1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:35 PM 17,658 active 1,445 known exploited

Catalog summary

17,658

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:35 PM 17,658 active 1,445 known exploited

Catalog summary

17,658

Active CVEs

8,779

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,951–9,000 of 17,658 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-41948Critical
    Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
    CVSS 9.4
    langgenius/difygeneric
    PublishedMay 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-41947Critical
    Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints
    CVSS 9.1
    langgenius/difygeneric
    PublishedMay 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-42009High
    Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMay 18, 2026First seen at HOL Jun 24, 2026Updated Jul 23, 2026View HOL analysis
  4. CVE-2023-24215Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMay 18, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-46720High
    Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections
    CVSS 8.2
    RRWO/Net::Statsd::Tinygeneric
    PublishedMay 17, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  6. CVE-2021-47952Critical
    python jsonpickle 2.0.0 Remote Code Execution via py/repr
    CVSS 9.8
    Jsonpickle/python jsonpicklegeneric
    PublishedMay 16, 2026First seen at HOL Jul 15, 2026Updated Jul 28, 2026View HOL analysis
  7. CVE-2026-46719Medium
    Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections
    CVSS 6.5
    RRWO/Net::Statsd::Litegeneric
    PublishedMay 16, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  8. CVE-2026-44774Critical
    Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
    CVSS 9.9
    traefik/traefikgeneric
    PublishedMay 15, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-45736Medium
    ws: Uninitialized memory disclosure
    CVSS 4.4
    websockets/wsgeneric
    PublishedMay 15, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  10. CVE-2026-46333High
    ptrace: slightly saner 'get_dumpable()' logic
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 15, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-43490High
    ksmbd: validate inherited ACE SID length
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 15, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-54518High
    CVE Program Container
    CVSS 7.0
    Affected software not mappedEcosystem not listed
    PublishedMay 15, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  13. CVE-2026-34253High
    CISA ADP Vulnrichment
    CVSS 8.2
    n/a/n/ageneric
    PublishedMay 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-44673High
    libyang: lyb_read_string() integer overflow → heap buffer overflow
    CVSS 7.5
    CESNET/libyanggeneric
    PublishedMay 14, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-20224High
    Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability
    CVSS 8.6
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-20210Medium
    Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
    CVSS 5.4
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  17. CVE-2026-20209Medium
    Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
    CVSS 5.4
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-20182High
    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
    Not scored Known exploited
    Cisco/Cisco Catalyst SD-WAN Controller, Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL May 24, 2026Updated Jun 16, 2026View HOL analysis
  19. CVE-2026-44216High
    Wasmtime: Panic when allocating a table exceeding the size of the host's address space
    CVSS 7.5
    bytecodealliance/wasmtimegeneric
    PublishedMay 14, 2026First seen at HOL Jul 13, 2026Updated Jul 28, 2026View HOL analysis
  20. CVE-2026-6477High
    PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedMay 14, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-42561High
    Python-Multipart: Denial of Service via unbounded multipart part headers
    CVSS 7.5
    Kludex/python-multipartgeneric
    PublishedMay 13, 2026First seen at HOL Jul 10, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-44379Medium
    MISP: Improper UUID validation in MISP Collections
    CVSS 5.3
    MISP/MISPgeneric
    PublishedMay 13, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2026-44380High
    MISP: Improper access control in auth key reset allows privilege escalation to site administrator
    CVSS 7.2
    MISP/MISPgeneric
    PublishedMay 13, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2026-44381Medium
    MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings
    CVSS 5.3
    MISP/MISPgeneric
    PublishedMay 13, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-28374Unknown severity
    IDOR in Annotations API allows unprivileged users to DELETE annotation
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  26. CVE-2026-33378Unknown severity
    Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  27. CVE-2026-28383Unknown severity
    Grafana plugin resources can lead to unbounded memory allocation
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  28. CVE-2026-33376Unknown severity
    Auth Proxy IPv6 whitelist bypass
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  29. CVE-2026-33380Medium
    SQL Expressions Read File From Disk
    Not scored
    Grafana/Grafana OSS, github.com/grafana/grafanageneric · go
    PublishedMay 13, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  30. CVE-2026-28380Unknown severity
    BAC in Snapshot API allows deletion of unauthorized dashboard snapshots
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  31. CVE-2026-33381Medium
    Users can generate Service Account tokens after permissions removal
    Not scored
    Grafana/Grafana OSS, github.com/grafana/grafanageneric · go
    PublishedMay 13, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-33377Unknown severity
    Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-28376Unknown severity
    Grafana Live push endpoint allows unbounded memory allocation leading to OOM
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  34. CVE-2026-28379Unknown severity
    Viewer-triggered race condition in Grafana Live leads to complete server crash
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  35. CVE-2026-0244High
    Prisma SD-WAN: Improper Certificate Validation Vulnerability
    CVSS 8.1
    Palo Alto Networks/Prisma SD-WAN IONgeneric
    PublishedMay 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  36. CVE-2026-0241High
    Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities
    CVSS 7.2
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  37. CVE-2026-0240High
    Trust Protection Foundation: Sensitive Information Disclosure Vulnerability
    CVSS 8.7
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-0239Medium
    Chronosphere Chronocollector Information Disclosure Vulnerability
    CVSS 6.5
    Palo Alto Networks/Chronosphere Chronocollectorgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  39. CVE-2026-44248Medium
    Netty: Resource exhaustion in MqttDecoder
    CVSS 5.3
    io.netty/netty-codec-mqtt, io.netty:netty-codec-mqtt +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 10, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  40. CVE-2026-42587High
    Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
    CVSS 7.5
    io.netty/netty-codec-http, io.netty/netty-codec-http2 +3generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 1, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-0238Low
    Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields
    CVSS 3.2
    Palo Alto Networks/Broker VMgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  42. CVE-2026-0256Unknown severity
    PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-0257High
    PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
    Not scored Known exploited
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Access +1generic
    PublishedMay 13, 2026First seen at HOL May 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-42584High
    Netty: HttpClientCodec response desynchronization
    CVSS 7.3
    io.netty/netty-codec-http, io.netty:netty-codec-http +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  45. CVE-2026-0258Unknown severity
    PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-8496Medium
    A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7
    CVSS 6.1
    Alinto SOGo/SOGogeneric
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-42579High
    Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
    CVSS 7.5
    io.netty:netty-codec-dns, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jun 11, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  48. CVE-2026-0261Unknown severity
    PAN-OS: Authenticated Admin Command Injection Vulnerability
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-42578High
    Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
    CVSS 7.5
    io.netty:netty-handler-proxy, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  50. CVE-2026-0236High
    Prisma Browser: Code Injection Enables Security Controls Bypass
    CVSS 7.8
    Palo Alto Networks/Prisma Browsergeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
Page 180 of 354
Previous178179180181182Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,779

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,951–9,000 of 17,658 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-41948Critical
    Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
    CVSS 9.4
    langgenius/difygeneric
    PublishedMay 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-41947Critical
    Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints
    CVSS 9.1
    langgenius/difygeneric
    PublishedMay 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-42009High
    Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMay 18, 2026First seen at HOL Jun 24, 2026Updated Jul 23, 2026View HOL analysis
  4. CVE-2023-24215Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMay 18, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-46720High
    Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections
    CVSS 8.2
    RRWO/Net::Statsd::Tinygeneric
    PublishedMay 17, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  6. CVE-2021-47952Critical
    python jsonpickle 2.0.0 Remote Code Execution via py/repr
    CVSS 9.8
    Jsonpickle/python jsonpicklegeneric
    PublishedMay 16, 2026First seen at HOL Jul 15, 2026Updated Jul 28, 2026View HOL analysis
  7. CVE-2026-46719Medium
    Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections
    CVSS 6.5
    RRWO/Net::Statsd::Litegeneric
    PublishedMay 16, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  8. CVE-2026-44774Critical
    Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
    CVSS 9.9
    traefik/traefikgeneric
    PublishedMay 15, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-45736Medium
    ws: Uninitialized memory disclosure
    CVSS 4.4
    websockets/wsgeneric
    PublishedMay 15, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  10. CVE-2026-46333High
    ptrace: slightly saner 'get_dumpable()' logic
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 15, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-43490High
    ksmbd: validate inherited ACE SID length
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 15, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-54518High
    CVE Program Container
    CVSS 7.0
    Affected software not mappedEcosystem not listed
    PublishedMay 15, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  13. CVE-2026-34253High
    CISA ADP Vulnrichment
    CVSS 8.2
    n/a/n/ageneric
    PublishedMay 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-44673High
    libyang: lyb_read_string() integer overflow → heap buffer overflow
    CVSS 7.5
    CESNET/libyanggeneric
    PublishedMay 14, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-20224High
    Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability
    CVSS 8.6
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-20210Medium
    Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
    CVSS 5.4
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  17. CVE-2026-20209Medium
    Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
    CVSS 5.4
    Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-20182High
    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
    Not scored Known exploited
    Cisco/Cisco Catalyst SD-WAN Controller, Cisco/Cisco Catalyst SD-WAN Managergeneric
    PublishedMay 14, 2026First seen at HOL May 24, 2026Updated Jun 16, 2026View HOL analysis
  19. CVE-2026-44216High
    Wasmtime: Panic when allocating a table exceeding the size of the host's address space
    CVSS 7.5
    bytecodealliance/wasmtimegeneric
    PublishedMay 14, 2026First seen at HOL Jul 13, 2026Updated Jul 28, 2026View HOL analysis
  20. CVE-2026-6477High
    PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedMay 14, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-42561High
    Python-Multipart: Denial of Service via unbounded multipart part headers
    CVSS 7.5
    Kludex/python-multipartgeneric
    PublishedMay 13, 2026First seen at HOL Jul 10, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-44379Medium
    MISP: Improper UUID validation in MISP Collections
    CVSS 5.3
    MISP/MISPgeneric
    PublishedMay 13, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2026-44380High
    MISP: Improper access control in auth key reset allows privilege escalation to site administrator
    CVSS 7.2
    MISP/MISPgeneric
    PublishedMay 13, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2026-44381Medium
    MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings
    CVSS 5.3
    MISP/MISPgeneric
    PublishedMay 13, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-28374Unknown severity
    IDOR in Annotations API allows unprivileged users to DELETE annotation
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  26. CVE-2026-33378Unknown severity
    Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  27. CVE-2026-28383Unknown severity
    Grafana plugin resources can lead to unbounded memory allocation
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  28. CVE-2026-33376Unknown severity
    Auth Proxy IPv6 whitelist bypass
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  29. CVE-2026-33380Medium
    SQL Expressions Read File From Disk
    Not scored
    Grafana/Grafana OSS, github.com/grafana/grafanageneric · go
    PublishedMay 13, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  30. CVE-2026-28380Unknown severity
    BAC in Snapshot API allows deletion of unauthorized dashboard snapshots
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  31. CVE-2026-33381Medium
    Users can generate Service Account tokens after permissions removal
    Not scored
    Grafana/Grafana OSS, github.com/grafana/grafanageneric · go
    PublishedMay 13, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-33377Unknown severity
    Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-28376Unknown severity
    Grafana Live push endpoint allows unbounded memory allocation leading to OOM
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  34. CVE-2026-28379Unknown severity
    Viewer-triggered race condition in Grafana Live leads to complete server crash
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMay 13, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  35. CVE-2026-0244High
    Prisma SD-WAN: Improper Certificate Validation Vulnerability
    CVSS 8.1
    Palo Alto Networks/Prisma SD-WAN IONgeneric
    PublishedMay 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  36. CVE-2026-0241High
    Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities
    CVSS 7.2
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  37. CVE-2026-0240High
    Trust Protection Foundation: Sensitive Information Disclosure Vulnerability
    CVSS 8.7
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-0239Medium
    Chronosphere Chronocollector Information Disclosure Vulnerability
    CVSS 6.5
    Palo Alto Networks/Chronosphere Chronocollectorgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  39. CVE-2026-44248Medium
    Netty: Resource exhaustion in MqttDecoder
    CVSS 5.3
    io.netty/netty-codec-mqtt, io.netty:netty-codec-mqtt +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 10, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  40. CVE-2026-42587High
    Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
    CVSS 7.5
    io.netty/netty-codec-http, io.netty/netty-codec-http2 +3generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 1, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-0238Low
    Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields
    CVSS 3.2
    Palo Alto Networks/Broker VMgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  42. CVE-2026-0256Unknown severity
    PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-0257High
    PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
    Not scored Known exploited
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Access +1generic
    PublishedMay 13, 2026First seen at HOL May 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-42584High
    Netty: HttpClientCodec response desynchronization
    CVSS 7.3
    io.netty/netty-codec-http, io.netty:netty-codec-http +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  45. CVE-2026-0258Unknown severity
    PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-8496Medium
    A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7
    CVSS 6.1
    Alinto SOGo/SOGogeneric
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-42579High
    Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
    CVSS 7.5
    io.netty:netty-codec-dns, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jun 11, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  48. CVE-2026-0261Unknown severity
    PAN-OS: Authenticated Admin Command Injection Vulnerability
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-42578High
    Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
    CVSS 7.5
    io.netty:netty-handler-proxy, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  50. CVE-2026-0236High
    Prisma Browser: Code Injection Enables Security Controls Bypass
    CVSS 7.8
    Palo Alto Networks/Prisma Browsergeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
Page 180 of 354
Previous178179180181182Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard