1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 1:20 AM 17,699 active 1,445 known exploited

Catalog summary

17,699

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 1:20 AM 17,699 active 1,445 known exploited

Catalog summary

17,699

Active CVEs

8,947

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,351–9,400 of 17,699 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-43129Medium
    ima: verify the previous kernel's IMA buffer lies in addressable RAM
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  2. CVE-2026-43128Unknown severity
    RDMA/umem: Fix double dma_buf_unpin in failure path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-43126Unknown severity
    ALSA: mixer: oss: Add card disconnect checkpoints
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-43125Critical
    dlm: validate length in dlm_search_rsb_tree
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-43120Unknown severity
    RDMA/irdma: Fix double free related to rereg_user_mr
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-43117Unknown severity
    btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-43116High
    netfilter: ctnetlink: ensure safe access to master conntrack
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-43114Critical
    netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
    CVSS 9.4
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jul 15, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-43113Unknown severity
    wifi: wl1251: validate packet IDs before indexing tx_frames
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-43112High
    fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jul 3, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  11. CVE-2026-43088Medium
    net: af_key: zero aligned sockaddr tail in PF_KEY exports
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  12. CVE-2026-36358Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 6, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  13. CVE-2026-28780Critical
    Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
    CVSS 9.8
    Apache Software Foundation/Apache HTTP Servergeneric
    PublishedMay 5, 2026First seen at HOL Jul 8, 2026Updated Jul 28, 2026View HOL analysis
  14. CVE-2026-41950Medium
    Dify < 1.14.0 Authorization Bypass via File UUID
    CVSS 6.5
    langgenius/difygeneric
    PublishedMay 5, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-35579Critical
    CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports
    CVSS 9.8
    coredns/corednsgeneric
    PublishedMay 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-25243High
    redis-server RESTORE invalid memory access may allow remote code execution
    CVSS 8.8
    redis/redisgeneric
    PublishedMay 5, 2026First seen at HOL Jun 30, 2026Updated Jul 16, 2026View HOL analysis
  17. CVE-2026-23631High
    redis-server Lua use-after-free may allow remote code execution
    CVSS 8.1
    redis/redisgeneric
    PublishedMay 5, 2026First seen at HOL Jun 30, 2026Updated Jul 16, 2026View HOL analysis
  18. CVE-2026-23479High
    redis-server use-after-free in unblock client flow may allow remote code execution
    CVSS 8.8
    redis/redisgeneric
    PublishedMay 5, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  19. CVE-2026-43064Medium
    dmaengine: idxd: Fix not releasing workqueue on .release()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 5, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  20. CVE-2026-6322High
    fast-uri vulnerable to host confusion via percent-encoded authority delimiters
    CVSS 7.5
    fast-uri, fast-uri/fast-urigeneric · npm
    PublishedMay 5, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  21. CVE-2026-43868Medium
    Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
    CVSS 5.3
    Apache Software Foundation/Apache Thriftgeneric
    PublishedMay 5, 2026First seen at HOL Jul 6, 2026Updated Jul 22, 2026 Fix availableView HOL analysis
  22. CVE-2026-43869High
    Apache Thrift: TSSLTransportFactory.java hostname verification
    CVSS 7.3
    Apache Software Foundation/Apache Thrift, org.apache.thrift:libthriftgeneric · maven
    PublishedMay 5, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2025-52206Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    n/a/n/ageneric
    PublishedMay 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2026-36355High
    CISA ADP Vulnrichment
    CVSS 7.7
    n/a/n/ageneric
    PublishedMay 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2026-36356Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMay 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2026-42997High
    CISA ADP Vulnrichment
    CVSS 7.7
    OpenStack/Ironicgeneric
    PublishedMay 5, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-42154High
    Prometheus: remote read endpoint allows denial of service via crafted snappy payload
    CVSS 7.5
    github.com/prometheus/prometheus, github.com/prometheus/prometheus/v2 +1generic · go
    PublishedMay 4, 2026First seen at HOL Jun 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  28. CVE-2026-42151High
    Prometheus Azure AD remote write OAuth client secret exposed via config API
    CVSS 7.5
    github.com/prometheus/prometheus, prometheus/prometheusgeneric · go
    PublishedMay 4, 2026First seen at HOL Jul 2, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  29. CVE-2026-43964Low
    CISA ADP Vulnrichment
    CVSS 3.7
    Postfix/Postfixgeneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-29004High
    BusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS
    CVSS 8.1
    vda-linux/busybox_mirrorgeneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2026-40682Critical
    Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
    CVSS 9.1
    Apache Software Foundation/Apache OpenNLPgeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  32. CVE-2026-24082High
    Use After Free in Automotive GPU
    CVSS 7.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-42027Critical
    Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
    CVSS 9.8
    Apache Software Foundation/Apache OpenNLPgeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  34. CVE-2026-42440High
    Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
    CVSS 7.5
    Apache Software Foundation/Apache OpenNLPgeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  35. CVE-2026-26332Critical
    vm2: Sandbox Escape
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-24781Critical
    vm2: Sandbox Breakout Through Inspect
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-24120Critical
    vm2: Sandbox Breakout Through Promise Species
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-24118Critical
    VM2 Sandbox Breakout Through __lookupGetter__
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-23918High
    Apache HTTP Server: http2: double free and possible RCE on early reset
    CVSS 8.8
    Apache Software Foundation/Apache HTTP Servergeneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-33846High
    Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMay 4, 2026First seen at HOL Jun 24, 2026Updated Jul 20, 2026View HOL analysis
  41. CVE-2025-70067Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  42. CVE-2025-70069High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2025-70070Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2025-70071Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2025-70072Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-37459High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-43057High
    net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 1, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-43052High
    wifi: mac80211: check tdls flag in ieee80211_tdls_oper
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 1, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  49. CVE-2026-43040High
    net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 1, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2026-43038Critical
    ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 1, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 188 of 354
Previous186187188189190Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,947

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,351–9,400 of 17,699 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-43129Medium
    ima: verify the previous kernel's IMA buffer lies in addressable RAM
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  2. CVE-2026-43128Unknown severity
    RDMA/umem: Fix double dma_buf_unpin in failure path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-43126Unknown severity
    ALSA: mixer: oss: Add card disconnect checkpoints
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-43125Critical
    dlm: validate length in dlm_search_rsb_tree
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-43120Unknown severity
    RDMA/irdma: Fix double free related to rereg_user_mr
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-43117Unknown severity
    btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-43116High
    netfilter: ctnetlink: ensure safe access to master conntrack
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-43114Critical
    netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
    CVSS 9.4
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jul 15, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-43113Unknown severity
    wifi: wl1251: validate packet IDs before indexing tx_frames
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-43112High
    fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jul 3, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  11. CVE-2026-43088Medium
    net: af_key: zero aligned sockaddr tail in PF_KEY exports
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 6, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  12. CVE-2026-36358Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 6, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  13. CVE-2026-28780Critical
    Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
    CVSS 9.8
    Apache Software Foundation/Apache HTTP Servergeneric
    PublishedMay 5, 2026First seen at HOL Jul 8, 2026Updated Jul 28, 2026View HOL analysis
  14. CVE-2026-41950Medium
    Dify < 1.14.0 Authorization Bypass via File UUID
    CVSS 6.5
    langgenius/difygeneric
    PublishedMay 5, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-35579Critical
    CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports
    CVSS 9.8
    coredns/corednsgeneric
    PublishedMay 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-25243High
    redis-server RESTORE invalid memory access may allow remote code execution
    CVSS 8.8
    redis/redisgeneric
    PublishedMay 5, 2026First seen at HOL Jun 30, 2026Updated Jul 16, 2026View HOL analysis
  17. CVE-2026-23631High
    redis-server Lua use-after-free may allow remote code execution
    CVSS 8.1
    redis/redisgeneric
    PublishedMay 5, 2026First seen at HOL Jun 30, 2026Updated Jul 16, 2026View HOL analysis
  18. CVE-2026-23479High
    redis-server use-after-free in unblock client flow may allow remote code execution
    CVSS 8.8
    redis/redisgeneric
    PublishedMay 5, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  19. CVE-2026-43064Medium
    dmaengine: idxd: Fix not releasing workqueue on .release()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMay 5, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  20. CVE-2026-6322High
    fast-uri vulnerable to host confusion via percent-encoded authority delimiters
    CVSS 7.5
    fast-uri, fast-uri/fast-urigeneric · npm
    PublishedMay 5, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  21. CVE-2026-43868Medium
    Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
    CVSS 5.3
    Apache Software Foundation/Apache Thriftgeneric
    PublishedMay 5, 2026First seen at HOL Jul 6, 2026Updated Jul 22, 2026 Fix availableView HOL analysis
  22. CVE-2026-43869High
    Apache Thrift: TSSLTransportFactory.java hostname verification
    CVSS 7.3
    Apache Software Foundation/Apache Thrift, org.apache.thrift:libthriftgeneric · maven
    PublishedMay 5, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2025-52206Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    n/a/n/ageneric
    PublishedMay 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2026-36355High
    CISA ADP Vulnrichment
    CVSS 7.7
    n/a/n/ageneric
    PublishedMay 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2026-36356Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMay 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2026-42997High
    CISA ADP Vulnrichment
    CVSS 7.7
    OpenStack/Ironicgeneric
    PublishedMay 5, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-42154High
    Prometheus: remote read endpoint allows denial of service via crafted snappy payload
    CVSS 7.5
    github.com/prometheus/prometheus, github.com/prometheus/prometheus/v2 +1generic · go
    PublishedMay 4, 2026First seen at HOL Jun 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  28. CVE-2026-42151High
    Prometheus Azure AD remote write OAuth client secret exposed via config API
    CVSS 7.5
    github.com/prometheus/prometheus, prometheus/prometheusgeneric · go
    PublishedMay 4, 2026First seen at HOL Jul 2, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  29. CVE-2026-43964Low
    CISA ADP Vulnrichment
    CVSS 3.7
    Postfix/Postfixgeneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-29004High
    BusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS
    CVSS 8.1
    vda-linux/busybox_mirrorgeneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2026-40682Critical
    Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
    CVSS 9.1
    Apache Software Foundation/Apache OpenNLPgeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  32. CVE-2026-24082High
    Use After Free in Automotive GPU
    CVSS 7.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-42027Critical
    Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
    CVSS 9.8
    Apache Software Foundation/Apache OpenNLPgeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  34. CVE-2026-42440High
    Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
    CVSS 7.5
    Apache Software Foundation/Apache OpenNLPgeneric
    PublishedMay 4, 2026First seen at HOL Jun 29, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  35. CVE-2026-26332Critical
    vm2: Sandbox Escape
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-24781Critical
    vm2: Sandbox Breakout Through Inspect
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-24120Critical
    vm2: Sandbox Breakout Through Promise Species
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-24118Critical
    VM2 Sandbox Breakout Through __lookupGetter__
    CVSS 9.8
    patriksimek/vm2generic
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-23918High
    Apache HTTP Server: http2: double free and possible RCE on early reset
    CVSS 8.8
    Apache Software Foundation/Apache HTTP Servergeneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-33846High
    Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMay 4, 2026First seen at HOL Jun 24, 2026Updated Jul 20, 2026View HOL analysis
  41. CVE-2025-70067Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  42. CVE-2025-70069High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2025-70070Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2025-70071Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2025-70072Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-37459High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMay 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-43057High
    net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 1, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-43052High
    wifi: mac80211: check tdls flag in ieee80211_tdls_oper
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedMay 1, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  49. CVE-2026-43040High
    net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 1, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2026-43038Critical
    ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 1, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 188 of 354
Previous186187188189190Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard