1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 3:20 AM 17,709 active 1,445 known exploited

Catalog summary

17,709

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 3:20 AM 17,709 active 1,445 known exploited

Catalog summary

17,709

Active CVEs

9,020

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,551–9,600 of 17,709 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-31494High
    net: macb: use the current queue number for stats
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-31489High
    spi: meson-spicc: Fix double-put in remove path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  3. CVE-2026-31488High
    drm/amd/display: Do not skip unrelated mode changes in DSC validation
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 10, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  4. CVE-2026-31486High
    hwmon: (pmbus/core) Protect regulator operations with mutex
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  5. CVE-2026-31485High
    spi: spi-fsl-lpspi: fix teardown order issue (UAF)
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-31474High
    can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  7. CVE-2026-31469High
    virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-31466Medium
    mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
    CVSS 4.7
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-31452High
    ext4: convert inline data to extents when truncate exceeds inline size
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-31450High
    ext4: publish jinode after initialization
    CVSS 8.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-31449High
    ext4: validate p_idx bounds in ext4_ext_correct_indexes
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  12. CVE-2026-31448Critical
    ext4: avoid infinite loops caused by residual data
    CVSS 9.4
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  13. CVE-2026-31447High
    ext4: reject mount if bigalloc with s_first_data_block != 0
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31446High
    ext4: fix use-after-free in update_super_work when racing with umount
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-31441Medium
    dmaengine: idxd: Fix memory leak when a wq is reset
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-41651High
    PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
    CVSS 8.8
    PackageKit/PackageKitgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-31432High
    ksmbd: fix OOB write in QUERY_INFO for compound requests
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  18. CVE-2026-31431High
    crypto: algif_aead - Revert to operating out-of-place
    CVSS 7.8 Known exploited
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedApr 22, 2026First seen at HOL May 24, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-6845Medium
    Binutils: binutils: denial of service via crafted elf file
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedApr 22, 2026First seen at HOL Jul 2, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-6235Critical
    Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests
    CVSS 9.8
    sendmachine/Sendmachine for WordPressgeneric
    PublishedApr 22, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-40542High
    Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
    CVSS 7.3
    Apache Software Foundation/Apache HttpClientgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2026-22754High
    ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
    CVSS 7.5
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-22747Medium
    Unauthorized User Impersonation when Using X.509 Client Certificates
    CVSS 6.8
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-40575Critical
    OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
    CVSS 9.1
    oauth2-proxy/oauth2-proxygeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-40938High
    Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
    CVSS 7.5
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedApr 21, 2026First seen at HOL Jul 8, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  26. CVE-2026-34282High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-22016High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-40906Critical
    Electric: SQL Injection via ORDER BY Parameter in Shape API
    CVSS 9.9
    electric-sql/electricgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-40895High
    follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets
    CVSS 7.5
    follow-redirects/follow-redirectsgeneric
    PublishedApr 21, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  30. CVE-2026-33813High
    Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/webpgeneric
    PublishedApr 21, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  31. CVE-2026-40372Critical
    ASP.NET Core Elevation of Privilege Vulnerability
    CVSS 9.1
    Microsoft/ASP.NET Core 10.0, Microsoft/Microsoft Visual Studio 2026 version 18.5generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  32. CVE-2026-40611High
    Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
    CVSS 8.8
    go-acme/legogeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-3298High
    Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
    CVSS 8.8
    Python Software Foundation/CPythongeneric
    PublishedApr 21, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-40244High
    OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)
    CVSS 7.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-31018High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  36. CVE-2026-31019High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  37. CVE-2026-22051Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    NETAPP/StorageGRID (formerly StorageGRID Webscale)generic
    PublishedApr 20, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-5450Critical
    scanf %mc off-by-one heap buffer overflow
    CVSS 9.8
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-5928High
    Potential buffer under-read in ungetwc
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-35154Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    Dell/PowerProtect Data Domain appliancesgeneric
    PublishedApr 20, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  41. CVE-2026-41245Medium
    Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
    CVSS 5.9
    junrar/junrargeneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  42. CVE-2026-33557Critical
    Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
    CVSS 9.1
    Apache Software Foundation/Apache Kafkageneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-30266High
    CISA ADP Vulnrichment
    CVSS 7.8
    n/a/n/ageneric
    PublishedApr 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2026-41242Critical
    protobufjs has an arbitrary code execution issue
    CVSS 9.8
    protobufjs/protobuf.jsgeneric
    PublishedApr 18, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-40478Critical
    Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  46. CVE-2026-40477Critical
    Improper restriction of the scope of accessible objects in Thymeleaf expressions
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  47. CVE-2026-40293Medium
    OpenFGA Playground Preshared Key Exposure
    CVSS 6.5
    openfga/openfgageneric
    PublishedApr 17, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026View HOL analysis
  48. CVE-2026-40066High
    Anviz Products Download of Code Without Integrity Check
    CVSS 8.8
    Anviz/Anviz CX2 Lite Firmware, Anviz/Anviz CX7 Firmwaregeneric
    PublishedApr 17, 2026First seen at HOL Jul 11, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-31927Medium
    Anviz CX7 Firmware Relative Path Traversal
    CVSS 4.9
    Anviz/Anviz CX7 Firmwaregeneric
    PublishedApr 17, 2026First seen at HOL Jul 11, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-21733High
    GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so)
    CVSS 7.3
    Imagination Technologies/Graphics DDKgeneric
    PublishedApr 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
Page 192 of 355
Previous190191192193194Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,020

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,551–9,600 of 17,709 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-31494High
    net: macb: use the current queue number for stats
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-31489High
    spi: meson-spicc: Fix double-put in remove path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  3. CVE-2026-31488High
    drm/amd/display: Do not skip unrelated mode changes in DSC validation
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 10, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  4. CVE-2026-31486High
    hwmon: (pmbus/core) Protect regulator operations with mutex
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  5. CVE-2026-31485High
    spi: spi-fsl-lpspi: fix teardown order issue (UAF)
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-31474High
    can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  7. CVE-2026-31469High
    virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-31466Medium
    mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
    CVSS 4.7
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-31452High
    ext4: convert inline data to extents when truncate exceeds inline size
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-31450High
    ext4: publish jinode after initialization
    CVSS 8.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-31449High
    ext4: validate p_idx bounds in ext4_ext_correct_indexes
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  12. CVE-2026-31448Critical
    ext4: avoid infinite loops caused by residual data
    CVSS 9.4
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  13. CVE-2026-31447High
    ext4: reject mount if bigalloc with s_first_data_block != 0
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31446High
    ext4: fix use-after-free in update_super_work when racing with umount
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-31441Medium
    dmaengine: idxd: Fix memory leak when a wq is reset
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-41651High
    PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
    CVSS 8.8
    PackageKit/PackageKitgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-31432High
    ksmbd: fix OOB write in QUERY_INFO for compound requests
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  18. CVE-2026-31431High
    crypto: algif_aead - Revert to operating out-of-place
    CVSS 7.8 Known exploited
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedApr 22, 2026First seen at HOL May 24, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-6845Medium
    Binutils: binutils: denial of service via crafted elf file
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedApr 22, 2026First seen at HOL Jul 2, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-6235Critical
    Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests
    CVSS 9.8
    sendmachine/Sendmachine for WordPressgeneric
    PublishedApr 22, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-40542High
    Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
    CVSS 7.3
    Apache Software Foundation/Apache HttpClientgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2026-22754High
    ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
    CVSS 7.5
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-22747Medium
    Unauthorized User Impersonation when Using X.509 Client Certificates
    CVSS 6.8
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-40575Critical
    OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
    CVSS 9.1
    oauth2-proxy/oauth2-proxygeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-40938High
    Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
    CVSS 7.5
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedApr 21, 2026First seen at HOL Jul 8, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  26. CVE-2026-34282High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-22016High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-40906Critical
    Electric: SQL Injection via ORDER BY Parameter in Shape API
    CVSS 9.9
    electric-sql/electricgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-40895High
    follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets
    CVSS 7.5
    follow-redirects/follow-redirectsgeneric
    PublishedApr 21, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  30. CVE-2026-33813High
    Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/webpgeneric
    PublishedApr 21, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  31. CVE-2026-40372Critical
    ASP.NET Core Elevation of Privilege Vulnerability
    CVSS 9.1
    Microsoft/ASP.NET Core 10.0, Microsoft/Microsoft Visual Studio 2026 version 18.5generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  32. CVE-2026-40611High
    Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
    CVSS 8.8
    go-acme/legogeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-3298High
    Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
    CVSS 8.8
    Python Software Foundation/CPythongeneric
    PublishedApr 21, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-40244High
    OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)
    CVSS 7.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-31018High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  36. CVE-2026-31019High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  37. CVE-2026-22051Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    NETAPP/StorageGRID (formerly StorageGRID Webscale)generic
    PublishedApr 20, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-5450Critical
    scanf %mc off-by-one heap buffer overflow
    CVSS 9.8
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-5928High
    Potential buffer under-read in ungetwc
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-35154Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    Dell/PowerProtect Data Domain appliancesgeneric
    PublishedApr 20, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  41. CVE-2026-41245Medium
    Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
    CVSS 5.9
    junrar/junrargeneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  42. CVE-2026-33557Critical
    Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
    CVSS 9.1
    Apache Software Foundation/Apache Kafkageneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-30266High
    CISA ADP Vulnrichment
    CVSS 7.8
    n/a/n/ageneric
    PublishedApr 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2026-41242Critical
    protobufjs has an arbitrary code execution issue
    CVSS 9.8
    protobufjs/protobuf.jsgeneric
    PublishedApr 18, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-40478Critical
    Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  46. CVE-2026-40477Critical
    Improper restriction of the scope of accessible objects in Thymeleaf expressions
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  47. CVE-2026-40293Medium
    OpenFGA Playground Preshared Key Exposure
    CVSS 6.5
    openfga/openfgageneric
    PublishedApr 17, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026View HOL analysis
  48. CVE-2026-40066High
    Anviz Products Download of Code Without Integrity Check
    CVSS 8.8
    Anviz/Anviz CX2 Lite Firmware, Anviz/Anviz CX7 Firmwaregeneric
    PublishedApr 17, 2026First seen at HOL Jul 11, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-31927Medium
    Anviz CX7 Firmware Relative Path Traversal
    CVSS 4.9
    Anviz/Anviz CX7 Firmwaregeneric
    PublishedApr 17, 2026First seen at HOL Jul 11, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-21733High
    GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so)
    CVSS 7.3
    Imagination Technologies/Graphics DDKgeneric
    PublishedApr 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
Page 192 of 355
Previous190191192193194Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard