HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 30, 2026, 12:49 PM 41,521 active 1,505 known exploited

Catalog summary

41,521

Active CVEs

21,389

Critical + high

1,505

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,551–9,600 of 41,521 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-80239Low
    CISA ADP Vulnrichment
    CVSS 2.4
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  2. CVE-2026-80174Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-87795High
    zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictCompress
    CVSS 8.2
    luben/zstd-jnigeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-87794High
    bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
    CVSS 8.4
    nfriedly/bestzipgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  5. CVE-2026-86777Medium
    AlchemyCMS before 7.4.16 and 8.x before 8.3.6 Missing Authorization on GET /api/nodes
    CVSS 5.3
    AlchemyCMS/alchemy_cmsgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-86776Low
    KeePass 2.35 through 2.61.1 Memory Exhaustion via KDBX Header Field Size
    CVSS 3.3
    KeePass/KeePassgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 10, 2026View HOL analysis
  7. CVE-2026-86547Medium
    mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER
    CVSS 6.2
    mrubyc/mrubycgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 10, 2026View HOL analysis
  8. CVE-2026-78377Medium
    Open Redirect in Yordam Informatics's Library Automation System
    CVSS 6.1
    Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc./Library Information and Document Automation Programgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  9. CVE-2026-19733Medium
    SSRF in Yordam Informatics's Library Automation System
    CVSS 5.3
    Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc./Library Information and Document Automation Programgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  10. CVE-2025-3271Medium
    DOM-based XSS vulnerability in OpenText™ Documentum Webtop
    CVSS 4.8
    OpenText™/Documentum Webtopgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  11. CVE-2026-11838Medium
    Improper Authorization in Yordam Informatics' Library Reservation System
    CVSS 4.3
    Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc./Library Reservation Systemgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  12. CVE-2026-79974Medium
    CISA ADP Vulnrichment
    CVSS 6.4
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  13. CVE-2026-79967Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  14. CVE-2026-87766High
    Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 22, 2026View HOL analysis
  15. CVE-2026-79973Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  16. CVE-2026-12858High
    Local privilege escalation vulnerability in ESET AV Remover
    CVSS 8.5
    ESET spol. s.r.o./ESET AV Remover (standalone)generic
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  17. CVE-2026-14989High
    Cookie Banner for GDPR / CCPA <= 4.4.1 - Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter
    CVSS 7.2
    wplegalpages/WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Modegeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  18. CVE-2026-14359High
    YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user
    CVSS 8.8
    Yith/YITH WooCommerce Waitlist Premiumgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  19. CVE-2026-80099High
    Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret
    CVSS 8.8
    Newfold/WP Module Data, Newfold/WP Plugin Bluehost +3generic
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  20. CVE-2026-79640Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  21. CVE-2025-46808Medium
    Sensitive information is leaked into NeuVector’s manager container logs
    CVSS 6.8
    SUSE/neuvectorgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-78491High
    CISA ADP Vulnrichment
    CVSS 8.2
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  23. CVE-2026-80122High
    CISA ADP Vulnrichment
    CVSS 7.3
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  24. CVE-2026-16272Critical
    Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
    CVSS 9.1
    PayTR Payment and Electronic Money Institution Inc./PayTR Virtual Pos iFrame API (v9x) WHMCS Modulegeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  25. CVE-2026-79696Critical
    Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
    CVSS 10.0
    Google Cloud/Agent Development Kit (ADK) for Pythongeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  26. CVE-2026-80175Low
    CISA ADP Vulnrichment
    CVSS 3.3
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  27. CVE-2026-78494High
    CISA ADP Vulnrichment
    CVSS 7.4
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  28. CVE-2026-79636High
    CISA ADP Vulnrichment
    CVSS 7.0
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  29. CVE-2026-80123High
    CISA ADP Vulnrichment
    CVSS 7.3
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  30. CVE-2026-80124Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  31. CVE-2026-80177Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  32. CVE-2026-80055Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  33. CVE-2026-15398Medium
    Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.22 - Authenticated (Subscriber+) Missing Authorization to Order Completion / Free Ticket Redemption
    CVSS 4.3
    arraytics/Eventin – Event Calendar, Tickets, Registration, Booking & WooCommercegeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  34. CVE-2026-17149Medium
    myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute
    CVSS 6.4
    saadiqbal/Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCredgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  35. CVE-2026-75927High
    PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant
    CVSS 7.2
    publishpress/User Role Editor – PublishPress Capabilities: Access Control and User Rolesgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 11, 2026View HOL analysis
  36. CVE-2026-19778Medium
    WPMR Google Feed Manager for WooCommerce <= 2.23.7 - Authenticated (Administrator+) SQL Injection via 'feed' Parameter
    CVSS 6.5
    aukejomm/WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shoppinggeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  37. CVE-2026-19729Medium
    Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parameters
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 16, 2026View HOL analysis
  38. CVE-2026-19802Medium
    Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via 'plugin' Parameter
    CVSS 4.3
    stylemix/Checkout Custom Fields Builder for WooCommercegeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  39. CVE-2026-87747Medium
    Ragic|Enterprise Cloud Database - Arbitrary File Read
    CVSS 4.9
    Ragic/Enterprise Cloud Databasegeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026View HOL analysis
  40. CVE-2026-85117Medium
    Contact Form 7 Captcha 0.1.7 - 0.1.8 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation
    CVSS 6.5
    Unknown/Contact Form 7 Captchageneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  41. CVE-2026-83537Medium
    WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_payment
    CVSS 5.3
    Unknown/WP Express Checkoutgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  42. CVE-2026-80440Medium
    Hustle < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution via Success Message Placeholders
    CVSS 4.8
    Unknown/Hustlegeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  43. CVE-2026-19855Medium
    Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Shortcode Execution via Comment Text
    CVSS 6.5
    Unknown/CleanTalkgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  44. CVE-2025-7062Medium
    Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
    CVSS 5.2
    Lumi Education UG/h5p-nodejs-librarygeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  45. CVE-2026-85418Medium
    Orbit Fox < 3.0.9 - Contributor+ Stored XSS via Beaver Builder Pricing Table Widget
    CVSS 5.4
    Unknown/Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & Moregeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  46. CVE-2026-85133Medium
    WPLP Cookie Consent < 4.4.2 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
    CVSS 5.4
    Unknown/WPLP Cookie Consentgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  47. CVE-2026-85132Medium
    WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan
    CVSS 4.3
    Unknown/WPLP Cookie Consentgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  48. CVE-2026-85037Medium
    Sunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOR
    CVSS 5.3
    Unknown/Sunshine Photo Cartgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  49. CVE-2026-84222Medium
    Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter
    CVSS 5.3
    Unknown/Kirkigeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-84113Medium
    Quentn WP < 1.2.15 - Admin+ SQLi via 'orderby'/'order' Parameter
    CVSS 4.1
    Unknown/Quentn WPgeneric
    PublishedSep 9, 2026First seen at HOL Sep 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
Page 192 of 831
Previous190191192193194Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard