1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 4:05 AM 17,710 active 1,445 known exploited

Catalog summary

17,710

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 4:05 AM 17,710 active 1,445 known exploited

Catalog summary

17,710

Active CVEs

9,081

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,651–9,700 of 17,710 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-40745Low
    CISA ADP Vulnrichment
    CVSS 3.7
    Siemens/Siemens Software Center, Siemens/Simcenter 3D +5generic
    PublishedApr 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  2. CVE-2025-61260Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 14, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-69893Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    n/a/n/ageneric
    PublishedApr 14, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2026-40164High
    jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
    CVSS 7.5
    jqlang/jqgeneric
    PublishedApr 13, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-39979Medium
    jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
    CVSS 6.5
    jqlang/jqgeneric
    PublishedApr 13, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-4786High
    Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
    CVSS 7.1
    Python Software Foundation/CPythongeneric
    PublishedApr 13, 2026First seen at HOL Jul 6, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-33908High
    ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-33901High
    ImageMagick has a Heap Buffer Overflow via MVG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-6100High
    Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
    CVSS 8.1
    Python Software Foundation/CPythongeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  10. CVE-2026-28291High
    simple-git has Command Execution via Option-Parsing Bypass
    CVSS 8.1
    steveukx/git-jsgeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2025-31991Medium
    HCL DevOps Velocity is susceptible to brute-force attacks
    CVSS 6.8
    HCLSoftware/Velocitygeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026View HOL analysis
  12. CVE-2026-1462High
    Safe Mode Bypass in keras-team/keras
    CVSS 7.8
    keras-team/keras-team/kerasgeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-31428Medium
    netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31427Medium
    netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-31424Medium
    netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-31423Medium
    net/sched: sch_hfsc: fix divide-by-zero in rtsc_min()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-31422Medium
    net/sched: cls_flow: fix NULL pointer dereference on shared blocks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-31421Medium
    net/sched: cls_fw: fix NULL pointer dereference on shared blocks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-31419High
    net: bonding: fix use-after-free in bond_xmit_broadcast()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 13, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-31418Medium
    netfilter: ipset: drop logically empty buckets in mtype_del
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-31417High
    net/x25: Fix overflow when accumulating packets
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-31416Medium
    netfilter: nfnetlink_log: account for netlink header size
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2026-31415Medium
    ipv6: avoid overflows in ip6_datagram_send_ctl()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-31414Critical
    netfilter: nf_conntrack_expect: use expect->helper
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-0232Medium
    Cortex XDR Agent: Local Administrator can disable the agent on Windows
    CVSS 4.4
    Palo Alto Networks/Cortex XDR Agentgeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  26. CVE-2026-0233High
    Autonomous Digital Experience Manager: Improper validation of ADEM certificate
    CVSS 8.8
    Palo Alto Networks/Autonomous Digital Experience Managergeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-0234Critical
    Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration
    CVSS 9.1
    Palo Alto Networks/Cortex XSIAM Microsoft Teams Marketplace, Palo Alto Networks/Cortex XSOAR Microsoft Teams Marketplacegeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  28. CVE-2025-63743Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 13, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  29. CVE-2025-69624High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedApr 13, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2025-69627High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedApr 13, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  31. CVE-2026-33555Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    HAProxy/HAProxygeneric
    PublishedApr 13, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  32. CVE-2026-40393High
    CISA ADP Vulnrichment
    CVSS 8.1
    mesa3d/Mesageneric
    PublishedApr 12, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  33. CVE-2019-25695High
    R 3.4.4 Local Buffer Overflow Windows XP SP3
    CVSS 8.4
    r-project/Rgeneric
    PublishedApr 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-31845Critical
    Rukovoditel CRM Reflected XSS via zd_echo Parameter in Zadarma Telephony API Endpoint
    CVSS 9.3
    Rukovoditel/Rukovoditel CRMgeneric
    PublishedApr 11, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  35. CVE-2026-32146High
    Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
    CVSS 7.8
    Gleam/Gleamgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-34621High
    Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
    Not scored Known exploited
    Adobe/Acrobat Readergeneric
    PublishedApr 11, 2026First seen at HOL May 24, 2026Updated Apr 27, 2026View HOL analysis
  37. CVE-2026-4154High
    GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-4153High
    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-4152High
    GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-4151High
    GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-4150High
    GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-5724Medium
    Missing Authentication on Streaming gRPC Replication Endpoint
    CVSS 6.3
    Temporal Technologies, Inc./temporalgeneric
    PublishedApr 10, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  43. CVE-2026-40190Medium
    LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
    CVSS 5.6
    langchain-ai/langsmith-sdkgeneric
    PublishedApr 10, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026View HOL analysis
  44. CVE-2026-40175Medium
    Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
    CVSS 4.8
    Siemens/gWAP, axios/axiosgeneric
    PublishedApr 10, 2026First seen at HOL Jul 9, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  45. CVE-2026-1502Medium
    HTTP client proxy tunnel headers not validated for CR/LF
    CVSS 5.7
    Python Software Foundation/CPythongeneric
    PublishedApr 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  46. CVE-2026-34481High
    Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
    CVSS 7.5
    Apache Software Foundation/Apache Log4j JSON Template Layout, org.apache.logging.log4j:log4j-layout-template-jsongeneric · maven
    PublishedApr 10, 2026First seen at HOL Jul 11, 2026Updated Jul 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-40217High
    CISA ADP Vulnrichment
    CVSS 8.8
    BerriAI/LiteLLMgeneric
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-39304High
    Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
    CVSS 7.5
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +2generic
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  49. CVE-2026-39848Medium
    Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation
    CVSS 6.5
    10ij/dockyardgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-33784Critical
    JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
    CVSS 9.8
    Juniper Networks/JSI LWCgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
Page 194 of 355
Previous192193194195196Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,081

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,651–9,700 of 17,710 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-40745Low
    CISA ADP Vulnrichment
    CVSS 3.7
    Siemens/Siemens Software Center, Siemens/Simcenter 3D +5generic
    PublishedApr 14, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  2. CVE-2025-61260Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 14, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-69893Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    n/a/n/ageneric
    PublishedApr 14, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2026-40164High
    jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
    CVSS 7.5
    jqlang/jqgeneric
    PublishedApr 13, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-39979Medium
    jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
    CVSS 6.5
    jqlang/jqgeneric
    PublishedApr 13, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-4786High
    Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
    CVSS 7.1
    Python Software Foundation/CPythongeneric
    PublishedApr 13, 2026First seen at HOL Jul 6, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-33908High
    ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-33901High
    ImageMagick has a Heap Buffer Overflow via MVG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-6100High
    Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
    CVSS 8.1
    Python Software Foundation/CPythongeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  10. CVE-2026-28291High
    simple-git has Command Execution via Option-Parsing Bypass
    CVSS 8.1
    steveukx/git-jsgeneric
    PublishedApr 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2025-31991Medium
    HCL DevOps Velocity is susceptible to brute-force attacks
    CVSS 6.8
    HCLSoftware/Velocitygeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026View HOL analysis
  12. CVE-2026-1462High
    Safe Mode Bypass in keras-team/keras
    CVSS 7.8
    keras-team/keras-team/kerasgeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-31428Medium
    netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31427Medium
    netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-31424Medium
    netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-31423Medium
    net/sched: sch_hfsc: fix divide-by-zero in rtsc_min()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-31422Medium
    net/sched: cls_flow: fix NULL pointer dereference on shared blocks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-31421Medium
    net/sched: cls_fw: fix NULL pointer dereference on shared blocks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-31419High
    net: bonding: fix use-after-free in bond_xmit_broadcast()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 13, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-31418Medium
    netfilter: ipset: drop logically empty buckets in mtype_del
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-31417High
    net/x25: Fix overflow when accumulating packets
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-31416Medium
    netfilter: nfnetlink_log: account for netlink header size
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2026-31415Medium
    ipv6: avoid overflows in ip6_datagram_send_ctl()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-31414Critical
    netfilter: nf_conntrack_expect: use expect->helper
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-0232Medium
    Cortex XDR Agent: Local Administrator can disable the agent on Windows
    CVSS 4.4
    Palo Alto Networks/Cortex XDR Agentgeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  26. CVE-2026-0233High
    Autonomous Digital Experience Manager: Improper validation of ADEM certificate
    CVSS 8.8
    Palo Alto Networks/Autonomous Digital Experience Managergeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-0234Critical
    Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration
    CVSS 9.1
    Palo Alto Networks/Cortex XSIAM Microsoft Teams Marketplace, Palo Alto Networks/Cortex XSOAR Microsoft Teams Marketplacegeneric
    PublishedApr 13, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  28. CVE-2025-63743Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 13, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  29. CVE-2025-69624High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedApr 13, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2025-69627High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedApr 13, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  31. CVE-2026-33555Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    HAProxy/HAProxygeneric
    PublishedApr 13, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  32. CVE-2026-40393High
    CISA ADP Vulnrichment
    CVSS 8.1
    mesa3d/Mesageneric
    PublishedApr 12, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  33. CVE-2019-25695High
    R 3.4.4 Local Buffer Overflow Windows XP SP3
    CVSS 8.4
    r-project/Rgeneric
    PublishedApr 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-31845Critical
    Rukovoditel CRM Reflected XSS via zd_echo Parameter in Zadarma Telephony API Endpoint
    CVSS 9.3
    Rukovoditel/Rukovoditel CRMgeneric
    PublishedApr 11, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  35. CVE-2026-32146High
    Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
    CVSS 7.8
    Gleam/Gleamgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-34621High
    Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
    Not scored Known exploited
    Adobe/Acrobat Readergeneric
    PublishedApr 11, 2026First seen at HOL May 24, 2026Updated Apr 27, 2026View HOL analysis
  37. CVE-2026-4154High
    GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-4153High
    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-4152High
    GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-4151High
    GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-4150High
    GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedApr 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-5724Medium
    Missing Authentication on Streaming gRPC Replication Endpoint
    CVSS 6.3
    Temporal Technologies, Inc./temporalgeneric
    PublishedApr 10, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  43. CVE-2026-40190Medium
    LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
    CVSS 5.6
    langchain-ai/langsmith-sdkgeneric
    PublishedApr 10, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026View HOL analysis
  44. CVE-2026-40175Medium
    Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
    CVSS 4.8
    Siemens/gWAP, axios/axiosgeneric
    PublishedApr 10, 2026First seen at HOL Jul 9, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  45. CVE-2026-1502Medium
    HTTP client proxy tunnel headers not validated for CR/LF
    CVSS 5.7
    Python Software Foundation/CPythongeneric
    PublishedApr 10, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  46. CVE-2026-34481High
    Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
    CVSS 7.5
    Apache Software Foundation/Apache Log4j JSON Template Layout, org.apache.logging.log4j:log4j-layout-template-jsongeneric · maven
    PublishedApr 10, 2026First seen at HOL Jul 11, 2026Updated Jul 11, 2026 Fix availableView HOL analysis
  47. CVE-2026-40217High
    CISA ADP Vulnrichment
    CVSS 8.8
    BerriAI/LiteLLMgeneric
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-39304High
    Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
    CVSS 7.5
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +2generic
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  49. CVE-2026-39848Medium
    Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation
    CVSS 6.5
    10ij/dockyardgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-33784Critical
    JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
    CVSS 9.8
    Juniper Networks/JSI LWCgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
Page 194 of 355
Previous192193194195196Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard