1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 5:35 AM 17,719 active 1,445 known exploited

Catalog summary

17,719

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 5:35 AM 17,719 active 1,445 known exploited

Catalog summary

17,719

Active CVEs

9,082

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,851–9,900 of 17,719 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-33983Medium
    FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-21710High
    CISA ADP Vulnrichment
    CVSS 7.5
    nodejs/nodegeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  3. CVE-2026-34714Critical
    CISA ADP Vulnrichment
    CVSS 9.2
    Vim/Vimgeneric
    PublishedMar 30, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-3502High
    TrueConf Client Update Integrity Verification Bypass
    Not scored Known exploited
    TrueConf/TrueConf Clientgeneric
    PublishedMar 30, 2026First seen at HOL May 24, 2026Updated Apr 16, 2026View HOL analysis
  5. CVE-2026-4046High
    iconv crash due to assertion failure with untrusted input
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-4315High
    WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI
    CVSS 7.1
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-4266High
    WatchGuard Firebox Insecure Deserialization in Fireware Access Portal
    CVSS 8.4
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  8. CVE-2026-5121High
    Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
    CVSS 7.5
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2025-15379Critical
    Command Injection in mlflow/mlflow
    CVSS 9.8
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  10. CVE-2026-3945High
    tinyproxy Integer Overflow in HTTP Chunked Transfer-Encoding Parser Leading to Denial of Service
    CVSS 7.5
    tinyproxy/tinyproxygeneric
    PublishedMar 30, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  11. CVE-2025-15036Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 10.0
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-29597Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  13. CVE-2026-30082Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  14. CVE-2026-2370High
    Improper Handling of Parameters in GitLab
    CVSS 8.1
    GitLab/GitLabgeneric
    PublishedMar 29, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  15. CVE-2026-3256Critical
    HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids
    CVSS 9.8
    KTAT/HTTP::Sessiongeneric
    PublishedMar 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  16. CVE-2026-34226High
    Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
    CVSS 7.5
    capricorn86/happy-domgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-33943High
    Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
    CVSS 8.8
    capricorn86/happy-domgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-33941High
    Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
    CVSS 8.2
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-33940High
    Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
    CVSS 8.1
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-33939High
    Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
    CVSS 7.5
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-33938High
    Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
    CVSS 8.1
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-33937Critical
    Handlebars.js has JavaScript Injection via AST Type Confusion
    CVSS 9.8
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-33896High
    Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
    CVSS 7.4
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-33895High
    Forge has signature forgery in Ed25519 due to missing S > L check
    CVSS 7.5
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-33894High
    Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
    CVSS 7.5
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  26. CVE-2026-33891High
    Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
    CVSS 7.5
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-33871High
    Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
    CVSS 7.5
    netty/nettygeneric
    PublishedMar 27, 2026First seen at HOL Jul 3, 2026Updated Aug 4, 2026View HOL analysis
  28. CVE-2026-33870High
    Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
    CVSS 7.5
    netty/nettygeneric
    PublishedMar 27, 2026First seen at HOL Jul 3, 2026Updated Aug 4, 2026View HOL analysis
  29. CVE-2025-15381High
    Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow
    CVSS 7.1
    mlflow/mlflow/mlflowgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-27879Unknown severity
    Query resampling can cause unbounded memory allocations
    Not scoredSource severity not reported
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  31. CVE-2026-28375Unknown severity
    Grafana Testdata datasource can issue unbounded memory allocations
    Not scoredSource severity not reported
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-27876Critical
    RCE on Grafana via sqlExpressions
    CVSS 9.1
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-33758Medium
    OpenBao has Reflected XSS in its OIDC authentication error message
    CVSS 6.1
    github.com/openbao/openbao, openbao/openbaogeneric · go
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  34. CVE-2026-27880High
    OpenFeature evaluation API reads input data with no bounds
    CVSS 7.5
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  35. CVE-2026-33757Critical
    OpenBao lacks user confirmation for OIDC direct callback mode
    CVSS 9.6
    openbao/openbaogeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-27877Medium
    Public dashboards discloses all direct mode datasources
    CVSS 6.5
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  37. CVE-2026-33433High
    Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
    CVSS 8.8
    traefik/traefikgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-32695High
    Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
    CVSS 7.7
    traefik/traefikgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-27858High
    CISA ADP Vulnrichment
    CVSS 7.5
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-27857Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-27856High
    CISA ADP Vulnrichment
    CVSS 7.4
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-24031High
    CISA ADP Vulnrichment
    CVSS 7.7
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2025-59032High
    CISA ADP Vulnrichment
    CVSS 7.5
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2025-61190Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  45. CVE-2026-30689Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    anjoy8/Blog.Coregeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-28377Unknown severity
    S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
    Not scoredSource severity not reported
    Grafana/Tempogeneric
    PublishedMar 26, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026View HOL analysis
  47. CVE-2026-21724Unknown severity
    Missing Protected-field Authorization in Provisioning Contact Points API
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMar 26, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  48. CVE-2026-33375Unknown severity
    Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMar 26, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  49. CVE-2026-2100Medium
    P11-kit: null dereference via c_derivekey with specific null parameters
    CVSS 5.3
    p11-glue/p11-kitgeneric
    PublishedMar 26, 2026First seen at HOL Jun 22, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  50. CVE-2026-32286High
    Denial of service in github.com/jackc/pgproto3/v2
    CVSS 7.5
    github.com/jackc/pgproto3/v2go
    PublishedMar 26, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
Page 198 of 355
Previous196197198199200Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,082

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 9,851–9,900 of 17,719 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-33983Medium
    FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-21710High
    CISA ADP Vulnrichment
    CVSS 7.5
    nodejs/nodegeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  3. CVE-2026-34714Critical
    CISA ADP Vulnrichment
    CVSS 9.2
    Vim/Vimgeneric
    PublishedMar 30, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-3502High
    TrueConf Client Update Integrity Verification Bypass
    Not scored Known exploited
    TrueConf/TrueConf Clientgeneric
    PublishedMar 30, 2026First seen at HOL May 24, 2026Updated Apr 16, 2026View HOL analysis
  5. CVE-2026-4046High
    iconv crash due to assertion failure with untrusted input
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-4315High
    WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI
    CVSS 7.1
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-4266High
    WatchGuard Firebox Insecure Deserialization in Fireware Access Portal
    CVSS 8.4
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  8. CVE-2026-5121High
    Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
    CVSS 7.5
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2025-15379Critical
    Command Injection in mlflow/mlflow
    CVSS 9.8
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  10. CVE-2026-3945High
    tinyproxy Integer Overflow in HTTP Chunked Transfer-Encoding Parser Leading to Denial of Service
    CVSS 7.5
    tinyproxy/tinyproxygeneric
    PublishedMar 30, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  11. CVE-2025-15036Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 10.0
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-29597Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  13. CVE-2026-30082Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  14. CVE-2026-2370High
    Improper Handling of Parameters in GitLab
    CVSS 8.1
    GitLab/GitLabgeneric
    PublishedMar 29, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  15. CVE-2026-3256Critical
    HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids
    CVSS 9.8
    KTAT/HTTP::Sessiongeneric
    PublishedMar 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  16. CVE-2026-34226High
    Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
    CVSS 7.5
    capricorn86/happy-domgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-33943High
    Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
    CVSS 8.8
    capricorn86/happy-domgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-33941High
    Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
    CVSS 8.2
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-33940High
    Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
    CVSS 8.1
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-33939High
    Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
    CVSS 7.5
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-33938High
    Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
    CVSS 8.1
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-33937Critical
    Handlebars.js has JavaScript Injection via AST Type Confusion
    CVSS 9.8
    handlebars-lang/handlebars.jsgeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-33896High
    Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
    CVSS 7.4
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-33895High
    Forge has signature forgery in Ed25519 due to missing S > L check
    CVSS 7.5
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-33894High
    Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
    CVSS 7.5
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  26. CVE-2026-33891High
    Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
    CVSS 7.5
    digitalbazaar/forgegeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-33871High
    Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
    CVSS 7.5
    netty/nettygeneric
    PublishedMar 27, 2026First seen at HOL Jul 3, 2026Updated Aug 4, 2026View HOL analysis
  28. CVE-2026-33870High
    Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
    CVSS 7.5
    netty/nettygeneric
    PublishedMar 27, 2026First seen at HOL Jul 3, 2026Updated Aug 4, 2026View HOL analysis
  29. CVE-2025-15381High
    Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow
    CVSS 7.1
    mlflow/mlflow/mlflowgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-27879Unknown severity
    Query resampling can cause unbounded memory allocations
    Not scoredSource severity not reported
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  31. CVE-2026-28375Unknown severity
    Grafana Testdata datasource can issue unbounded memory allocations
    Not scoredSource severity not reported
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-27876Critical
    RCE on Grafana via sqlExpressions
    CVSS 9.1
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-33758Medium
    OpenBao has Reflected XSS in its OIDC authentication error message
    CVSS 6.1
    github.com/openbao/openbao, openbao/openbaogeneric · go
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  34. CVE-2026-27880High
    OpenFeature evaluation API reads input data with no bounds
    CVSS 7.5
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  35. CVE-2026-33757Critical
    OpenBao lacks user confirmation for OIDC direct callback mode
    CVSS 9.6
    openbao/openbaogeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-27877Medium
    Public dashboards discloses all direct mode datasources
    CVSS 6.5
    Grafana/Grafanageneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  37. CVE-2026-33433High
    Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
    CVSS 8.8
    traefik/traefikgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-32695High
    Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
    CVSS 7.7
    traefik/traefikgeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-27858High
    CISA ADP Vulnrichment
    CVSS 7.5
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-27857Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-27856High
    CISA ADP Vulnrichment
    CVSS 7.4
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-24031High
    CISA ADP Vulnrichment
    CVSS 7.7
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2025-59032High
    CISA ADP Vulnrichment
    CVSS 7.5
    Open-Xchange GmbH/OX Dovecot Progeneric
    PublishedMar 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2025-61190Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 27, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  45. CVE-2026-30689Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    anjoy8/Blog.Coregeneric
    PublishedMar 27, 2026First seen at HOL Jul 2, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-28377Unknown severity
    S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
    Not scoredSource severity not reported
    Grafana/Tempogeneric
    PublishedMar 26, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026View HOL analysis
  47. CVE-2026-21724Unknown severity
    Missing Protected-field Authorization in Provisioning Contact Points API
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMar 26, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  48. CVE-2026-33375Unknown severity
    Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
    Not scoredSource severity not reported
    Grafana/Grafana OSSgeneric
    PublishedMar 26, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  49. CVE-2026-2100Medium
    P11-kit: null dereference via c_derivekey with specific null parameters
    CVSS 5.3
    p11-glue/p11-kitgeneric
    PublishedMar 26, 2026First seen at HOL Jun 22, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  50. CVE-2026-32286High
    Denial of service in github.com/jackc/pgproto3/v2
    CVSS 7.5
    github.com/jackc/pgproto3/v2go
    PublishedMar 26, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
Page 198 of 355
Previous196197198199200Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard