1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 10:35 PM 17,673 active 1,445 known exploited

Catalog summary

17,673

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 10:35 PM 17,673 active 1,445 known exploited

Catalog summary

17,673

Active CVEs

8,891

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,001–9,050 of 17,673 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-0241High
    Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities
    CVSS 7.2
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  2. CVE-2026-0240High
    Trust Protection Foundation: Sensitive Information Disclosure Vulnerability
    CVSS 8.7
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  3. CVE-2026-0239Medium
    Chronosphere Chronocollector Information Disclosure Vulnerability
    CVSS 6.5
    Palo Alto Networks/Chronosphere Chronocollectorgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  4. CVE-2026-44248Medium
    Netty: Resource exhaustion in MqttDecoder
    CVSS 5.3
    io.netty/netty-codec-mqtt, io.netty:netty-codec-mqtt +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 10, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  5. CVE-2026-42587High
    Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
    CVSS 7.5
    io.netty/netty-codec-http, io.netty/netty-codec-http2 +3generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 1, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-0238Low
    Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields
    CVSS 3.2
    Palo Alto Networks/Broker VMgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-0256Unknown severity
    PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-0257High
    PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
    Not scored Known exploited
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Access +1generic
    PublishedMay 13, 2026First seen at HOL May 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-42584High
    Netty: HttpClientCodec response desynchronization
    CVSS 7.3
    io.netty/netty-codec-http, io.netty:netty-codec-http +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  10. CVE-2026-0258Unknown severity
    PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-8496Medium
    A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7
    CVSS 6.1
    Alinto SOGo/SOGogeneric
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-42579High
    Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
    CVSS 7.5
    io.netty:netty-codec-dns, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jun 11, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  13. CVE-2026-0261Unknown severity
    PAN-OS: Authenticated Admin Command Injection Vulnerability
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-42578High
    Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
    CVSS 7.5
    io.netty:netty-handler-proxy, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  15. CVE-2026-0236High
    Prisma Browser: Code Injection Enables Security Controls Bypass
    CVSS 7.8
    Palo Alto Networks/Prisma Browsergeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  16. CVE-2026-42581Medium
    Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
    CVSS 5.8
    io.netty:netty-codec-http, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-0262Unknown severity
    PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Access +1generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-0237High
    Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
    CVSS 7.8
    Palo Alto Networks/Prisma Browsergeneric
    PublishedMay 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-0263Critical
    PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
    CVSS 9.8
    Palo Alto Networks/PAN-OSgeneric
    PublishedMay 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-44005Critical
    vm2: Sandbox escape
    CVSS 10.0
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-0264Unknown severity
    PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-45411Critical
    vm2: Sandbox Breakout Using Async Generator
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-0265Unknown severity
    PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-44009Critical
    vm2: Sandbox Breakout Through Null Proto Exception
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-44008Critical
    vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-44007Critical
    vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution
    CVSS 9.1
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-44006Critical
    vm2: Sandbox Escape
    CVSS 10.0
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-44004High
    vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)
    CVSS 7.5
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-44001High
    vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
    CVSS 8.6
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-43999Critical
    vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape
    CVSS 9.9
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-43998High
    vm2: NodeVM require.root bypass via symlink traversal allows sandbox escape
    CVSS 8.5
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-43997Critical
    vm2: Sandbox Escape
    CVSS 10.0
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-45109High
    Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  34. CVE-2026-44579High
    Next.js: Denial of Service via connection exhaustion in applications using Cache Components
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-44578High
    Next.js: Server-side request forgery in applications using WebSocket upgrades
    CVSS 8.6
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  36. CVE-2026-44577Medium
    Next.js: Denial of Service in the Image Optimization API
    CVSS 5.9
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  37. CVE-2026-44574High
    Next.js: Middleware / Proxy bypass through dynamic route parameter injection
    CVSS 8.1
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-44575High
    Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 31, 2026View HOL analysis
  39. CVE-2026-44573High
    Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  40. CVE-2026-44431Medium
    urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    CVSS 5.3
    urllib3/urllib3generic
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  41. CVE-2026-44432High
    urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
    CVSS 7.5
    urllib3, urllib3/urllib3generic · pip
    PublishedMay 13, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  42. CVE-2026-43489Medium
    liveupdate: luo_file: remember retrieve() status
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  43. CVE-2026-43488Medium
    usb: xhci: Prevent interrupt storm on host controller error (HCE)
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  44. CVE-2026-43487Medium
    ata: libata-core: Disable LPM on ST1000DM010-2EP102
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  45. CVE-2026-43486Medium
    arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  46. CVE-2026-43485Medium
    nouveau/gsp: drop WARN_ON in ACPI probes
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  47. CVE-2026-43484Medium
    mmc: core: Avoid bitfield RMW for claim/retune flags
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  48. CVE-2026-43483Medium
    KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  49. CVE-2026-43482Medium
    sched_ext: Disable preemption between scx_claim_exit() and kicking helper work
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  50. CVE-2026-43481High
    net-shapers: don't free reply skb after genlmsg_reply()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 181 of 354
Previous179180181182183Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,891

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,001–9,050 of 17,673 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-0241High
    Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities
    CVSS 7.2
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  2. CVE-2026-0240High
    Trust Protection Foundation: Sensitive Information Disclosure Vulnerability
    CVSS 8.7
    Palo Alto Networks/Trust Protection Foundationgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  3. CVE-2026-0239Medium
    Chronosphere Chronocollector Information Disclosure Vulnerability
    CVSS 6.5
    Palo Alto Networks/Chronosphere Chronocollectorgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  4. CVE-2026-44248Medium
    Netty: Resource exhaustion in MqttDecoder
    CVSS 5.3
    io.netty/netty-codec-mqtt, io.netty:netty-codec-mqtt +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 10, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  5. CVE-2026-42587High
    Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
    CVSS 7.5
    io.netty/netty-codec-http, io.netty/netty-codec-http2 +3generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 1, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-0238Low
    Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields
    CVSS 3.2
    Palo Alto Networks/Broker VMgeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-0256Unknown severity
    PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-0257High
    PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
    Not scored Known exploited
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Access +1generic
    PublishedMay 13, 2026First seen at HOL May 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-42584High
    Netty: HttpClientCodec response desynchronization
    CVSS 7.3
    io.netty/netty-codec-http, io.netty:netty-codec-http +1generic · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  10. CVE-2026-0258Unknown severity
    PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-8496Medium
    A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7
    CVSS 6.1
    Alinto SOGo/SOGogeneric
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-42579High
    Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
    CVSS 7.5
    io.netty:netty-codec-dns, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jun 11, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  13. CVE-2026-0261Unknown severity
    PAN-OS: Authenticated Admin Command Injection Vulnerability
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-42578High
    Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
    CVSS 7.5
    io.netty:netty-handler-proxy, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  15. CVE-2026-0236High
    Prisma Browser: Code Injection Enables Security Controls Bypass
    CVSS 7.8
    Palo Alto Networks/Prisma Browsergeneric
    PublishedMay 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  16. CVE-2026-42581Medium
    Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
    CVSS 5.8
    io.netty:netty-codec-http, netty/nettygeneric · maven
    PublishedMay 13, 2026First seen at HOL Jul 9, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-0262Unknown severity
    PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Access +1generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-0237High
    Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
    CVSS 7.8
    Palo Alto Networks/Prisma Browsergeneric
    PublishedMay 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-0263Critical
    PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
    CVSS 9.8
    Palo Alto Networks/PAN-OSgeneric
    PublishedMay 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-44005Critical
    vm2: Sandbox escape
    CVSS 10.0
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-0264Unknown severity
    PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-45411Critical
    vm2: Sandbox Breakout Using Async Generator
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-0265Unknown severity
    PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
    Not scoredSource severity not reported
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 13, 2026First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-44009Critical
    vm2: Sandbox Breakout Through Null Proto Exception
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-44008Critical
    vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-44007Critical
    vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution
    CVSS 9.1
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-44006Critical
    vm2: Sandbox Escape
    CVSS 10.0
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-44004High
    vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)
    CVSS 7.5
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-44001High
    vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
    CVSS 8.6
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-43999Critical
    vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape
    CVSS 9.9
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-43998High
    vm2: NodeVM require.root bypass via symlink traversal allows sandbox escape
    CVSS 8.5
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-43997Critical
    vm2: Sandbox Escape
    CVSS 10.0
    patriksimek/vm2generic
    PublishedMay 13, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-45109High
    Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  34. CVE-2026-44579High
    Next.js: Denial of Service via connection exhaustion in applications using Cache Components
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-44578High
    Next.js: Server-side request forgery in applications using WebSocket upgrades
    CVSS 8.6
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  36. CVE-2026-44577Medium
    Next.js: Denial of Service in the Image Optimization API
    CVSS 5.9
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  37. CVE-2026-44574High
    Next.js: Middleware / Proxy bypass through dynamic route parameter injection
    CVSS 8.1
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-44575High
    Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 31, 2026View HOL analysis
  39. CVE-2026-44573High
    Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
    CVSS 7.5
    vercel/next.jsgeneric
    PublishedMay 13, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  40. CVE-2026-44431Medium
    urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    CVSS 5.3
    urllib3/urllib3generic
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  41. CVE-2026-44432High
    urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
    CVSS 7.5
    urllib3, urllib3/urllib3generic · pip
    PublishedMay 13, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  42. CVE-2026-43489Medium
    liveupdate: luo_file: remember retrieve() status
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  43. CVE-2026-43488Medium
    usb: xhci: Prevent interrupt storm on host controller error (HCE)
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  44. CVE-2026-43487Medium
    ata: libata-core: Disable LPM on ST1000DM010-2EP102
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  45. CVE-2026-43486Medium
    arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  46. CVE-2026-43485Medium
    nouveau/gsp: drop WARN_ON in ACPI probes
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  47. CVE-2026-43484Medium
    mmc: core: Avoid bitfield RMW for claim/retune flags
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  48. CVE-2026-43483Medium
    KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  49. CVE-2026-43482Medium
    sched_ext: Disable preemption between scx_claim_exit() and kicking helper work
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  50. CVE-2026-43481High
    net-shapers: don't free reply skb after genlmsg_reply()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 13, 2026First seen at HOL Jun 26, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 181 of 354
Previous179180181182183Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard