501Critical
    ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-43499High
    rtmutex: Use waiter::task instead of current in remove_waiter()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-43498High
    accel/ivpu: Disallow re-exporting imported GEM objects
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-43497High
    fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
    CVSS 7.3
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-43496Medium
    net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  49. CVE-2026-43495High
    net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-43494High
    net/rds: reset op_nents when zerocopy page pin fails
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 178 of 353
Previous176177178179180Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard