HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 5:44 AM 38,735 active 1,498 known exploited

Catalog summary

38,735

Active CVEs

19,688

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 951–1,000 of 38,735 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15890Medium
    AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization
    CVSS 5.3
    zephyrproject/zephyrgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  2. CVE-2026-59815Medium
    Joplin: Pending share recipients can write items into shared folders before accepting invitations
    CVSS 4.3
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  3. CVE-2026-55210High
    Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin)
    CVSS 7.4
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  4. CVE-2026-61652High
    Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
    CVSS 8.7
    kap-sh/zapros, zaprosgeneric · pip · pypi
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  5. CVE-2026-59814High
    Joplin: Stored XSS via inline-served note attachment on published shares
    CVSS 7.6
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  6. CVE-2026-61647High
    @roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
    CVSS 7.1
    @roomi-fields/notebooklm-mcp, roomi-fields/notebooklm-mcpgeneric · npm
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  7. CVE-2026-55105High
    Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer
    CVSS 7.7
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  8. CVE-2026-46649Unknown severity
    Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint
    Not scoredSource severity not reported
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  9. CVE-2026-55179Medium
    Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID
    CVSS 6.5
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  10. CVE-2026-59816Medium
    Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash
    CVSS 4.3
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  11. CVE-2026-49449Unknown severity
    Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows
    Not scoredSource severity not reported
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  12. CVE-2026-49453Unknown severity
    Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory
    Not scoredSource severity not reported
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  13. CVE-2026-49450Unknown severity
    Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherName
    Not scoredSource severity not reported
    laurent22/joplingeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  14. CVE-2026-79919Medium
    MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)
    CVSS 6.3
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  15. CVE-2026-79918Unknown severity
    MaxKB: Sandbox escape via unhooked fexecve
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  16. CVE-2026-77517Unknown severity
    MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  17. CVE-2026-77521Unknown severity
    MaxKB: Prompt-injectable agent can lead to command execution
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  18. CVE-2026-94424Critical
    Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow
    CVSS 9.3
    Moore Threads/MTT S80 Driver Packagegeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  19. CVE-2026-77522Unknown severity
    MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  20. CVE-2026-79917Medium
    MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation
    CVSS 6.5
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  21. CVE-2026-77516Unknown severity
    MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  22. CVE-2026-77523Unknown severity
    MaxKB: Cross-workspace model parameter form write
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  23. CVE-2026-77525Unknown severity
    MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  24. CVE-2026-77518Unknown severity
    MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  25. CVE-2026-79916Critical
    MaxKB AWS Bedrock model credential injection leads to remote code execution
    CVSS 9.1
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  26. CVE-2026-58272Medium
    Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
    CVSS 5.3
    @sync-in/server, Sync-in/servergeneric · npm
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  27. CVE-2026-58270Medium
    Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
    CVSS 6.5
    @sync-in/server, Sync-in/servergeneric · npm
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  28. CVE-2026-77520Medium
    MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application
    CVSS 5.4
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  29. CVE-2026-77519Unknown severity
    MaxKB: Expired application API keys remain usable on `/chat/api/mcp`
    Not scoredSource severity not reported
    1Panel-dev/MaxKBgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  30. CVE-2026-73511Medium
    Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache Tomcat)
    CVSS 5.3
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  31. CVE-2026-73553Unknown severity
    Envoy: RBAC Authorization Bypass via Path Parameters
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  32. CVE-2026-73551Unknown severity
    Envoy: Path normalization does not handle dot and dotdot segments with parameters
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  33. CVE-2026-93433Unknown severity
    Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  34. CVE-2026-94571Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    OpenStack/Octaviageneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  35. CVE-2026-58269High
    Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
    CVSS 8.1
    @sync-in/server, Sync-in/servergeneric · npm
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  36. CVE-2026-73546Unknown severity
    Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  37. CVE-2026-73512Unknown severity
    Envoy: use-after-free in QUIC on internal redirects
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  38. CVE-2026-58271Medium
    @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
    CVSS 6.8
    @sync-in/server, Sync-in/servergeneric · npm
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  39. CVE-2026-73550Unknown severity
    Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  40. CVE-2026-73547High
    Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  41. CVE-2026-48521Unknown severity
    Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  42. CVE-2026-73549Unknown severity
    Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  43. CVE-2026-73513Unknown severity
    Envoy: oghttp2 upstream trailers incorrect handling
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  44. CVE-2026-85219Unknown severity
    Denial-of-Service in the OpenCanary Redis service
    Not scoredSource severity not reported
    Thinkst Applied Research/OpenCanarygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  45. CVE-2026-49811Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Dell/Command | Monitor (DCM)generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  46. CVE-2026-73552High
    Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values
    CVSS 7.5
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  47. CVE-2026-73548Unknown severity
    Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool
    Not scoredSource severity not reported
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  48. CVE-2026-50572Medium
    Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault
    CVSS 5.9
    envoyproxy/envoygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  49. CVE-2026-55897High
    luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root
    CVSS 8.8
    openwrt/lucigeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  50. CVE-2026-55159High
    luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entries
    CVSS 8.8
    openwrt/luci-app-adblock-fastgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
Page 20 of 775
Previous1819202122Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard