1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 4:20 PM 16,250 active 1,443 known exploited

Catalog summary

16,250

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 4:20 PM 16,250 active 1,443 known exploited

Catalog summary

16,250

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 901–950 of 16,250 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-7456Medium
    Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action
    CVSS 6.5
    webocoders/Udimi Toolsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  2. CVE-2026-71227Medium
    Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-71294High
    Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions
    CVSS 7.6
    Cotonti/Cotontigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  4. CVE-2026-71293Medium
    Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable
    CVSS 6.2
    statamic/cmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  5. CVE-2026-71292High
    Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter
    CVSS 7.2
    intelliants/subriongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  6. CVE-2026-71291High
    Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering
    CVSS 8.8
    bolt/coregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  7. CVE-2026-71226High
    Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-71289Critical
    NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API
    CVSS 9.8
    NASA-AMMOS/anmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  9. CVE-2026-71288High
    Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.pl
    CVSS 8.8
    Koha Community/Kohageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  10. CVE-2026-71287High
    Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Blind SQL Injection
    CVSS 8.8
    Cacti/cactigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  11. CVE-2026-71286Medium
    ember-dynamic-render-template Client-Side Template Injection via Unsanitized templateString
    CVSS 6.1
    miguelcobain/ember-dynamic-render-templategeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  12. CVE-2026-71285High
    Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages
    CVSS 8.1
    louislam/uptime-kumageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  13. CVE-2026-71284High
    Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename
    CVSS 7.2
    fledge-iot/fledgegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  14. CVE-2026-71283Medium
    Fledge IoT Gateway Backup Restore Tar Path Traversal
    CVSS 4.9
    fledge-iot/fledgegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  15. CVE-2026-71282Medium
    ChirpStack SQLite Backend SQL Injection via Device Tag Key in ListDevices Filter
    CVSS 6.5
    chirpstack/chirpstackgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-71281High
    peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA and CorDA Modules
    CVSS 8.8
    huggingface/peftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-71280High
    go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch
    CVSS 8.5
    go-shiori/shiorigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-71279High
    Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Execution
    CVSS 8.0
    Koenkk/zigbee2mqttgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  19. CVE-2026-71278Critical
    rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation
    CVSS 9.8
    iot-ecology/rust-iot-platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  20. CVE-2026-71277Critical
    rust-iot-platform Authentication Bypass via Non-Validated Authorization Header
    CVSS 9.1
    iot-ecology/rust-iot-platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-71276High
    Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Parameter
    CVSS 7.1
    absmach/magistralageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-71275Medium
    OpenBK7231T Reflected XSS via OTA host Parameter
    CVSS 5.4
    openshwprojects/OpenBK7231T_Appgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  23. CVE-2026-71274High
    OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels
    CVSS 8.5
    openshwprojects/OpenBK7231T_Appgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-71273Medium
    OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable and WiFi Hijack
    CVSS 6.5
    openshwprojects/OpenBK7231T_Appgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  25. CVE-2026-71272High
    Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()
    CVSS 8.5
    usememos/memosgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  26. CVE-2026-71271High
    Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass
    CVSS 8.5
    usememos/memosgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  27. CVE-2026-71270High
    Stirling-PDF Server-Side Request Forgery via /api/v1/convert/url/pdf WeasyPrint Subprocess
    CVSS 8.6
    Stirling-Tools/Stirling-PDFgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-71269High
    Node-RED Library API Path Traversal Leading to Arbitrary File Read/Write
    CVSS 7.2
    node-red/node-redgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-71268Critical
    OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write
    CVSS 9.9
    thiagoralves/OpenPLC_v3generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  30. CVE-2026-71267Critical
    microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()
    CVSS 9.8
    rxi/microtargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  31. CVE-2026-71266High
    tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing
    CVSS 7.8
    syoyo/tinyobjloader-cgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-71265High
    Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy()
    CVSS 7.5
    domoticz/domoticzgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-71264High
    WLED Unauthenticated Configuration Disclosure via /json/cfg and Global Settings-PIN Lock State
    CVSS 8.2
    Aircoookie/WLEDgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-71263Critical
    FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool()
    CVSS 9.1
    cwalter-at/FreeModbusgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-71262Critical
    IoTSharp BlobStorageController Missing Authentication and Path Traversal
    CVSS 9.8
    IoTSharp/IoTSharpgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-71261High
    dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buffer Overflow on 32-bit Builds
    CVSS 7.8
    mackron/dr_libsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-71260Medium
    ESPHome web_server Plaintext Password Disclosure via JSON "value" Field
    CVSS 6.5
    esphome/esphomegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-71259High
    ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution
    CVSS 8.6
    esphome/esphomegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-71225Medium
    Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-16022High
    Command Injection in @oblique/cli
    CVSS 7.8
    Swiss Federal Office of Information Technology, Systems and Telecommunication/@oblique/cligeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-0516Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    SonicWall/SonicOSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-71256Critical
    nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id
    CVSS 9.8
    debevv/nanoMODBUSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  43. CVE-2026-71255High
    nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res()
    CVSS 8.6
    debevv/nanoMODBUSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-71254Critical
    nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record()
    CVSS 9.8
    debevv/nanoMODBUSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-18933High
    wp-downloadmanager: Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal
    CVSS 7.2
    wp-downloadmanager/wp-downloadmanagergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64582Unknown severity
    RDMA/rxe: Fix a use-after-free problem in rxe_mmap
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  47. CVE-2026-46581High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Mojarrageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-61891High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Theiageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-60009High
    CISA ADP Vulnrichment
    CVSS 8.8
    Eclipse Foundation/Eclipse Theiageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-71252High
    toner-management: Unauthenticated State-Changing Admin Actions
    CVSS 8.2
    raghav993/toner-managementgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
Page 19 of 325
Previous1718192021Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 901–950 of 16,250 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-7456Medium
    Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action
    CVSS 6.5
    webocoders/Udimi Toolsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  2. CVE-2026-71227Medium
    Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-71294High
    Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions
    CVSS 7.6
    Cotonti/Cotontigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  4. CVE-2026-71293Medium
    Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable
    CVSS 6.2
    statamic/cmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  5. CVE-2026-71292High
    Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter
    CVSS 7.2
    intelliants/subriongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  6. CVE-2026-71291High
    Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering
    CVSS 8.8
    bolt/coregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  7. CVE-2026-71226High
    Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-71289Critical
    NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API
    CVSS 9.8
    NASA-AMMOS/anmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  9. CVE-2026-71288High
    Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.pl
    CVSS 8.8
    Koha Community/Kohageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  10. CVE-2026-71287High
    Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Blind SQL Injection
    CVSS 8.8
    Cacti/cactigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  11. CVE-2026-71286Medium
    ember-dynamic-render-template Client-Side Template Injection via Unsanitized templateString
    CVSS 6.1
    miguelcobain/ember-dynamic-render-templategeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  12. CVE-2026-71285High
    Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages
    CVSS 8.1
    louislam/uptime-kumageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  13. CVE-2026-71284High
    Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename
    CVSS 7.2
    fledge-iot/fledgegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  14. CVE-2026-71283Medium
    Fledge IoT Gateway Backup Restore Tar Path Traversal
    CVSS 4.9
    fledge-iot/fledgegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  15. CVE-2026-71282Medium
    ChirpStack SQLite Backend SQL Injection via Device Tag Key in ListDevices Filter
    CVSS 6.5
    chirpstack/chirpstackgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-71281High
    peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA and CorDA Modules
    CVSS 8.8
    huggingface/peftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-71280High
    go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch
    CVSS 8.5
    go-shiori/shiorigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-71279High
    Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Execution
    CVSS 8.0
    Koenkk/zigbee2mqttgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  19. CVE-2026-71278Critical
    rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation
    CVSS 9.8
    iot-ecology/rust-iot-platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  20. CVE-2026-71277Critical
    rust-iot-platform Authentication Bypass via Non-Validated Authorization Header
    CVSS 9.1
    iot-ecology/rust-iot-platformgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-71276High
    Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Parameter
    CVSS 7.1
    absmach/magistralageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-71275Medium
    OpenBK7231T Reflected XSS via OTA host Parameter
    CVSS 5.4
    openshwprojects/OpenBK7231T_Appgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  23. CVE-2026-71274High
    OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels
    CVSS 8.5
    openshwprojects/OpenBK7231T_Appgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-71273Medium
    OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable and WiFi Hijack
    CVSS 6.5
    openshwprojects/OpenBK7231T_Appgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  25. CVE-2026-71272High
    Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()
    CVSS 8.5
    usememos/memosgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  26. CVE-2026-71271High
    Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass
    CVSS 8.5
    usememos/memosgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  27. CVE-2026-71270High
    Stirling-PDF Server-Side Request Forgery via /api/v1/convert/url/pdf WeasyPrint Subprocess
    CVSS 8.6
    Stirling-Tools/Stirling-PDFgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-71269High
    Node-RED Library API Path Traversal Leading to Arbitrary File Read/Write
    CVSS 7.2
    node-red/node-redgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-71268Critical
    OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write
    CVSS 9.9
    thiagoralves/OpenPLC_v3generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  30. CVE-2026-71267Critical
    microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()
    CVSS 9.8
    rxi/microtargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  31. CVE-2026-71266High
    tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing
    CVSS 7.8
    syoyo/tinyobjloader-cgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-71265High
    Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy()
    CVSS 7.5
    domoticz/domoticzgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-71264High
    WLED Unauthenticated Configuration Disclosure via /json/cfg and Global Settings-PIN Lock State
    CVSS 8.2
    Aircoookie/WLEDgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-71263Critical
    FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool()
    CVSS 9.1
    cwalter-at/FreeModbusgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-71262Critical
    IoTSharp BlobStorageController Missing Authentication and Path Traversal
    CVSS 9.8
    IoTSharp/IoTSharpgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-71261High
    dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buffer Overflow on 32-bit Builds
    CVSS 7.8
    mackron/dr_libsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-71260Medium
    ESPHome web_server Plaintext Password Disclosure via JSON "value" Field
    CVSS 6.5
    esphome/esphomegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-71259High
    ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution
    CVSS 8.6
    esphome/esphomegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-71225Medium
    Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-16022High
    Command Injection in @oblique/cli
    CVSS 7.8
    Swiss Federal Office of Information Technology, Systems and Telecommunication/@oblique/cligeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-0516Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    SonicWall/SonicOSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-71256Critical
    nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id
    CVSS 9.8
    debevv/nanoMODBUSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  43. CVE-2026-71255High
    nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res()
    CVSS 8.6
    debevv/nanoMODBUSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-71254Critical
    nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record()
    CVSS 9.8
    debevv/nanoMODBUSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-18933High
    wp-downloadmanager: Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal
    CVSS 7.2
    wp-downloadmanager/wp-downloadmanagergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64582Unknown severity
    RDMA/rxe: Fix a use-after-free problem in rxe_mmap
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  47. CVE-2026-46581High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Mojarrageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-61891High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Theiageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-60009High
    CISA ADP Vulnrichment
    CVSS 8.8
    Eclipse Foundation/Eclipse Theiageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-71252High
    toner-management: Unauthenticated State-Changing Admin Actions
    CVSS 8.2
    raghav993/toner-managementgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
Page 19 of 325
Previous1718192021Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard