1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:03 AM 17,758 active 1,445 known exploited

Catalog summary

17,758

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:03 AM 17,758 active 1,445 known exploited

Catalog summary

17,758

Active CVEs

9,092

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,001–10,050 of 17,758 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-4729Critical
    Memory safety bugs fixed in Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-4720Critical
    Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-4700Critical
    Mitigation bypass in the Networking: HTTP component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-4699High
    Incorrect boundary conditions in the Layout: Text and Fonts component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-4698Critical
    JIT miscompilation in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-4697High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-4696Critical
    Use-after-free in the Layout: Text and Fonts component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-4695High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-4694High
    Incorrect boundary conditions, integer overflow in the Graphics component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-4693High
    Incorrect boundary conditions in the Audio/Video: Playback component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-4692Critical
    Sandbox escape in the Responsive Design Mode component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-4691Critical
    Use-after-free in the CSS Parsing and Computation component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2026-4690High
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-4689Critical
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-4688Critical
    Sandbox escape due to use-after-free in the Disability Access APIs component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-4687High
    Sandbox escape due to incorrect boundary conditions in the Telemetry component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-4686High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-4685High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-4684High
    Race condition, use-after-free in the Graphics: WebRender component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-33211Critical
    Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod
    CVSS 9.6
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedMar 23, 2026First seen at HOL Jul 9, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-33195Critical
    Rails Active Storage has possible Path Traversal in DiskService
    CVSS 9.8
    activestorage, rails/activestoragegeneric · rubygems
    PublishedMar 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2026-33634High
    Trivy ecosystem supply chain briefly compromised
    Not scored Known exploited
    BerriAI/LiteLLM, aquasecurity/setup-trivy +4generic · github actions · go
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Jun 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-3055High
    Insufficient input validation leading to memory overread
    Not scored Known exploited
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  24. CVE-2026-32845High
    jkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer Overflow
    CVSS 8.4
    jkuhlmann/cgltfgeneric
    PublishedMar 23, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  25. CVE-2026-4647Medium
    Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 23, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-31851Unknown severity
    Nexxt Nebula 300+ - Lack of Rate Limiting Enables Brute-Force Attacks
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  27. CVE-2026-31850Unknown severity
    Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  28. CVE-2026-31849Unknown severity
    Missing CSRF Protection on Administrative Endpoints in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  29. CVE-2026-31848Critical
    Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+
    CVSS 9.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  30. CVE-2026-31847High
    Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+
    CVSS 8.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  31. CVE-2026-31846Medium
    Unauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+
    CVSS 6.5
    Nexxt Solutions/Nebula 300+ / Tenda F3 V2.0 Firmwaregeneric
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  32. CVE-2026-4603Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  33. CVE-2026-4601High
    CISA ADP Vulnrichment
    CVSS 8.7
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-4599Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-4598High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-4602High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-4600High
    CISA ADP Vulnrichment
    CVSS 7.4
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  38. CVE-2025-52204Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2026-33228Critical
    flatted: Prototype Pollution via parse()
    CVSS 9.8
    WebReflection/flattedgeneric
    PublishedMar 20, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  40. CVE-2026-33210Critical
    Ruby JSON has a format string injection vulnerability
    CVSS 9.1
    json, ruby/jsongeneric · rubygems
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  41. CVE-2026-33236High
    NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
    CVSS 8.1
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 21, 2026View HOL analysis
  42. CVE-2026-33231High
    NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app
    CVSS 7.5
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-33186Critical
    gRPC-Go has an authorization bypass via missing leading slash in :path
    CVSS 9.1
    grpc/grpc-gogeneric
    PublishedMar 20, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026View HOL analysis
  44. CVE-2026-33180High
    HAPI FHIR HTTP authentication leak in redirects
    CVSS 7.5
    ca.uhn.hapi.fhir:org.hl7.fhir.convertors, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 +11generic · maven
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  45. CVE-2026-23536High
    Feast: unauthenticated arbitrary file read
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-33150High
    Use After Free in libfuse
    CVSS 7.8
    libfuse/libfusegeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-4438Medium
    gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
    CVSS 5.4
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-4437High
    gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-15608Critical
    Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53 + Archer AX55
    CVSS 9.8
    TP-Link Systems Inc./AX53 v1, TP-Link Systems Inc./AX55 v4 +1generic
    PublishedMar 20, 2026First seen at HOL Jul 13, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  50. CVE-2026-4519Low
    webbrowser.open() allows leading dashes in URLs
    CVSS 3.3
    Python Software Foundation/CPythongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 201 of 356
Previous199200201202203Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,092

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,001–10,050 of 17,758 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-4729Critical
    Memory safety bugs fixed in Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-4720Critical
    Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-4700Critical
    Mitigation bypass in the Networking: HTTP component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-4699High
    Incorrect boundary conditions in the Layout: Text and Fonts component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-4698Critical
    JIT miscompilation in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-4697High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-4696Critical
    Use-after-free in the Layout: Text and Fonts component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-4695High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-4694High
    Incorrect boundary conditions, integer overflow in the Graphics component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-4693High
    Incorrect boundary conditions in the Audio/Video: Playback component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-4692Critical
    Sandbox escape in the Responsive Design Mode component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-4691Critical
    Use-after-free in the CSS Parsing and Computation component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2026-4690High
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-4689Critical
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-4688Critical
    Sandbox escape due to use-after-free in the Disability Access APIs component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-4687High
    Sandbox escape due to incorrect boundary conditions in the Telemetry component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-4686High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-4685High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-4684High
    Race condition, use-after-free in the Graphics: WebRender component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-33211Critical
    Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod
    CVSS 9.6
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedMar 23, 2026First seen at HOL Jul 9, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-33195Critical
    Rails Active Storage has possible Path Traversal in DiskService
    CVSS 9.8
    activestorage, rails/activestoragegeneric · rubygems
    PublishedMar 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2026-33634High
    Trivy ecosystem supply chain briefly compromised
    Not scored Known exploited
    BerriAI/LiteLLM, aquasecurity/setup-trivy +4generic · github actions · go
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Jun 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-3055High
    Insufficient input validation leading to memory overread
    Not scored Known exploited
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  24. CVE-2026-32845High
    jkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer Overflow
    CVSS 8.4
    jkuhlmann/cgltfgeneric
    PublishedMar 23, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  25. CVE-2026-4647Medium
    Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 23, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-31851Unknown severity
    Nexxt Nebula 300+ - Lack of Rate Limiting Enables Brute-Force Attacks
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  27. CVE-2026-31850Unknown severity
    Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  28. CVE-2026-31849Unknown severity
    Missing CSRF Protection on Administrative Endpoints in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  29. CVE-2026-31848Critical
    Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+
    CVSS 9.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  30. CVE-2026-31847High
    Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+
    CVSS 8.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  31. CVE-2026-31846Medium
    Unauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+
    CVSS 6.5
    Nexxt Solutions/Nebula 300+ / Tenda F3 V2.0 Firmwaregeneric
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  32. CVE-2026-4603Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  33. CVE-2026-4601High
    CISA ADP Vulnrichment
    CVSS 8.7
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-4599Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-4598High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-4602High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-4600High
    CISA ADP Vulnrichment
    CVSS 7.4
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  38. CVE-2025-52204Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2026-33228Critical
    flatted: Prototype Pollution via parse()
    CVSS 9.8
    WebReflection/flattedgeneric
    PublishedMar 20, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  40. CVE-2026-33210Critical
    Ruby JSON has a format string injection vulnerability
    CVSS 9.1
    json, ruby/jsongeneric · rubygems
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  41. CVE-2026-33236High
    NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
    CVSS 8.1
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 21, 2026View HOL analysis
  42. CVE-2026-33231High
    NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app
    CVSS 7.5
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-33186Critical
    gRPC-Go has an authorization bypass via missing leading slash in :path
    CVSS 9.1
    grpc/grpc-gogeneric
    PublishedMar 20, 2026First seen at HOL Jul 1, 2026Updated Aug 11, 2026View HOL analysis
  44. CVE-2026-33180High
    HAPI FHIR HTTP authentication leak in redirects
    CVSS 7.5
    ca.uhn.hapi.fhir:org.hl7.fhir.convertors, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 +11generic · maven
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  45. CVE-2026-23536High
    Feast: unauthenticated arbitrary file read
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-33150High
    Use After Free in libfuse
    CVSS 7.8
    libfuse/libfusegeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-4438Medium
    gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
    CVSS 5.4
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-4437High
    gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-15608Critical
    Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53 + Archer AX55
    CVSS 9.8
    TP-Link Systems Inc./AX53 v1, TP-Link Systems Inc./AX55 v4 +1generic
    PublishedMar 20, 2026First seen at HOL Jul 13, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  50. CVE-2026-4519Low
    webbrowser.open() allows leading dashes in URLs
    CVSS 3.3
    Python Software Foundation/CPythongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 201 of 356
Previous199200201202203Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard