1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:30 AM 16,232 active 1,443 known exploited

Catalog summary

16,232

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:30 AM 16,232 active 1,443 known exploited

Catalog summary

16,232

Active CVEs

8,389

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 51–100 of 16,232 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-19245Low
    HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure
    CVSS 3.3
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-66061High
    Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution
    CVSS 7.1
    home-assistant/coregeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2026-9031Medium
    Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
    CVSS 6.8
    TP-Link Systems Inc./Archer A6 v4generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-9030Medium
    Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
    CVSS 6.8
    TP-Link Systems Inc./Archer A6 v4generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  5. CVE-2026-66060High
    Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers
    CVSS 7.1
    home-assistant/coregeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-46358Medium
    OpenBao's Inline Auth Incorrectly Redacted Headers
    CVSS 5.4
    openbao/openbaogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-19244Medium
    HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control
    CVSS 4.7
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2026-47664High
    Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and warehouse data poisoning
    CVSS 8.6
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  9. CVE-2026-71381Medium
    Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization
    CVSS 4.0
    Adobe/Adobe Genuine Software Integrity Servicegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-47663High
    Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutation
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  11. CVE-2026-47662High
    Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLs
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-11425Medium
    Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert Device Rendering
    CVSS 4.4
    Domoticz/Domoticzgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-59717Medium
    Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
    CVSS 4.3
    home-assistant/coregeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-61808Critical
    LightRAG: Missing Authentication for Critical API Functions in Default Configuration
    CVSS 9.8
    HKUDS/LightRAGgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-62296High
    HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of service
    CVSS 7.5
    hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.r5, hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.utilities +3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-47661High
    Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-47660High
    Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltration
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-47659High
    Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-62295High
    HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service
    CVSS 7.5
    hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.r5, hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.utilities +3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  20. CVE-2026-48007High
    Element Call reports full URLs of visited pages to analytics server
    CVSS 8.6
    @element-hq/element-call-embedded, element-hq/element-callgeneric · npm
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-19243Medium
    HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection
    CVSS 6.3
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-48039Critical
    Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
    CVSS 9.1
    meta-ads-mcp, pipeboard-co/meta-ads-mcpgeneric · pip
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-71870Medium
    pypdf: Possible large memory usage for large /ToUnicode streams
    CVSS 4.8
    py-pdf/pypdf, pypdfgeneric · pip
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-62293Medium
    HAPI FHIR: Stored XSS in scan report via unescaped IG and profile titles
    CVSS 5.0
    hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.validation, hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli +1generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-19113Medium
    Unauthenticated denial of service via unbounded request body processing
    CVSS 5.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  26. CVE-2026-15972High
    Unauthenticated denial of service via unbounded external gRPC connection acceptance
    CVSS 7.5
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-15970Medium
    L7 intention authorization bypass via custom public listener
    CVSS 4.2
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-19017Medium
    Consul vulnerable to partial arbitrary file read via Vault Connect CA provider
    CVSS 6.8
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2026-65819High
    gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser
    CVSS 7.5
    gopacket/gopacketgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  30. CVE-2026-19015Medium
    Uncontrolled resource consumption in the Consul Connect CA roots endpoint
    CVSS 5.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  31. CVE-2026-19014Medium
    Uncontrolled resource consumption in the Consul Connect authorization endpoint
    CVSS 4.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  32. CVE-2026-19012Medium
    Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path
    CVSS 5.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-19016Medium
    Authorization bypass for session deletion in the transaction API
    CVSS 4.2
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-48098High
    NexTOR IP Changer Unsafely Uses sudo and shell=True
    CVSS 7.3
    0x5t4l1n/NexTOR_IP_CHANGERgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  35. CVE-2026-48097High
    NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution
    CVSS 7.8
    0x5t4l1n/NexTOR_IP_CHANGERgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-17435Unknown severity
    File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
    Not scoredSource severity not reported
    RRWO/File::Rotate::Simplegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2025-71409High
    No Authentication for Very High Frequency Data Link messages used in CPDLC
    CVSS 7.1
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2025-71410Medium
    Malicious Link Control Frames Can Cause Loss of CPDLC Functions
    CVSS 5.3
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-11430High
    Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
    CVSS 7.3
    Trilby Media/getgrav/grav, Trilby Media/grav-plugin-scheduler-webhookgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2025-71411Medium
    In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultaneously
    CVSS 5.3
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  41. CVE-2025-71412High
    In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate
    CVSS 7.1
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  42. CVE-2025-71413Medium
    In CPDLC, Malformed or Out of Sequence Frames Can Cause Resets
    CVSS 5.3
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  43. CVE-2026-71852Medium
    pypdf: Possible long runtimes/large memory usage for large CID font width ranges
    CVSS 4.8
    py-pdf/pypdf, pypdfgeneric · pip
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-71851Critical
    crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
    CVSS 9.0
    brix/crypto-js, crypto-jsgeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-71850Medium
    Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
    CVSS 4.8
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-71849Low
    Hono: Proxy Helper does not remove response headers listed in the `Connection` header
    CVSS 3.7
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-71848Medium
    Hono: Algorithmic Complexity DoS in Language Middleware
    CVSS 5.3
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  48. CVE-2026-69127Medium
    Kirby: System path exposure from error messages in the REST API
    CVSS 6.9
    getkirby/kirbygeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  49. CVE-2026-71847Low
    Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
    CVSS 8.7
    json, ruby/jsongeneric · rubygems
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-19231High
    SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection
    CVSS 7.3
    SourceCodester/Simple Doctors Appointment Systemgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
Page 2 of 325
Previous12345Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,389

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 51–100 of 16,232 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-19245Low
    HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure
    CVSS 3.3
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-66061High
    Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution
    CVSS 7.1
    home-assistant/coregeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2026-9031Medium
    Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
    CVSS 6.8
    TP-Link Systems Inc./Archer A6 v4generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-9030Medium
    Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
    CVSS 6.8
    TP-Link Systems Inc./Archer A6 v4generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  5. CVE-2026-66060High
    Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers
    CVSS 7.1
    home-assistant/coregeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-46358Medium
    OpenBao's Inline Auth Incorrectly Redacted Headers
    CVSS 5.4
    openbao/openbaogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-19244Medium
    HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control
    CVSS 4.7
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2026-47664High
    Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and warehouse data poisoning
    CVSS 8.6
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  9. CVE-2026-71381Medium
    Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization
    CVSS 4.0
    Adobe/Adobe Genuine Software Integrity Servicegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-47663High
    Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutation
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  11. CVE-2026-47662High
    Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLs
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-11425Medium
    Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert Device Rendering
    CVSS 4.4
    Domoticz/Domoticzgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-59717Medium
    Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
    CVSS 4.3
    home-assistant/coregeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-61808Critical
    LightRAG: Missing Authentication for Critical API Functions in Default Configuration
    CVSS 9.8
    HKUDS/LightRAGgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-62296High
    HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of service
    CVSS 7.5
    hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.r5, hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.utilities +3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-47661High
    Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-47660High
    Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltration
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-47659High
    Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}
    CVSS 8.7
    aehrc/pathlinggeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-62295High
    HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service
    CVSS 7.5
    hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.r5, hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.utilities +3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  20. CVE-2026-48007High
    Element Call reports full URLs of visited pages to analytics server
    CVSS 8.6
    @element-hq/element-call-embedded, element-hq/element-callgeneric · npm
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-19243Medium
    HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection
    CVSS 6.3
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-48039Critical
    Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
    CVSS 9.1
    meta-ads-mcp, pipeboard-co/meta-ads-mcpgeneric · pip
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-71870Medium
    pypdf: Possible large memory usage for large /ToUnicode streams
    CVSS 4.8
    py-pdf/pypdf, pypdfgeneric · pip
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-62293Medium
    HAPI FHIR: Stored XSS in scan report via unescaped IG and profile titles
    CVSS 5.0
    hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.validation, hapifhir/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli +1generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-19113Medium
    Unauthenticated denial of service via unbounded request body processing
    CVSS 5.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  26. CVE-2026-15972High
    Unauthenticated denial of service via unbounded external gRPC connection acceptance
    CVSS 7.5
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-15970Medium
    L7 intention authorization bypass via custom public listener
    CVSS 4.2
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-19017Medium
    Consul vulnerable to partial arbitrary file read via Vault Connect CA provider
    CVSS 6.8
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2026-65819High
    gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser
    CVSS 7.5
    gopacket/gopacketgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  30. CVE-2026-19015Medium
    Uncontrolled resource consumption in the Consul Connect CA roots endpoint
    CVSS 5.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  31. CVE-2026-19014Medium
    Uncontrolled resource consumption in the Consul Connect authorization endpoint
    CVSS 4.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  32. CVE-2026-19012Medium
    Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path
    CVSS 5.3
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-19016Medium
    Authorization bypass for session deletion in the transaction API
    CVSS 4.2
    HashiCorp/Consul, HashiCorp/Consul Enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-48098High
    NexTOR IP Changer Unsafely Uses sudo and shell=True
    CVSS 7.3
    0x5t4l1n/NexTOR_IP_CHANGERgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  35. CVE-2026-48097High
    NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution
    CVSS 7.8
    0x5t4l1n/NexTOR_IP_CHANGERgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-17435Unknown severity
    File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
    Not scoredSource severity not reported
    RRWO/File::Rotate::Simplegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2025-71409High
    No Authentication for Very High Frequency Data Link messages used in CPDLC
    CVSS 7.1
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2025-71410Medium
    Malicious Link Control Frames Can Cause Loss of CPDLC Functions
    CVSS 5.3
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-11430High
    Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
    CVSS 7.3
    Trilby Media/getgrav/grav, Trilby Media/grav-plugin-scheduler-webhookgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2025-71411Medium
    In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultaneously
    CVSS 5.3
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  41. CVE-2025-71412High
    In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate
    CVSS 7.1
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  42. CVE-2025-71413Medium
    In CPDLC, Malformed or Out of Sequence Frames Can Cause Resets
    CVSS 5.3
    ATN-B1/CPDLCgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  43. CVE-2026-71852Medium
    pypdf: Possible long runtimes/large memory usage for large CID font width ranges
    CVSS 4.8
    py-pdf/pypdf, pypdfgeneric · pip
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-71851Critical
    crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
    CVSS 9.0
    brix/crypto-js, crypto-jsgeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-71850Medium
    Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
    CVSS 4.8
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-71849Low
    Hono: Proxy Helper does not remove response headers listed in the `Connection` header
    CVSS 3.7
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-71848Medium
    Hono: Algorithmic Complexity DoS in Language Middleware
    CVSS 5.3
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  48. CVE-2026-69127Medium
    Kirby: System path exposure from error messages in the REST API
    CVSS 6.9
    getkirby/kirbygeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  49. CVE-2026-71847Low
    Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
    CVSS 8.7
    json, ruby/jsongeneric · rubygems
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-19231High
    SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection
    CVSS 7.3
    SourceCodester/Simple Doctors Appointment Systemgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
Page 2 of 325
Previous12345Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard