1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:35 PM 17,658 active 1,445 known exploited

Catalog summary

17,658

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:35 PM 17,658 active 1,445 known exploited

Catalog summary

17,658

Active CVEs

8,779

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,901–8,950 of 17,656 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-39828Medium
    Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
    CVSS 6.3
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  2. CVE-2026-39832Critical
    Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh/agent +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  3. CVE-2026-34911High
    CISA ADP Vulnrichment
    CVSS 7.7
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  4. CVE-2026-33000Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Ubiquiti Inc/UniFi OS Servergeneric
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  5. CVE-2026-34910Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  6. CVE-2026-34908Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  7. CVE-2026-34909Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +30generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2025-45145High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  9. CVE-2026-36227Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  10. CVE-2026-36228High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-37470High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  12. CVE-2026-34926High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Trend Micro, Inc./TrendAI Apex One, Trend Micro, Inc./TrendAI Apex One as a Servicegeneric
    PublishedMay 21, 2026First seen at HOL May 24, 2026Updated Jun 4, 2026 Fix availableView HOL analysis
  13. CVE-2026-43502High
    net/rds: handle zerocopy send cleanup before the message is queued
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-43501Critical
    ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-43499High
    rtmutex: Use waiter::task instead of current in remove_waiter()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-43498High
    accel/ivpu: Disallow re-exporting imported GEM objects
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-43497High
    fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
    CVSS 7.3
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-43496Medium
    net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  19. CVE-2026-43495High
    net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-43494High
    net/rds: reset op_nents when zerocopy page pin fails
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-48172High
    CISA ADP Vulnrichment
    Not scored Known exploited
    LiteSpeed Technologies/WHM Plugin, LiteSpeed Technologies/cPanel Plugingeneric
    PublishedMay 21, 2026First seen at HOL May 26, 2026Updated May 29, 2026 Fix availableView HOL analysis
  22. CVE-2026-20199Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    Cisco/Cisco ThousandEyes Enterprise Agentgeneric
    PublishedMay 20, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2026-20223Critical
    Cisco Secure Workload Unauthorized API Access Vulnerability
    CVSS 10.0
    Cisco/Cisco Secure Workloadgeneric
    PublishedMay 20, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  24. CVE-2026-3593High
    Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
    CVSS 7.4
    ISC/BIND 9generic
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-3039High
    BIND 9 server memory exhaustion during GSS-API TKEY negotiation
    CVSS 7.5
    ISC/BIND 9generic
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-29518High
    Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
    CVSS 7.0
    RsyncProject/rsyncgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-44390Medium
    Unbounded name compression in certain cases causes degradation of service
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  28. CVE-2026-42959High
    Crash during DNSSEC validation of malicious content
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-42944High
    Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-42534Medium
    Jostle logic bypass degrades resolution performance
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  31. CVE-2026-41292High
    Long list of incoming EDNS options degrades performance
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  32. CVE-2026-33278Critical
    Possible arbitrary code execution during DNSSEC validation
    CVSS 9.8
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  33. CVE-2026-47783High
    CISA ADP Vulnrichment
    CVSS 8.1
    memcached/memcachedgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  34. CVE-2026-43618High
    Rsync < 3.4.3 Integer Overflow Information Disclosure
    CVSS 8.1
    RsyncProject/rsyncgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  35. CVE-2026-32882High
    libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride
    CVSS 7.1
    strukturag/libheifgeneric
    PublishedMay 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-32741High
    libheif has a heap buffer overflow in decode_mask_image()
    CVSS 7.1
    strukturag/libheifgeneric
    PublishedMay 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-32740High
    libheif: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing
    CVSS 8.8
    strukturag/libheifgeneric
    PublishedMay 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2025-40904Unknown severity
    HTML injection in Smart Polling in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  39. CVE-2025-40903Unknown severity
    HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  40. CVE-2025-40902Unknown severity
    HTML injection in Users in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  41. CVE-2025-40901Unknown severity
    HTML injection in Credentials Manager in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  42. CVE-2025-40900Unknown severity
    Angular template injection in Reports in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  43. CVE-2026-43493Critical
    crypto: pcrypt - Fix handling of MAY_BACKLOG requests
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 19, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-43492Medium
    lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 19, 2026First seen at HOL Jun 19, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  45. CVE-2026-43491Medium
    net: qrtr: ns: Limit the maximum server registration per node
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 19, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  46. CVE-2026-8813High
    CISA ADP Vulnrichment
    Not scored
    exifreader, n/a/exifreadergeneric · npm
    PublishedMay 19, 2026First seen at HOL Jul 17, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-25244Critical
    WebdriverIO has Command Injection in the BrowserStack Service
    CVSS 9.8
    webdriverio/webdriveriogeneric
    PublishedMay 18, 2026First seen at HOL Jul 15, 2026Updated Jul 23, 2026View HOL analysis
  48. CVE-2026-45829Critical
    CISA ADP Vulnrichment
    CVSS 10.0
    Chroma/ChromaDBgeneric
    PublishedMay 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-20685Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Private Cloud Compute Server Softwaregeneric
    PublishedMay 18, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  50. CVE-2026-41949Medium
    Dify < 1.14.2 Authorization Bypass via File Preview Endpoint
    CVSS 5.9
    langgenius/difygeneric
    PublishedMay 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 179 of 354
Previous177178179180181Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,779

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,901–8,950 of 17,656 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-39828Medium
    Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
    CVSS 6.3
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  2. CVE-2026-39832Critical
    Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
    CVSS 9.1
    golang.org/x/crypto, golang.org/x/crypto/golang.org/x/crypto/ssh/agent +1generic · go
    PublishedMay 22, 2026First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  3. CVE-2026-34911High
    CISA ADP Vulnrichment
    CVSS 7.7
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  4. CVE-2026-33000Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Ubiquiti Inc/UniFi OS Servergeneric
    PublishedMay 22, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026 Fix availableView HOL analysis
  5. CVE-2026-34910Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  6. CVE-2026-34908Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +29generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  7. CVE-2026-34909Critical
    CISA ADP Vulnrichment
    CVSS 10.0 Known exploited
    Ubiquiti Inc/EFG, Ubiquiti Inc/ENVR +30generic
    PublishedMay 22, 2026First seen at HOL Jun 23, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2025-45145High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  9. CVE-2026-36227Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  10. CVE-2026-36228High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-37470High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedMay 22, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  12. CVE-2026-34926High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Trend Micro, Inc./TrendAI Apex One, Trend Micro, Inc./TrendAI Apex One as a Servicegeneric
    PublishedMay 21, 2026First seen at HOL May 24, 2026Updated Jun 4, 2026 Fix availableView HOL analysis
  13. CVE-2026-43502High
    net/rds: handle zerocopy send cleanup before the message is queued
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-43501Critical
    ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-43499High
    rtmutex: Use waiter::task instead of current in remove_waiter()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-43498High
    accel/ivpu: Disallow re-exporting imported GEM objects
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-43497High
    fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
    CVSS 7.3
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-43496Medium
    net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  19. CVE-2026-43495High
    net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-43494High
    net/rds: reset op_nents when zerocopy page pin fails
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 21, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-48172High
    CISA ADP Vulnrichment
    Not scored Known exploited
    LiteSpeed Technologies/WHM Plugin, LiteSpeed Technologies/cPanel Plugingeneric
    PublishedMay 21, 2026First seen at HOL May 26, 2026Updated May 29, 2026 Fix availableView HOL analysis
  22. CVE-2026-20199Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    Cisco/Cisco ThousandEyes Enterprise Agentgeneric
    PublishedMay 20, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2026-20223Critical
    Cisco Secure Workload Unauthorized API Access Vulnerability
    CVSS 10.0
    Cisco/Cisco Secure Workloadgeneric
    PublishedMay 20, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  24. CVE-2026-3593High
    Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
    CVSS 7.4
    ISC/BIND 9generic
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-3039High
    BIND 9 server memory exhaustion during GSS-API TKEY negotiation
    CVSS 7.5
    ISC/BIND 9generic
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-29518High
    Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
    CVSS 7.0
    RsyncProject/rsyncgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-44390Medium
    Unbounded name compression in certain cases causes degradation of service
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  28. CVE-2026-42959High
    Crash during DNSSEC validation of malicious content
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-42944High
    Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-42534Medium
    Jostle logic bypass degrades resolution performance
    CVSS 5.3
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  31. CVE-2026-41292High
    Long list of incoming EDNS options degrades performance
    CVSS 7.5
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  32. CVE-2026-33278Critical
    Possible arbitrary code execution during DNSSEC validation
    CVSS 9.8
    NLnet Labs/Unboundgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  33. CVE-2026-47783High
    CISA ADP Vulnrichment
    CVSS 8.1
    memcached/memcachedgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  34. CVE-2026-43618High
    Rsync < 3.4.3 Integer Overflow Information Disclosure
    CVSS 8.1
    RsyncProject/rsyncgeneric
    PublishedMay 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  35. CVE-2026-32882High
    libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride
    CVSS 7.1
    strukturag/libheifgeneric
    PublishedMay 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-32741High
    libheif has a heap buffer overflow in decode_mask_image()
    CVSS 7.1
    strukturag/libheifgeneric
    PublishedMay 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-32740High
    libheif: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing
    CVSS 8.8
    strukturag/libheifgeneric
    PublishedMay 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2025-40904Unknown severity
    HTML injection in Smart Polling in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  39. CVE-2025-40903Unknown severity
    HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  40. CVE-2025-40902Unknown severity
    HTML injection in Users in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  41. CVE-2025-40901Unknown severity
    HTML injection in Credentials Manager in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  42. CVE-2025-40900Unknown severity
    Angular template injection in Reports in Guardian/CMC before 26.1.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMay 19, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  43. CVE-2026-43493Critical
    crypto: pcrypt - Fix handling of MAY_BACKLOG requests
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 19, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-43492Medium
    lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 19, 2026First seen at HOL Jun 19, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  45. CVE-2026-43491Medium
    net: qrtr: ns: Limit the maximum server registration per node
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 19, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  46. CVE-2026-8813High
    CISA ADP Vulnrichment
    Not scored
    exifreader, n/a/exifreadergeneric · npm
    PublishedMay 19, 2026First seen at HOL Jul 17, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-25244Critical
    WebdriverIO has Command Injection in the BrowserStack Service
    CVSS 9.8
    webdriverio/webdriveriogeneric
    PublishedMay 18, 2026First seen at HOL Jul 15, 2026Updated Jul 23, 2026View HOL analysis
  48. CVE-2026-45829Critical
    CISA ADP Vulnrichment
    CVSS 10.0
    Chroma/ChromaDBgeneric
    PublishedMay 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-20685Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Private Cloud Compute Server Softwaregeneric
    PublishedMay 18, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  50. CVE-2026-41949Medium
    Dify < 1.14.2 Authorization Bypass via File Preview Endpoint
    CVSS 5.9
    langgenius/difygeneric
    PublishedMay 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 179 of 354
Previous177178179180181Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard