1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 5:35 AM 17,719 active 1,445 known exploited

Catalog summary

17,719

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 5:35 AM 17,719 active 1,445 known exploited

Catalog summary

17,719

Active CVEs

9,082

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,801–9,850 of 17,719 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-23450Critical
    net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-23449High
    net/sched: teql: Fix double-free in teql_master_xmit
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-23446Medium
    net: usb: aqc111: Do not perform PM inside suspend callback
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-23439Medium
    udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-23438Medium
    net: mvpp2: guard flow control update with global_tx_fc in buffer switching
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-23434High
    mtd: rawnand: serialize lock/unlock against other NAND operations
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-23422High
    dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-5463Critical
    pymetasploit3 - Command Injection via Newline Injection in console.run_module_with_output()
    Not scored
    Dan McInerney/pymetasploit3, pymetasploit3generic · pip
    PublishedApr 3, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026View HOL analysis
  9. CVE-2026-35535High
    CISA ADP Vulnrichment
    CVSS 7.4
    Siemens/RUGGEDCOM RST2428P, Sudo project/Sudogeneric
    PublishedApr 3, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  10. CVE-2026-34742High
    Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhost
    CVSS 8.1
    modelcontextprotocol/go-sdkgeneric
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-34601High
    xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-34827High
    Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-34829High
    Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2026-35386Low
    CISA ADP Vulnrichment
    CVSS 3.6
    OpenBSD/OpenSSHgeneric
    PublishedApr 2, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-34785High
    Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-35385High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenBSD/OpenSSHgeneric
    PublishedApr 2, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2026-32871Critical
    FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
    CVSS 10.0
    PrefectHQ/fastmcpgeneric
    PublishedApr 2, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-2737Medium
    Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application
    CVSS 6.1
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  19. CVE-2026-3692High
    Unintended command execution during report generation in Progress Flowmon
    CVSS 8.8
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  20. CVE-2026-4636High
    Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-4634High
    Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-4282High
    Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-3872High
    Keycloak: keycloak: information disclosure due to redirect_uri validation bypass
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-23414High
    tls: Purge async_hold in tls_decrypt_async_wait()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 2, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-26895Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2026-30603Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2026-3987High
    WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI
    CVSS 8.6
    WatchGuard/Fireware OSgeneric
    PublishedApr 1, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  28. CVE-2026-34545High
    OpenEXR: integer overflow lead to OOB in HTJ2K decoder
    CVSS 7.3
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-27489High
    ONNX: Path Traversal via Symlink
    CVSS 7.5
    onnx/onnxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-20160Critical
    Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
    CVSS 9.8
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  31. CVE-2026-20174Medium
    Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
    CVSS 4.9
    Cisco/Cisco Nexus Dashboard, Cisco/Cisco Nexus Dashboard Insightsgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  32. CVE-2026-20151High
    Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
    CVSS 7.3
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  33. CVE-2026-20155High
    Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
    CVSS 8.0
    Cisco/Cisco Evolved Programmable Network Manager (EPNM)generic
    PublishedApr 1, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  34. CVE-2026-20042Medium
    Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
    CVSS 6.5
    Cisco/Cisco Nexus Dashboardgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  35. CVE-2026-35093High
    Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-23401Medium
    KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  37. CVE-2026-29598Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 1, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  38. CVE-2021-23337High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-4800High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-34881Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    OpenStack/Glancegeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  41. CVE-2026-34070High
    LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
    CVSS 7.5
    langchain-ai/langchain, langchain-coregeneric · pypi
    PublishedMar 31, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-33997Medium
    Moby: Off-by-one error in plugin privilege validation
    CVSS 6.8
    moby/mobygeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026View HOL analysis
  43. CVE-2026-30277High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2026-30278Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  45. CVE-2026-30279High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-30282Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  47. CVE-2026-30283Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  48. CVE-2026-30284High
    CISA ADP Vulnrichment
    CVSS 8.6
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  49. CVE-2026-33986High
    FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-33984High
    FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
Page 197 of 355
Previous195196197198199Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,082

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,801–9,850 of 17,719 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-23450Critical
    net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
    CVSS 9.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-23449High
    net/sched: teql: Fix double-free in teql_master_xmit
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-23446Medium
    net: usb: aqc111: Do not perform PM inside suspend callback
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-23439Medium
    udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-23438Medium
    net: mvpp2: guard flow control update with global_tx_fc in buffer switching
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-23434High
    mtd: rawnand: serialize lock/unlock against other NAND operations
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-23422High
    dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 3, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-5463Critical
    pymetasploit3 - Command Injection via Newline Injection in console.run_module_with_output()
    Not scored
    Dan McInerney/pymetasploit3, pymetasploit3generic · pip
    PublishedApr 3, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026View HOL analysis
  9. CVE-2026-35535High
    CISA ADP Vulnrichment
    CVSS 7.4
    Siemens/RUGGEDCOM RST2428P, Sudo project/Sudogeneric
    PublishedApr 3, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  10. CVE-2026-34742High
    Model Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on Localhost
    CVSS 8.1
    modelcontextprotocol/go-sdkgeneric
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-34601High
    xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
    CVSS 7.5
    xmldom/xmldomgeneric
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-34827High
    Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-34829High
    Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2026-35386Low
    CISA ADP Vulnrichment
    CVSS 3.6
    OpenBSD/OpenSSHgeneric
    PublishedApr 2, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-34785High
    Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-35385High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenBSD/OpenSSHgeneric
    PublishedApr 2, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2026-32871Critical
    FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
    CVSS 10.0
    PrefectHQ/fastmcpgeneric
    PublishedApr 2, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-2737Medium
    Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application
    CVSS 6.1
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  19. CVE-2026-3692High
    Unintended command execution during report generation in Progress Flowmon
    CVSS 8.8
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  20. CVE-2026-4636High
    Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-4634High
    Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-4282High
    Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-3872High
    Keycloak: keycloak: information disclosure due to redirect_uri validation bypass
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-23414High
    tls: Purge async_hold in tls_decrypt_async_wait()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 2, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-26895Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2026-30603Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2026-3987High
    WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI
    CVSS 8.6
    WatchGuard/Fireware OSgeneric
    PublishedApr 1, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  28. CVE-2026-34545High
    OpenEXR: integer overflow lead to OOB in HTJ2K decoder
    CVSS 7.3
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-27489High
    ONNX: Path Traversal via Symlink
    CVSS 7.5
    onnx/onnxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-20160Critical
    Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
    CVSS 9.8
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  31. CVE-2026-20174Medium
    Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
    CVSS 4.9
    Cisco/Cisco Nexus Dashboard, Cisco/Cisco Nexus Dashboard Insightsgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  32. CVE-2026-20151High
    Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
    CVSS 7.3
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  33. CVE-2026-20155High
    Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
    CVSS 8.0
    Cisco/Cisco Evolved Programmable Network Manager (EPNM)generic
    PublishedApr 1, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  34. CVE-2026-20042Medium
    Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
    CVSS 6.5
    Cisco/Cisco Nexus Dashboardgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  35. CVE-2026-35093High
    Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-23401Medium
    KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  37. CVE-2026-29598Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 1, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  38. CVE-2021-23337High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-4800High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-34881Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    OpenStack/Glancegeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  41. CVE-2026-34070High
    LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
    CVSS 7.5
    langchain-ai/langchain, langchain-coregeneric · pypi
    PublishedMar 31, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-33997Medium
    Moby: Off-by-one error in plugin privilege validation
    CVSS 6.8
    moby/mobygeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026View HOL analysis
  43. CVE-2026-30277High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2026-30278Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  45. CVE-2026-30279High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-30282Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  47. CVE-2026-30283Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  48. CVE-2026-30284High
    CISA ADP Vulnrichment
    CVSS 8.6
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  49. CVE-2026-33986High
    FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-33984High
    FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
Page 197 of 355
Previous195196197198199Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard