1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 4:04 AM 17,710 active 1,445 known exploited

Catalog summary

17,710

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 4:04 AM 17,710 active 1,445 known exploited

Catalog summary

17,710

Active CVEs

9,081

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,601–9,650 of 17,710 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-21733High
    GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so)
    CVSS 7.3
    Imagination Technologies/Graphics DDKgeneric
    PublishedApr 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  2. CVE-2026-35073Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  3. CVE-2026-35074Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  4. CVE-2026-35072Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  5. CVE-2026-35153Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  6. CVE-2026-40002Medium
    ZTE Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations.
    CVSS 5.0
    ZTE/Red Magic 11 Pro (NX809J)generic
    PublishedApr 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-4525High
    Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
    CVSS 7.5
    HashiCorp/Vault, HashiCorp/Vault Enterprisegeneric
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2026-3605High
    Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
    CVSS 8.1
    HashiCorp/Vault, HashiCorp/Vault Enterprisegeneric
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  9. CVE-2026-40170High
    ngtcp2 has a qlog transport parameter serialization stack buffer overflow
    CVSS 7.5
    ngtcp2/ngtcp2generic
    PublishedApr 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-35469High
    SpdyStream: DOS on CRI
    CVSS 6.5
    github.com/moby/spdystream, moby/spdystreamgeneric · go
    PublishedApr 16, 2026First seen at HOL Jun 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  11. CVE-2025-54502High
    CISA ADP Vulnrichment
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-41082High
    CISA ADP Vulnrichment
    CVSS 7.3
    OCaml/opamgeneric
    PublishedApr 16, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-41080Low
    CISA ADP Vulnrichment
    CVSS 2.9
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31843Critical
    goodoneuz/pay-uz Unauthenticated PHP File Overwrite via /payment/api/editable/update Leading to Remote Code Execution
    CVSS 9.8
    goodoneuz/pay-uzcomposer · generic
    PublishedApr 16, 2026First seen at HOL Aug 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-41035High
    CISA ADP Vulnrichment
    CVSS 7.4
    Samba/rsyncgeneric
    PublishedApr 16, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-3861Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedApr 16, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  17. CVE-2026-30459High
    CISA ADP Vulnrichment
    CVSS 7.1
    n/a/n/ageneric
    PublishedApr 16, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  18. CVE-2026-40192High
    Pillow is vulnerable to a FITS GZIP decompression bomb
    CVSS 7.5
    python-pillow/Pillowgeneric
    PublishedApr 15, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  19. CVE-2026-40261High
    Composer has Command Injection via Malicious Perforce Reference
    CVSS 8.8
    composer/composergeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-40176High
    Composer is vulnerable to Command Injection via Malicious Perforce Repository
    CVSS 7.8
    composer/composergeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-21726Unknown severity
    Loki Path Traversal - CVE-2021-36156 Bypass
    Not scoredSource severity not reported
    Grafana/Lokigeneric
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  22. CVE-2025-41118Critical
    Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection
    CVSS 9.1
    Grafana/Pyroscopegeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2026-21727Unknown severity
    Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 Record
    Not scoredSource severity not reported
    Grafana/Grafana Correlationsgeneric
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  24. CVE-2026-34632High
    Photoshop Installer | CWE-427: Uncontrolled Search Path Element
    CVSS 8.2
    Adobe/Adobe Photoshop Installergeneric
    PublishedApr 15, 2026First seen at HOL Jul 7, 2026Updated Jul 20, 2026View HOL analysis
  25. CVE-2026-20136Medium
    Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability
    CVSS 6.0
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-20170Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Cisco/Cisco Webex Contact Centergeneric
    PublishedApr 15, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-20180Critical
    Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
    CVSS 9.9
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-20186Critical
    Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability
    CVSS 9.9
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  29. CVE-2026-20148Medium
    Cisco Identity Services Engine Path Traversal Vulnerability
    CVSS 4.9
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  30. CVE-2026-20147Critical
    Cisco Identity Services Engine Remote Code Execution Vulnerability
    CVSS 9.9
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-20132Medium
    Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
    CVSS 4.8
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  32. CVE-2026-3505High
    Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
    CVSS 7.5
    Legion of the Bouncy Castle Inc./BC-JAVAgeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  33. CVE-2026-5598High
    Non-constant time comparisons risk private key leakage in FrodoKEM.
    CVSS 7.5
    Legion of the Bouncy Castle Inc./BC-JAVA, org.bouncycastle:bcprov-jdk14 +2generic · maven
    PublishedApr 15, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-0636Medium
    LDAP Injection Vulnerability in LDAPStoreHelper.java
    CVSS 6.5
    Legion of the Bouncy Castle Inc./BC-JAVAgeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  35. CVE-2025-40899Unknown severity
    Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  36. CVE-2025-40897Unknown severity
    Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  37. CVE-2025-32442High
    fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
    CVSS 7.5
    fastify, fastify/fastifygeneric · npm
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  38. CVE-2026-33806High
    fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
    CVSS 7.5
    fastify, fastify/fastifygeneric · npm
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  39. CVE-2026-30461High
    CISA ADP Vulnrichment
    CVSS 8.3
    n/a/n/ageneric
    PublishedApr 15, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-33414High
    PowerShell Command Injection in Podman HyperV Machine
    CVSS 7.8
    containers/podmangeneric
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-40683High
    CISA ADP Vulnrichment
    CVSS 7.7
    OpenStack/Keystonegeneric
    PublishedApr 14, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-26171High
    .NET Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/.NET 10.0, Microsoft/.NET 8.0 +3generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2026-23666High
    .NET Framework Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/Microsoft .NET Framework 3.5, Microsoft/Microsoft .NET Framework 3.5 AND 4.7.2 +4generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-33116High
    .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/.NET 10.0, Microsoft/.NET 8.0 +7generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  45. CVE-2026-32178High
    .NET Spoofing Vulnerability
    CVSS 7.5
    Microsoft/.NET 10.0, Microsoft/.NET 8.0 +3generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  46. CVE-2025-61848High
    CISA ADP Vulnrichment
    CVSS 7.2
    Fortinet/FortiAnalyzer, Fortinet/FortiAnalyzer Cloud +2generic
    PublishedApr 14, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026View HOL analysis
  47. CVE-2026-22155Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Fortinet/FortiSOAR PaaS, Fortinet/FortiSOAR on-premisegeneric
    PublishedApr 14, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  48. CVE-2026-21742Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    Fortinet/FortiSOAR PaaS, Fortinet/FortiSOAR on-premisegeneric
    PublishedApr 14, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  49. CVE-2026-39808Critical
    CISA ADP Vulnrichment
    CVSS 9.8 Known exploited
    Fortinet/FortiSandbox, Fortinet/FortiSandbox PaaSgeneric
    PublishedApr 14, 2026First seen at HOL Jul 16, 2026Updated Jul 19, 2026View HOL analysis
  50. CVE-2026-2332High
    HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
    CVSS 7.4
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedApr 14, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026View HOL analysis
Page 193 of 355
Previous191192193194195Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,081

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,601–9,650 of 17,710 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-21733High
    GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so)
    CVSS 7.3
    Imagination Technologies/Graphics DDKgeneric
    PublishedApr 17, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  2. CVE-2026-35073Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  3. CVE-2026-35074Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  4. CVE-2026-35072Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  5. CVE-2026-35153Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Dell/PowerProtect Data Domaingeneric
    PublishedApr 17, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  6. CVE-2026-40002Medium
    ZTE Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations.
    CVSS 5.0
    ZTE/Red Magic 11 Pro (NX809J)generic
    PublishedApr 17, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-4525High
    Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
    CVSS 7.5
    HashiCorp/Vault, HashiCorp/Vault Enterprisegeneric
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2026-3605High
    Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
    CVSS 8.1
    HashiCorp/Vault, HashiCorp/Vault Enterprisegeneric
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  9. CVE-2026-40170High
    ngtcp2 has a qlog transport parameter serialization stack buffer overflow
    CVSS 7.5
    ngtcp2/ngtcp2generic
    PublishedApr 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-35469High
    SpdyStream: DOS on CRI
    CVSS 6.5
    github.com/moby/spdystream, moby/spdystreamgeneric · go
    PublishedApr 16, 2026First seen at HOL Jun 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  11. CVE-2025-54502High
    CISA ADP Vulnrichment
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-41082High
    CISA ADP Vulnrichment
    CVSS 7.3
    OCaml/opamgeneric
    PublishedApr 16, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-41080Low
    CISA ADP Vulnrichment
    CVSS 2.9
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31843Critical
    goodoneuz/pay-uz Unauthenticated PHP File Overwrite via /payment/api/editable/update Leading to Remote Code Execution
    CVSS 9.8
    goodoneuz/pay-uzcomposer · generic
    PublishedApr 16, 2026First seen at HOL Aug 2, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-41035High
    CISA ADP Vulnrichment
    CVSS 7.4
    Samba/rsyncgeneric
    PublishedApr 16, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-3861Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedApr 16, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  17. CVE-2026-30459High
    CISA ADP Vulnrichment
    CVSS 7.1
    n/a/n/ageneric
    PublishedApr 16, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  18. CVE-2026-40192High
    Pillow is vulnerable to a FITS GZIP decompression bomb
    CVSS 7.5
    python-pillow/Pillowgeneric
    PublishedApr 15, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  19. CVE-2026-40261High
    Composer has Command Injection via Malicious Perforce Reference
    CVSS 8.8
    composer/composergeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-40176High
    Composer is vulnerable to Command Injection via Malicious Perforce Repository
    CVSS 7.8
    composer/composergeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-21726Unknown severity
    Loki Path Traversal - CVE-2021-36156 Bypass
    Not scoredSource severity not reported
    Grafana/Lokigeneric
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  22. CVE-2025-41118Critical
    Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection
    CVSS 9.1
    Grafana/Pyroscopegeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2026-21727Unknown severity
    Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 Record
    Not scoredSource severity not reported
    Grafana/Grafana Correlationsgeneric
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  24. CVE-2026-34632High
    Photoshop Installer | CWE-427: Uncontrolled Search Path Element
    CVSS 8.2
    Adobe/Adobe Photoshop Installergeneric
    PublishedApr 15, 2026First seen at HOL Jul 7, 2026Updated Jul 20, 2026View HOL analysis
  25. CVE-2026-20136Medium
    Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability
    CVSS 6.0
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-20170Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Cisco/Cisco Webex Contact Centergeneric
    PublishedApr 15, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-20180Critical
    Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
    CVSS 9.9
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-20186Critical
    Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability
    CVSS 9.9
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  29. CVE-2026-20148Medium
    Cisco Identity Services Engine Path Traversal Vulnerability
    CVSS 4.9
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  30. CVE-2026-20147Critical
    Cisco Identity Services Engine Remote Code Execution Vulnerability
    CVSS 9.9
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-20132Medium
    Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
    CVSS 4.8
    Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedApr 15, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  32. CVE-2026-3505High
    Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
    CVSS 7.5
    Legion of the Bouncy Castle Inc./BC-JAVAgeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  33. CVE-2026-5598High
    Non-constant time comparisons risk private key leakage in FrodoKEM.
    CVSS 7.5
    Legion of the Bouncy Castle Inc./BC-JAVA, org.bouncycastle:bcprov-jdk14 +2generic · maven
    PublishedApr 15, 2026First seen at HOL Jun 19, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-0636Medium
    LDAP Injection Vulnerability in LDAPStoreHelper.java
    CVSS 6.5
    Legion of the Bouncy Castle Inc./BC-JAVAgeneric
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  35. CVE-2025-40899Unknown severity
    Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  36. CVE-2025-40897Unknown severity
    Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedApr 15, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  37. CVE-2025-32442High
    fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
    CVSS 7.5
    fastify, fastify/fastifygeneric · npm
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  38. CVE-2026-33806High
    fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
    CVSS 7.5
    fastify, fastify/fastifygeneric · npm
    PublishedApr 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  39. CVE-2026-30461High
    CISA ADP Vulnrichment
    CVSS 8.3
    n/a/n/ageneric
    PublishedApr 15, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-33414High
    PowerShell Command Injection in Podman HyperV Machine
    CVSS 7.8
    containers/podmangeneric
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-40683High
    CISA ADP Vulnrichment
    CVSS 7.7
    OpenStack/Keystonegeneric
    PublishedApr 14, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-26171High
    .NET Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/.NET 10.0, Microsoft/.NET 8.0 +3generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2026-23666High
    .NET Framework Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/Microsoft .NET Framework 3.5, Microsoft/Microsoft .NET Framework 3.5 AND 4.7.2 +4generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-33116High
    .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/.NET 10.0, Microsoft/.NET 8.0 +7generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  45. CVE-2026-32178High
    .NET Spoofing Vulnerability
    CVSS 7.5
    Microsoft/.NET 10.0, Microsoft/.NET 8.0 +3generic
    PublishedApr 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  46. CVE-2025-61848High
    CISA ADP Vulnrichment
    CVSS 7.2
    Fortinet/FortiAnalyzer, Fortinet/FortiAnalyzer Cloud +2generic
    PublishedApr 14, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026View HOL analysis
  47. CVE-2026-22155Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Fortinet/FortiSOAR PaaS, Fortinet/FortiSOAR on-premisegeneric
    PublishedApr 14, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  48. CVE-2026-21742Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    Fortinet/FortiSOAR PaaS, Fortinet/FortiSOAR on-premisegeneric
    PublishedApr 14, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  49. CVE-2026-39808Critical
    CISA ADP Vulnrichment
    CVSS 9.8 Known exploited
    Fortinet/FortiSandbox, Fortinet/FortiSandbox PaaSgeneric
    PublishedApr 14, 2026First seen at HOL Jul 16, 2026Updated Jul 19, 2026View HOL analysis
  50. CVE-2026-2332High
    HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
    CVSS 7.4
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedApr 14, 2026First seen at HOL Jul 2, 2026Updated Aug 10, 2026View HOL analysis
Page 193 of 355
Previous191192193194195Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard