1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 12:30 AM 17,692 active 1,445 known exploited

Catalog summary

17,692

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 12:30 AM 17,692 active 1,445 known exploited

Catalog summary

17,692

Active CVEs

8,947

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,251–9,300 of 17,692 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-42208Critical
    LiteLLM: SQL injection in Proxy API key verification
    CVSS 9.8 Known exploited
    BerriAI/litellmgeneric
    PublishedMay 8, 2026First seen at HOL May 24, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-42203High
    LiteLLM: Server-Side Template Injection in /prompts/test endpoint
    CVSS 8.8
    BerriAI/litellmgeneric
    PublishedMay 8, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-42264High
    Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
    CVSS 7.4
    axios/axiosgeneric
    PublishedMay 8, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026View HOL analysis
  4. CVE-2026-42880Critical
    ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
    CVSS 9.6
    argoproj/Argo CD, argoproj/argo-cd +3generic · go
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  5. CVE-2026-43824Critical
    ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
    CVSS 9.6
    argoproj/Argo CD, argoproj/argo-cd +3generic · go
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  6. CVE-2026-7891Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Siemens/Mendix Runtimegeneric
    PublishedMay 7, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-39820High
    Quadratic string concatentation in consumeComment in net/mail
    CVSS 7.5
    Go standard library/net/mailgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  8. CVE-2026-33811High
    Crash when handling long CNAME response in net
    CVSS 7.5
    Go standard library/netgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  9. CVE-2026-42499High
    Quadratic string concatenation in consumePhrase in net/mail
    CVSS 7.5
    Go standard library/net/mailgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  10. CVE-2026-33814High
    Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
    CVSS 7.5
    Go standard library/net/http, golang.org/x/net +2generic · go
    PublishedMay 7, 2026First seen at HOL Jul 2, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  11. CVE-2026-43510Medium
    CISA manage.get.gov insecure portfolio administrative privileges
    CVSS 5.9
    CISA/manage.get.govgeneric
    PublishedMay 7, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  12. CVE-2026-42011High
    Gnutls: gnutls: security bypass due to incorrect name constraint handling
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMay 7, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  13. CVE-2026-8091Critical
    Incorrect boundary conditions in the Audio/Video: Playback component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  14. CVE-2026-42010High
    Gnutls: gnutls: authentication bypass via nul character in username
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedMay 7, 2026First seen at HOL Jun 24, 2026Updated Jul 23, 2026View HOL analysis
  15. CVE-2026-41139High
    Unsafe array index getter in mathjs
    CVSS 8.8
    josdejong/mathjs, mathjsgeneric · npm
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-42216Critical
    OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion
    CVSS 9.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedMay 7, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-41142High
    OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API
    CVSS 8.8
    AcademySoftwareFoundation/openexrgeneric
    PublishedMay 7, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-41675High
    xmldom: XML node injection through unvalidated processing instruction serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 6, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-41674High
    xmldom: XML injection through unvalidated DocumentType serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  20. CVE-2026-41673High
    xmldom: Denial of service via uncontrolled recursion in XML serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-41672High
    xmldom: XML node injection through unvalidated comment serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 6, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-36387Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 7, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  23. CVE-2026-36388Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 7, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2026-0300High
    PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
    Not scored Known exploited
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 6, 2026First seen at HOL May 24, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-33079High
    Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
    CVSS 7.5
    lepture/mistunegeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  26. CVE-2026-20034High
    Cisco Unity Connection Remote Code Execution Vulnerability
    CVSS 8.8
    Cisco/Cisco Unity Connectiongeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-20035High
    Cisco Unity Connection Server-Side Request Forgery Vulnerability
    CVSS 7.2
    Cisco/Cisco Unity Connectiongeneric
    PublishedMay 6, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-20167High
    Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
    CVSS 7.7
    Cisco/Cisco IoT Field Network Director (IoT-FND)generic
    PublishedMay 6, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  29. CVE-2026-20169Medium
    Cisco IoT Field Network Director Command Injection Vulnerability
    CVSS 6.4
    Cisco/Cisco IoT Field Network Director (IoT-FND)generic
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-20168Medium
    Cisco IoT Field Network Director Path Traversal Vulnerability
    CVSS 6.5
    Cisco/Cisco IoT Field Network Director (IoT-FND)generic
    PublishedMay 6, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2026-20189Medium
    Cisco Prime Infrastructure Information Disclosure Vulnerability
    CVSS 4.3
    Cisco/Cisco Prime Infrastructuregeneric
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-20193Medium
    Cisco Identity Services Engine Authentication Bypass Vulnerability
    CVSS 4.3
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  33. CVE-2026-20195Medium
    Cisco Identity Services Engine Observable Response Discrepancy Vulnerability
    CVSS 5.3
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  34. CVE-2026-6788High
    Uncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard Agent
    CVSS 7.8
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-6787High
    Usage of a hard-coded cryptographic key in WatchGuard Agent allows inclusion of code into existing process
    CVSS 7.8
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-41286Medium
    Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant B
    CVSS 6.5
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  37. CVE-2026-41288High
    WatchGuard Agent on Windows Privilege Escalation Vulnerability
    CVSS 7.8
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  38. CVE-2025-31976Medium
    HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials
    CVSS 4.8
    HCL Software/BigFix Service Management (SM)generic
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  39. CVE-2025-31978Medium
    HCL BigFix Service Management (SM) does not adequately sanitize or safely render
    CVSS 4.6
    HCL Software/BigFix Service Management (SM)generic
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2026-41287Medium
    Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant A
    CVSS 6.5
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  41. CVE-2026-43283Unknown severity
    net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-43280Unknown severity
    drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-43279Unknown severity
    ALSA: usb-audio: Add sanity check for OOB writes at silencing
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-43278Unknown severity
    dm: clear cloned request bio pointer when last clone bio completes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-43274Unknown severity
    mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-43263Unknown severity
    media: chips-media: wave5: Fix Null reference while testing fluster
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-43258Unknown severity
    alpha: fix user-space corruption during memory compaction
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-43256Unknown severity
    media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-43254Unknown severity
    ovpn: tcp - fix packet extraction from stream
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-43253Unknown severity
    iommu/amd: move wait_on_sem() out of spinlock
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 186 of 354
Previous184185186187188Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,947

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,251–9,300 of 17,692 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-42208Critical
    LiteLLM: SQL injection in Proxy API key verification
    CVSS 9.8 Known exploited
    BerriAI/litellmgeneric
    PublishedMay 8, 2026First seen at HOL May 24, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-42203High
    LiteLLM: Server-Side Template Injection in /prompts/test endpoint
    CVSS 8.8
    BerriAI/litellmgeneric
    PublishedMay 8, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-42264High
    Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
    CVSS 7.4
    axios/axiosgeneric
    PublishedMay 8, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026View HOL analysis
  4. CVE-2026-42880Critical
    ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
    CVSS 9.6
    argoproj/Argo CD, argoproj/argo-cd +3generic · go
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  5. CVE-2026-43824Critical
    ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
    CVSS 9.6
    argoproj/Argo CD, argoproj/argo-cd +3generic · go
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  6. CVE-2026-7891Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Siemens/Mendix Runtimegeneric
    PublishedMay 7, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-39820High
    Quadratic string concatentation in consumeComment in net/mail
    CVSS 7.5
    Go standard library/net/mailgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  8. CVE-2026-33811High
    Crash when handling long CNAME response in net
    CVSS 7.5
    Go standard library/netgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  9. CVE-2026-42499High
    Quadratic string concatenation in consumePhrase in net/mail
    CVSS 7.5
    Go standard library/net/mailgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  10. CVE-2026-33814High
    Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
    CVSS 7.5
    Go standard library/net/http, golang.org/x/net +2generic · go
    PublishedMay 7, 2026First seen at HOL Jul 2, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  11. CVE-2026-43510Medium
    CISA manage.get.gov insecure portfolio administrative privileges
    CVSS 5.9
    CISA/manage.get.govgeneric
    PublishedMay 7, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  12. CVE-2026-42011High
    Gnutls: gnutls: security bypass due to incorrect name constraint handling
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMay 7, 2026First seen at HOL Jun 24, 2026Updated Jul 22, 2026View HOL analysis
  13. CVE-2026-8091Critical
    Incorrect boundary conditions in the Audio/Video: Playback component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  14. CVE-2026-42010High
    Gnutls: gnutls: authentication bypass via nul character in username
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedMay 7, 2026First seen at HOL Jun 24, 2026Updated Jul 23, 2026View HOL analysis
  15. CVE-2026-41139High
    Unsafe array index getter in mathjs
    CVSS 8.8
    josdejong/mathjs, mathjsgeneric · npm
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-42216Critical
    OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion
    CVSS 9.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedMay 7, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-41142High
    OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API
    CVSS 8.8
    AcademySoftwareFoundation/openexrgeneric
    PublishedMay 7, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-41675High
    xmldom: XML node injection through unvalidated processing instruction serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 6, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-41674High
    xmldom: XML injection through unvalidated DocumentType serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  20. CVE-2026-41673High
    xmldom: Denial of service via uncontrolled recursion in XML serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 1, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-41672High
    xmldom: XML node injection through unvalidated comment serialization
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedMay 7, 2026First seen at HOL Jul 6, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-36387Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 7, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  23. CVE-2026-36388Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 7, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2026-0300High
    PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
    Not scored Known exploited
    Palo Alto Networks/PAN-OS, Siemens/RUGGEDCOM APE1808generic
    PublishedMay 6, 2026First seen at HOL May 24, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-33079High
    Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
    CVSS 7.5
    lepture/mistunegeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  26. CVE-2026-20034High
    Cisco Unity Connection Remote Code Execution Vulnerability
    CVSS 8.8
    Cisco/Cisco Unity Connectiongeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-20035High
    Cisco Unity Connection Server-Side Request Forgery Vulnerability
    CVSS 7.2
    Cisco/Cisco Unity Connectiongeneric
    PublishedMay 6, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-20167High
    Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
    CVSS 7.7
    Cisco/Cisco IoT Field Network Director (IoT-FND)generic
    PublishedMay 6, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  29. CVE-2026-20169Medium
    Cisco IoT Field Network Director Command Injection Vulnerability
    CVSS 6.4
    Cisco/Cisco IoT Field Network Director (IoT-FND)generic
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-20168Medium
    Cisco IoT Field Network Director Path Traversal Vulnerability
    CVSS 6.5
    Cisco/Cisco IoT Field Network Director (IoT-FND)generic
    PublishedMay 6, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2026-20189Medium
    Cisco Prime Infrastructure Information Disclosure Vulnerability
    CVSS 4.3
    Cisco/Cisco Prime Infrastructuregeneric
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-20193Medium
    Cisco Identity Services Engine Authentication Bypass Vulnerability
    CVSS 4.3
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  33. CVE-2026-20195Medium
    Cisco Identity Services Engine Observable Response Discrepancy Vulnerability
    CVSS 5.3
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  34. CVE-2026-6788High
    Uncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard Agent
    CVSS 7.8
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-6787High
    Usage of a hard-coded cryptographic key in WatchGuard Agent allows inclusion of code into existing process
    CVSS 7.8
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-41286Medium
    Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant B
    CVSS 6.5
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  37. CVE-2026-41288High
    WatchGuard Agent on Windows Privilege Escalation Vulnerability
    CVSS 7.8
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  38. CVE-2025-31976Medium
    HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials
    CVSS 4.8
    HCL Software/BigFix Service Management (SM)generic
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  39. CVE-2025-31978Medium
    HCL BigFix Service Management (SM) does not adequately sanitize or safely render
    CVSS 4.6
    HCL Software/BigFix Service Management (SM)generic
    PublishedMay 6, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2026-41287Medium
    Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service - Variant A
    CVSS 6.5
    WatchGuard/WatchGuard Agentgeneric
    PublishedMay 6, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  41. CVE-2026-43283Unknown severity
    net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-43280Unknown severity
    drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-43279Unknown severity
    ALSA: usb-audio: Add sanity check for OOB writes at silencing
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-43278Unknown severity
    dm: clear cloned request bio pointer when last clone bio completes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-43274Unknown severity
    mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-43263Unknown severity
    media: chips-media: wave5: Fix Null reference while testing fluster
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-43258Unknown severity
    alpha: fix user-space corruption during memory compaction
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-43256Unknown severity
    media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-43254Unknown severity
    ovpn: tcp - fix packet extraction from stream
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-43253Unknown severity
    iommu/amd: move wait_on_sem() out of spinlock
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 186 of 354
Previous184185186187188Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard