1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:10 AM 17,758 active 1,445 known exploited

Catalog summary

17,758

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:10 AM 17,758 active 1,445 known exploited

Catalog summary

17,758

Active CVEs

9,092

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,051–10,100 of 17,758 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-32305Medium
    Traefik mTLS bypass via fragmented ClientHello SNI extraction failure
    CVSS 5.3
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  2. CVE-2026-23277Medium
    net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-23274High
    netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-23273High
    macvlan: observe an RCU grace period in macvlan_common_newlink() error path
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-23271High
    perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-32875High
    UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-32874High
    UltraJSON has a Memory Leak parsing large integers allows DoS
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-32829High
    lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
    CVSS 7.5
    PSeitz/lz4_flexgeneric
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Aug 11, 2026View HOL analysis
  9. CVE-2025-63260Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  10. CVE-2025-67260High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-3029High
    CVE-2026-3029
    CVSS 7.5
    Artifex Software Inc. *PyMuPDF*/PyMuPDFgeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-4424High
    Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2006-10003Critical
    XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack
    CVSS 9.8
    TODDR/XML::Parsergeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2025-15031Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 9.1
    mlflow/mlflow/mlflowgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-27135High
    nghttp2 Denial of service: Assertion failure due to the missing state validation
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-23270High
    net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-33001High
    CISA ADP Vulnrichment
    CVSS 8.8
    org.jenkins-ci.main:jenkins-coremaven
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  18. CVE-2026-23247Medium
    tcp: secure_seq: add back ports to TS offset
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 18, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  19. CVE-2026-23245High
    net/sched: act_gate: snapshot parameters with RCU on replace
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-23243High
    RDMA/umad: Reject negative data_len in ib_umad_write
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-23242High
    RDMA/siw: Fix potential NULL pointer dereference in header processing
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2025-71267Medium
    fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2025-71266Medium
    fs: ntfs3: check return value of indx_find to avoid infinite loop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2025-71265Medium
    fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-31938Critical
    jsPDF has HTML Injection in New Window paths
    CVSS 9.6
    parallax/jsPDFgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  26. CVE-2026-31898High
    jsPDF has a PDF Object Injection via FreeText color
    CVSS 8.1
    parallax/jsPDFgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2026-30922High
    pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
    CVSS 7.5
    pyasn1/pyasn1generic
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-2603High
    Keycloak: keycloak: unauthorized authentication via disabled saml identity provider
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-26740High
    CISA ADP Vulnrichment
    CVSS 8.2
    n/a/n/ageneric
    PublishedMar 18, 2026First seen at HOL Jun 30, 2026Updated Jul 23, 2026View HOL analysis
  30. CVE-2026-30695Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 18, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  31. CVE-2026-27459Critical
    pyOpenSSL DTLS cookie callback buffer overflow
    CVSS 9.8
    pyca/pyopensslgeneric
    PublishedMar 17, 2026First seen at HOL Jul 1, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-3564Critical
    ScreenConnect Instance Level Cryptographic Material Exposure
    CVSS 9.0
    ConnectWise/ScreenConnectgeneric
    PublishedMar 17, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  33. CVE-2026-4258Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/org.webjars.npm:sjcl, n/a/sjclgeneric
    PublishedMar 17, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-4177Critical
    YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter
    CVSS 9.1
    TODDR/YAML::Syckgeneric
    PublishedMar 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2025-69196Medium
    FastMCP OAuth Proxy token reuse across MCP servers
    CVSS 6.5
    jlowin/fastmcpgeneric
    PublishedMar 16, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-28498High
    Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
    CVSS 7.5
    authlib/authlibgeneric
    PublishedMar 16, 2026First seen at HOL Jul 1, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-4224High
    Stack overflow parsing XML with deeply nested DTD content models
    CVSS 7.5
    Python Software Foundation/CPythongeneric
    PublishedMar 16, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-3644High
    Incomplete control character validation in http.cookies
    CVSS 7.5
    Python Software Foundation/CPythongeneric
    PublishedMar 16, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-27962Critical
    Authlib JWS JWK Header Injection: Signature Verification Bypass
    CVSS 9.1
    authlib/authlibgeneric
    PublishedMar 16, 2026First seen at HOL Jul 1, 2026Updated Jul 30, 2026View HOL analysis
  40. CVE-2026-32778Low
    CISA ADP Vulnrichment
    CVSS 2.9
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  41. CVE-2026-32777Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-32776Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2025-50881High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 16, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2025-14287High
    Command Injection in mlflow/mlflow
    CVSS 8.8
    mlflow/mlflow/mlflowgeneric
    PublishedMar 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-3441Medium
    Binutils: gnu binutils: information disclosure via specially crafted xcoff object file
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 15, 2026First seen at HOL Jun 30, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-3442Medium
    Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 15, 2026First seen at HOL Jun 30, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-3227Medium
    Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
    CVSS 6.8
    TP Link Systems Inc./TL-WR840N v6, TP-Link Systems Inc./TL-WR802N v4 +1generic
    PublishedMar 13, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  48. CVE-2026-3084High
    GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability
    CVSS 7.8
    GStreamer/GStreamergeneric
    PublishedMar 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-2921High
    GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GStreamer/GStreamergeneric
    PublishedMar 13, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  50. CVE-2026-3083High
    GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability
    CVSS 8.8
    GStreamer/GStreamergeneric
    PublishedMar 13, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
Page 202 of 356
Previous200201202203204Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,092

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,051–10,100 of 17,758 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-32305Medium
    Traefik mTLS bypass via fragmented ClientHello SNI extraction failure
    CVSS 5.3
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  2. CVE-2026-23277Medium
    net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-23274High
    netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-23273High
    macvlan: observe an RCU grace period in macvlan_common_newlink() error path
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-23271High
    perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-32875High
    UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-32874High
    UltraJSON has a Memory Leak parsing large integers allows DoS
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-32829High
    lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
    CVSS 7.5
    PSeitz/lz4_flexgeneric
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Aug 11, 2026View HOL analysis
  9. CVE-2025-63260Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  10. CVE-2025-67260High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-3029High
    CVE-2026-3029
    CVSS 7.5
    Artifex Software Inc. *PyMuPDF*/PyMuPDFgeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-4424High
    Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2006-10003Critical
    XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack
    CVSS 9.8
    TODDR/XML::Parsergeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2025-15031Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 9.1
    mlflow/mlflow/mlflowgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-27135High
    nghttp2 Denial of service: Assertion failure due to the missing state validation
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-23270High
    net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-33001High
    CISA ADP Vulnrichment
    CVSS 8.8
    org.jenkins-ci.main:jenkins-coremaven
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  18. CVE-2026-23247Medium
    tcp: secure_seq: add back ports to TS offset
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 18, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  19. CVE-2026-23245High
    net/sched: act_gate: snapshot parameters with RCU on replace
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-23243High
    RDMA/umad: Reject negative data_len in ib_umad_write
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-23242High
    RDMA/siw: Fix potential NULL pointer dereference in header processing
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2025-71267Medium
    fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2025-71266Medium
    fs: ntfs3: check return value of indx_find to avoid infinite loop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2025-71265Medium
    fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-31938Critical
    jsPDF has HTML Injection in New Window paths
    CVSS 9.6
    parallax/jsPDFgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  26. CVE-2026-31898High
    jsPDF has a PDF Object Injection via FreeText color
    CVSS 8.1
    parallax/jsPDFgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2026-30922High
    pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
    CVSS 7.5
    pyasn1/pyasn1generic
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-2603High
    Keycloak: keycloak: unauthorized authentication via disabled saml identity provider
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-26740High
    CISA ADP Vulnrichment
    CVSS 8.2
    n/a/n/ageneric
    PublishedMar 18, 2026First seen at HOL Jun 30, 2026Updated Jul 23, 2026View HOL analysis
  30. CVE-2026-30695Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 18, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  31. CVE-2026-27459Critical
    pyOpenSSL DTLS cookie callback buffer overflow
    CVSS 9.8
    pyca/pyopensslgeneric
    PublishedMar 17, 2026First seen at HOL Jul 1, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-3564Critical
    ScreenConnect Instance Level Cryptographic Material Exposure
    CVSS 9.0
    ConnectWise/ScreenConnectgeneric
    PublishedMar 17, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  33. CVE-2026-4258Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/org.webjars.npm:sjcl, n/a/sjclgeneric
    PublishedMar 17, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-4177Critical
    YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter
    CVSS 9.1
    TODDR/YAML::Syckgeneric
    PublishedMar 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2025-69196Medium
    FastMCP OAuth Proxy token reuse across MCP servers
    CVSS 6.5
    jlowin/fastmcpgeneric
    PublishedMar 16, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-28498High
    Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
    CVSS 7.5
    authlib/authlibgeneric
    PublishedMar 16, 2026First seen at HOL Jul 1, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-4224High
    Stack overflow parsing XML with deeply nested DTD content models
    CVSS 7.5
    Python Software Foundation/CPythongeneric
    PublishedMar 16, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-3644High
    Incomplete control character validation in http.cookies
    CVSS 7.5
    Python Software Foundation/CPythongeneric
    PublishedMar 16, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-27962Critical
    Authlib JWS JWK Header Injection: Signature Verification Bypass
    CVSS 9.1
    authlib/authlibgeneric
    PublishedMar 16, 2026First seen at HOL Jul 1, 2026Updated Jul 30, 2026View HOL analysis
  40. CVE-2026-32778Low
    CISA ADP Vulnrichment
    CVSS 2.9
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  41. CVE-2026-32777Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-32776Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 16, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2025-50881High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 16, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2025-14287High
    Command Injection in mlflow/mlflow
    CVSS 8.8
    mlflow/mlflow/mlflowgeneric
    PublishedMar 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-3441Medium
    Binutils: gnu binutils: information disclosure via specially crafted xcoff object file
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 15, 2026First seen at HOL Jun 30, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-3442Medium
    Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 15, 2026First seen at HOL Jun 30, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-3227Medium
    Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
    CVSS 6.8
    TP Link Systems Inc./TL-WR840N v6, TP-Link Systems Inc./TL-WR802N v4 +1generic
    PublishedMar 13, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  48. CVE-2026-3084High
    GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability
    CVSS 7.8
    GStreamer/GStreamergeneric
    PublishedMar 13, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-2921High
    GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GStreamer/GStreamergeneric
    PublishedMar 13, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  50. CVE-2026-3083High
    GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability
    CVSS 8.8
    GStreamer/GStreamergeneric
    PublishedMar 13, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
Page 202 of 356
Previous200201202203204Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard