1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 2:23 AM 17,704 active 1,445 known exploited

Catalog summary

17,704

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 2:23 AM 17,704 active 1,445 known exploited

Catalog summary

17,704

Active CVEs

9,020

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,451–9,500 of 17,704 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-6238Medium
    Buffer overread in ns_printrrf with corrupted RDATA field
    CVSS 6.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 28, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-5435High
    Potential buffer overflow in ns_sprintrrf TSIG handling path
    CVSS 7.3
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 28, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-41607Medium
    Apache Thrift: C++ JSON OOB read
    CVSS 6.5
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  4. CVE-2026-41606Medium
    Apache Thrift: c_glib dispatch stack overflow
    CVSS 5.3
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  5. CVE-2026-41605High
    Apache Thrift: Swift Compact Protocol integer overflow
    CVSS 7.3
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-41604High
    Apache Thrift: Swift Range crash in skip()
    CVSS 8.2
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-41602High
    Apache Thrift: Go TFramedTransport uint32 overflow
    CVSS 7.5
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  8. CVE-2025-48431High
    Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
    CVSS 7.5
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  9. CVE-2024-54013High
    Authentication Bypass
    CVSS 8.8
    Hanwha Vision/QND-8080Rgeneric
    PublishedApr 28, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  10. CVE-2024-54012Medium
    Command Injection
    CVSS 5.3
    Hanwha Vision/QND-8080Rgeneric
    PublishedApr 28, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  11. CVE-2024-54011Medium
    Missing Error/Exception Handling
    CVSS 6.5
    Hanwha Vision/QND-8080Rgeneric
    PublishedApr 28, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  12. CVE-2026-1460High
    CISA ADP Vulnrichment
    CVSS 7.2
    Zyxel/DX3301-T0 firmware, Zyxel/EX3301-T0 firmwaregeneric
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  13. CVE-2026-0711Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Zyxel/DX3300-T0 firmwaregeneric
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2025-60887Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedApr 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  15. CVE-2025-60889Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  16. CVE-2026-40355Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    MIT/Kerberos 5, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-40356Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    MIT/Kerberos 5generic
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-42167High
    CISA ADP Vulnrichment
    CVSS 8.1
    ProFTPD/ProFTPDgeneric
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-40976Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Spring/Spring Boot, org.springframework.boot:spring-bootgeneric · maven
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-40975Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    Spring/Spring Bootgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  21. CVE-2026-3087High
    shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
    CVSS 7.5
    Python Software Foundation/CPythongeneric
    PublishedApr 27, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-27172High
    Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store
    CVSS 8.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-33453Critical
    Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
    CVSS 10.0
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-33454Critical
    Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)
    CVSS 9.4
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-40022High
    Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime
    CVSS 8.2
    Apache Software Foundation/Apache Camel Platform HTTP Maingeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  26. CVE-2026-40858High
    Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
    CVSS 8.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-40453Critical
    Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
    CVSS 9.9
    Apache Software Foundation/Apache Camel CoAP, Apache Software Foundation/Apache Camel Google PubSub +1generic
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-40860Critical
    Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-40048High
    Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
    CVSS 7.8
    Apache Software Foundation/Apache Camel PQCgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-40473High
    Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
    CVSS 8.8
    Apache Software Foundation/Apache Camel Minageneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2026-3006High
    Race Condition Vulnerability
    CVSS 7.0
    WinFSP/WinFSPgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-30352Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2026-30462Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2026-38934High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2026-38935Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  36. CVE-2026-38936Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  37. CVE-2026-31682Critical
    bridge: br_nd_send: linearize skb before parsing ND options
    CVSS 9.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-31680High
    net: ipv6: flowlabel: defer exclusive option free until RCU teardown
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-31674High
    netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-41473Critical
    CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints
    CVSS 9.1
    usmannasir/cyberpanelgeneric
    PublishedApr 24, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  41. CVE-2026-41472Medium
    CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard
    CVSS 6.1
    usmannasir/cyberpanelgeneric
    PublishedApr 24, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  42. CVE-2026-41326High
    Kata Containers: CopyFile Policy Subversion via Symlinks
    CVSS 8.2
    kata-containers/kata-containersgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-42039High
    Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedApr 24, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-42041Medium
    Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
    CVSS 4.8
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  45. CVE-2026-42043High
    Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
    CVSS 7.2
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  46. CVE-2026-42044Medium
    Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
    CVSS 6.5
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  47. CVE-2026-42033High
    Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    CVSS 7.4
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  48. CVE-2026-41898Medium
    rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer
    CVSS 5.3
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-41681High
    rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
    CVSS 7.5
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-41678High
    rust-openssl: Incorrect bounds assertion in aes key wrap
    CVSS 8.1
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 190 of 355
Previous188189190191192Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,020

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,451–9,500 of 17,704 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-6238Medium
    Buffer overread in ns_printrrf with corrupted RDATA field
    CVSS 6.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 28, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-5435High
    Potential buffer overflow in ns_sprintrrf TSIG handling path
    CVSS 7.3
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 28, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-41607Medium
    Apache Thrift: C++ JSON OOB read
    CVSS 6.5
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  4. CVE-2026-41606Medium
    Apache Thrift: c_glib dispatch stack overflow
    CVSS 5.3
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  5. CVE-2026-41605High
    Apache Thrift: Swift Compact Protocol integer overflow
    CVSS 7.3
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-41604High
    Apache Thrift: Swift Range crash in skip()
    CVSS 8.2
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-41602High
    Apache Thrift: Go TFramedTransport uint32 overflow
    CVSS 7.5
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 9, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  8. CVE-2025-48431High
    Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
    CVSS 7.5
    Apache Software Foundation/Apache Thriftgeneric
    PublishedApr 28, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  9. CVE-2024-54013High
    Authentication Bypass
    CVSS 8.8
    Hanwha Vision/QND-8080Rgeneric
    PublishedApr 28, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  10. CVE-2024-54012Medium
    Command Injection
    CVSS 5.3
    Hanwha Vision/QND-8080Rgeneric
    PublishedApr 28, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  11. CVE-2024-54011Medium
    Missing Error/Exception Handling
    CVSS 6.5
    Hanwha Vision/QND-8080Rgeneric
    PublishedApr 28, 2026First seen at HOL Jun 27, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  12. CVE-2026-1460High
    CISA ADP Vulnrichment
    CVSS 7.2
    Zyxel/DX3301-T0 firmware, Zyxel/EX3301-T0 firmwaregeneric
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  13. CVE-2026-0711Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Zyxel/DX3300-T0 firmwaregeneric
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2025-60887Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedApr 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  15. CVE-2025-60889Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  16. CVE-2026-40355Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    MIT/Kerberos 5, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-40356Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    MIT/Kerberos 5generic
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-42167High
    CISA ADP Vulnrichment
    CVSS 8.1
    ProFTPD/ProFTPDgeneric
    PublishedApr 28, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-40976Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Spring/Spring Boot, org.springframework.boot:spring-bootgeneric · maven
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-40975Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    Spring/Spring Bootgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  21. CVE-2026-3087High
    shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
    CVSS 7.5
    Python Software Foundation/CPythongeneric
    PublishedApr 27, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-27172High
    Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store
    CVSS 8.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-33453Critical
    Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
    CVSS 10.0
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-33454Critical
    Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)
    CVSS 9.4
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-40022High
    Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime
    CVSS 8.2
    Apache Software Foundation/Apache Camel Platform HTTP Maingeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  26. CVE-2026-40858High
    Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
    CVSS 8.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-40453Critical
    Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
    CVSS 9.9
    Apache Software Foundation/Apache Camel CoAP, Apache Software Foundation/Apache Camel Google PubSub +1generic
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-40860Critical
    Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-40048High
    Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
    CVSS 7.8
    Apache Software Foundation/Apache Camel PQCgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-40473High
    Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
    CVSS 8.8
    Apache Software Foundation/Apache Camel Minageneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2026-3006High
    Race Condition Vulnerability
    CVSS 7.0
    WinFSP/WinFSPgeneric
    PublishedApr 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-30352Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2026-30462Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2026-38934High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2026-38935Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  36. CVE-2026-38936Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  37. CVE-2026-31682Critical
    bridge: br_nd_send: linearize skb before parsing ND options
    CVSS 9.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-31680High
    net: ipv6: flowlabel: defer exclusive option free until RCU teardown
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-31674High
    netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-41473Critical
    CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints
    CVSS 9.1
    usmannasir/cyberpanelgeneric
    PublishedApr 24, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  41. CVE-2026-41472Medium
    CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard
    CVSS 6.1
    usmannasir/cyberpanelgeneric
    PublishedApr 24, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  42. CVE-2026-41326High
    Kata Containers: CopyFile Policy Subversion via Symlinks
    CVSS 8.2
    kata-containers/kata-containersgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-42039High
    Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
    CVSS 7.5
    axios, axios/axiosgeneric · npm
    PublishedApr 24, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-42041Medium
    Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
    CVSS 4.8
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  45. CVE-2026-42043High
    Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
    CVSS 7.2
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  46. CVE-2026-42044Medium
    Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
    CVSS 6.5
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  47. CVE-2026-42033High
    Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    CVSS 7.4
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  48. CVE-2026-41898Medium
    rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer
    CVSS 5.3
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-41681High
    rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
    CVSS 7.5
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-41678High
    rust-openssl: Incorrect bounds assertion in aes key wrap
    CVSS 8.1
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 190 of 355
Previous188189190191192Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard