1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 3:15 AM 17,709 active 1,445 known exploited

Catalog summary

17,709

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 3:15 AM 17,709 active 1,445 known exploited

Catalog summary

17,709

Active CVEs

9,020

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,501–9,550 of 17,709 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-42044Medium
    Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
    CVSS 6.5
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  2. CVE-2026-42033High
    Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    CVSS 7.4
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2026-41898Medium
    rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer
    CVSS 5.3
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-41681High
    rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
    CVSS 7.5
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-41678High
    rust-openssl: Incorrect bounds assertion in aes key wrap
    CVSS 8.1
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  6. CVE-2026-41676High
    rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
    CVSS 7.5
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-41140High
    Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
    CVSS 8.7
    python-poetry/poetrygeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-40897High
    Math.js: Unsafe object property setter in mathjs
    CVSS 8.8
    josdejong/mathjsgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-31671Medium
    xfrm_user: fix info leak in build_report()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-31670Medium
    net: rfkill: prevent unlimited numbers of rfkill events from being created
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-31669Critical
    mptcp: fix slab-use-after-free in __inet_lookup_established
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  12. CVE-2026-31665High
    netfilter: nft_ct: fix use-after-free in timeout object destroy
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  13. CVE-2026-31664Medium
    xfrm: clear trailing padding in build_polexpire()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31663High
    xfrm: hold dev ref until after transport_finish NF_HOOK
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jun 19, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  15. CVE-2026-31658Medium
    net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-31651Medium
    mmc: vub300: fix NULL-deref on disconnect
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-31649Critical
    net: stmmac: fix integer underflow in chain mode
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-31641High
    rxrpc: Fix RxGK token loading to check bounds
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-31634Medium
    rxrpc: fix reference count leak in rxrpc_server_keyring()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-31628Medium
    x86/CPU: Fix FPDSS on Zen1
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-31617Medium
    usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  22. CVE-2026-31607Critical
    usbip: validate number_of_packets in usbip_pack_ret_submit()
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  23. CVE-2026-31565Medium
    RDMA/irdma: Fix deadlock during netdev reset with active connections
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-31563High
    net: macb: Use dev_consume_skb_any() to free TX SKBs
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-31555Medium
    futex: Clear stale exiting pointer in futex_lock_pi() retry path
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  26. CVE-2026-31546Medium
    net: bonding: fix NULL deref in bond_debug_rlb_hash_show
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  27. CVE-2026-41044High
    Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
    CVSS 8.8
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +4generic · maven
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-40466High
    Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
    CVSS 8.8
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +4generic · maven
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-21728High
    Tempo query limit results in unbounded memory allocation
    CVSS 7.5
    Grafana/Enterprise Traces (GET), Grafana/Tempo +1generic · go
    PublishedApr 24, 2026First seen at HOL Jun 29, 2026Updated Aug 11, 2026View HOL analysis
  30. CVE-2026-40886High
    Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
    CVSS 7.7
    argoproj/argo-workflowsgeneric
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-31533Critical
    net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  32. CVE-2026-34003High
    Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-34001High
    Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-33999High
    Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2025-13763Medium
    Libopensc: opensc: multiple uses of uninitialized variable
    CVSS 5.7
    OpenSC/OpenSCgeneric
    PublishedApr 23, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  36. CVE-2026-41989Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  37. CVE-2026-41907Low
    CISA ADP Vulnrichment
    CVSS 3.2
    uuid, uuidjs/uuidgeneric · npm
    PublishedApr 23, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-41988Low
    CISA ADP Vulnrichment
    CVSS 3.2
    uuid, uuidjs/uuidgeneric · npm
    PublishedApr 23, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-41179Critical
    RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
    CVSS 9.8
    github.com/ncw/rclone, github.com/rclone/rclone +1generic · go
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  40. CVE-2026-39087Medium
    CISA ADP Vulnrichment
    CVSS 6.4
    ntfy/ntfygeneric
    PublishedApr 23, 2026First seen at HOL Jul 4, 2026Updated Jul 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-41176Critical
    Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
    CVSS 9.8
    rclone/rclonegeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-31521Medium
    module: Fix kernel panic when a symbol st_shndx is out of bounds
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-31518Medium
    esp: fix skb leak with espintcp and async crypto
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-31515Medium
    af_key: validate families in pfkey_send_migrate()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-31508High
    net: openvswitch: Avoid releasing netdev before teardown completes
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-31507High
    net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-31504High
    net: fix fanout UAF in packet_release() via NETDEV_UP race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-31503Medium
    udp: Fix wildcard bind conflict check when using hash2
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-31496Medium
    netfilter: nf_conntrack_expect: skip expectations in other netns via proc
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2026-31495Medium
    netfilter: ctnetlink: use netlink policy range checks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 191 of 355
Previous189190191192193Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,020

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,501–9,550 of 17,709 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-42044Medium
    Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
    CVSS 6.5
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  2. CVE-2026-42033High
    Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    CVSS 7.4
    axios/axiosgeneric
    PublishedApr 24, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2026-41898Medium
    rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer
    CVSS 5.3
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-41681High
    rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
    CVSS 7.5
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-41678High
    rust-openssl: Incorrect bounds assertion in aes key wrap
    CVSS 8.1
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  6. CVE-2026-41676High
    rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
    CVSS 7.5
    rust-openssl/rust-opensslgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-41140High
    Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
    CVSS 8.7
    python-poetry/poetrygeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-40897High
    Math.js: Unsafe object property setter in mathjs
    CVSS 8.8
    josdejong/mathjsgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-31671Medium
    xfrm_user: fix info leak in build_report()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-31670Medium
    net: rfkill: prevent unlimited numbers of rfkill events from being created
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-31669Critical
    mptcp: fix slab-use-after-free in __inet_lookup_established
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  12. CVE-2026-31665High
    netfilter: nft_ct: fix use-after-free in timeout object destroy
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  13. CVE-2026-31664Medium
    xfrm: clear trailing padding in build_polexpire()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31663High
    xfrm: hold dev ref until after transport_finish NF_HOOK
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jun 19, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  15. CVE-2026-31658Medium
    net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-31651Medium
    mmc: vub300: fix NULL-deref on disconnect
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-31649Critical
    net: stmmac: fix integer underflow in chain mode
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-31641High
    rxrpc: Fix RxGK token loading to check bounds
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-31634Medium
    rxrpc: fix reference count leak in rxrpc_server_keyring()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-31628Medium
    x86/CPU: Fix FPDSS on Zen1
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-31617Medium
    usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  22. CVE-2026-31607Critical
    usbip: validate number_of_packets in usbip_pack_ret_submit()
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  23. CVE-2026-31565Medium
    RDMA/irdma: Fix deadlock during netdev reset with active connections
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-31563High
    net: macb: Use dev_consume_skb_any() to free TX SKBs
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-31555Medium
    futex: Clear stale exiting pointer in futex_lock_pi() retry path
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  26. CVE-2026-31546Medium
    net: bonding: fix NULL deref in bond_debug_rlb_hash_show
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 24, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  27. CVE-2026-41044High
    Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
    CVSS 8.8
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +4generic · maven
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-40466High
    Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
    CVSS 8.8
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +4generic · maven
    PublishedApr 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-21728High
    Tempo query limit results in unbounded memory allocation
    CVSS 7.5
    Grafana/Enterprise Traces (GET), Grafana/Tempo +1generic · go
    PublishedApr 24, 2026First seen at HOL Jun 29, 2026Updated Aug 11, 2026View HOL analysis
  30. CVE-2026-40886High
    Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
    CVSS 7.7
    argoproj/argo-workflowsgeneric
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-31533Critical
    net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  32. CVE-2026-34003High
    Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-34001High
    Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-33999High
    Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2025-13763Medium
    Libopensc: opensc: multiple uses of uninitialized variable
    CVSS 5.7
    OpenSC/OpenSCgeneric
    PublishedApr 23, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  36. CVE-2026-41989Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  37. CVE-2026-41907Low
    CISA ADP Vulnrichment
    CVSS 3.2
    uuid, uuidjs/uuidgeneric · npm
    PublishedApr 23, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-41988Low
    CISA ADP Vulnrichment
    CVSS 3.2
    uuid, uuidjs/uuidgeneric · npm
    PublishedApr 23, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-41179Critical
    RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
    CVSS 9.8
    github.com/ncw/rclone, github.com/rclone/rclone +1generic · go
    PublishedApr 23, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  40. CVE-2026-39087Medium
    CISA ADP Vulnrichment
    CVSS 6.4
    ntfy/ntfygeneric
    PublishedApr 23, 2026First seen at HOL Jul 4, 2026Updated Jul 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-41176Critical
    Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
    CVSS 9.8
    rclone/rclonegeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-31521Medium
    module: Fix kernel panic when a symbol st_shndx is out of bounds
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-31518Medium
    esp: fix skb leak with espintcp and async crypto
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-31515Medium
    af_key: validate families in pfkey_send_migrate()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-31508High
    net: openvswitch: Avoid releasing netdev before teardown completes
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-31507High
    net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-31504High
    net: fix fanout UAF in packet_release() via NETDEV_UP race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-31503Medium
    udp: Fix wildcard bind conflict check when using hash2
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-31496Medium
    netfilter: nf_conntrack_expect: skip expectations in other netns via proc
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2026-31495Medium
    netfilter: ctnetlink: use netlink policy range checks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 191 of 355
Previous189190191192193Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard