1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:55 AM 17,759 active 1,445 known exploited

Catalog summary

17,759

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:55 AM 17,759 active 1,445 known exploited

Catalog summary

17,759

Active CVEs

9,092

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,151–10,200 of 17,759 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-11739High
    CISA ADP Vulnrichment
    CVSS 7.8
    Schneider Electric/EcoStruxure™ Power Monitoring Expert (PME), Schneider Electric/EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Modulegeneric
    PublishedMar 10, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026View HOL analysis
  2. CVE-2026-3843Critical
    SQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution
    CVSS 9.8
    Nefteprodukttekhnika LLC/BUK TS-G Gas Station Automation Systemgeneric
    PublishedMar 10, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2025-56421High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2025-56422Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-28693High
    ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write
    CVSS 8.1
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-28691High
    ImageMagick has an uninitialized pointer dereference in JBIG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2024-14027Medium
    xattr: switch to CLASS(fd)
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 9, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2026-25604Medium
    Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
    CVSS 5.4
    Apache Software Foundation/Apache Airflow Providers Amazongeneric
    PublishedMar 9, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  9. CVE-2026-3823Critical
    Atop Technologies|EHG2408 series switch - Stack-based Buffer Overflow
    CVSS 9.8
    Atop Technologies/EHG2408, Atop Technologies/EHG2408-2SFPgeneric
    PublishedMar 9, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-29786Medium
    node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
    CVSS 6.3
    isaacs/node-targeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-29186High
    @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
    CVSS 7.7
    backstage/backstagegeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-24308High
    Apache ZooKeeper: Sensitive information disclosure in client configuration handling
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-24281High
    Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
    CVSS 7.4
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2026-25679High
    Incorrect parsing of IPv6 host literals in net/url
    CVSS 7.5
    Go standard library/net/url, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jun 30, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  15. CVE-2026-27137High
    Incorrect enforcement of email constraints in crypto/x509
    CVSS 7.5
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jul 2, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  16. CVE-2026-29063Critical
    Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
    CVSS 9.8
    immutable-js/immutable-jsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2026-29091High
    Locutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code Injection
    CVSS 8.1
    locutusjs/locutusgeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-26017High
    CoreDNS ACL Bypass
    CVSS 7.7
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-26018High
    CoreDNS Loop Detection Denial of Service Vulnerability
    CVSS 7.5
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-1468Medium
    Cross-Site Request Forgery in QuickCMS
    CVSS 5.1
    OpenSolution/QuickCMSgeneric
    PublishedMar 6, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  21. CVE-2026-29074High
    SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
    CVSS 7.5
    svg/svgogeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  22. CVE-2026-29062High
    jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
    CVSS 7.5
    FasterXML/jackson-coregeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-28802Critical
    Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification
    CVSS 9.8
    authlib/authlibgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Jul 20, 2026View HOL analysis
  24. CVE-2025-70363High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 6, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2026-3047High
    Org.keycloak.broker.saml: keycloak saml broker: authentication bypass due to disabled saml client completing idp-initiated login
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-3009High
    Org.keycloak/keycloak-services: improper enforcement of disabled identity provider in identitybrokerservice (authentication bypass)
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  27. CVE-2026-24457Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Eclipse Foundation/Eclipse GlassFish, Eclipse Foundation/Eclipse OpenMQgeneric
    PublishedMar 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-29054High
    Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-26999High
    Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-30783Critical
    RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  31. CVE-2026-30789Critical
    RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2026-30798High
    RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  33. CVE-2026-25048High
    xgrammar: Multi-layer nesting causes DoS
    CVSS 7.5
    mlc-ai/xgrammargeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  34. CVE-2026-30796High
    RustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jul 19, 2026View HOL analysis
  35. CVE-2026-30792High
    RustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings
    CVSS 8.1
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  36. CVE-2026-1605High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  37. CVE-2025-45691High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-2297Medium
    SourcelessFileLoader does not use io.open_code()
    CVSS 5.7
    Python Software Foundation/CPythongeneric
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-66024High
    XWiki Blog Application home page vulnerable to Stored XSS via Post Title
    CVSS 9.0
    org.xwiki.contrib.blog:application-blog-ui, xwiki-contrib/application-blog-uigeneric · maven
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-20131High
    Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
    Not scored Known exploited
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL May 24, 2026Updated Mar 25, 2026View HOL analysis
  41. CVE-2026-20079Unknown severity
    Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-3520High
    Multer vulnerable to Denial of Service via uncontrolled recursion
    CVSS 7.5
    expressjs/multergeneric
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2025-15558High
    Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    CVSS 8.0
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2025-12801Medium
    Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  45. CVE-2025-40894Unknown severity
    HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMar 4, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  46. CVE-2026-23231High
    netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
    CVSS 7.8
    Linux/Linux, Siemens/RUGGEDCOM RST2428P +3generic
    PublishedMar 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-27446Critical
    Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
    CVSS 9.8
    Apache Software Foundation/Apache ActiveMQ Artemis, Apache Software Foundation/Apache Artemis +1generic
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  48. CVE-2026-27622High
    OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
    CVSS 7.8
    AcademySoftwareFoundation/openexrgeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-3437High
    Improper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engineering Toolkits
    CVSS 8.8
    Portwell/Portwell Engineering Toolkitsgeneric
    PublishedMar 3, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  50. CVE-2026-25673High
    Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows
    CVSS 7.5
    djangoproject/Djangogeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 204 of 356
Previous202203204205206Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,092

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,151–10,200 of 17,759 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-11739High
    CISA ADP Vulnrichment
    CVSS 7.8
    Schneider Electric/EcoStruxure™ Power Monitoring Expert (PME), Schneider Electric/EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Modulegeneric
    PublishedMar 10, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026View HOL analysis
  2. CVE-2026-3843Critical
    SQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution
    CVSS 9.8
    Nefteprodukttekhnika LLC/BUK TS-G Gas Station Automation Systemgeneric
    PublishedMar 10, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2025-56421High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2025-56422Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-28693High
    ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write
    CVSS 8.1
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-28691High
    ImageMagick has an uninitialized pointer dereference in JBIG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2024-14027Medium
    xattr: switch to CLASS(fd)
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 9, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2026-25604Medium
    Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
    CVSS 5.4
    Apache Software Foundation/Apache Airflow Providers Amazongeneric
    PublishedMar 9, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  9. CVE-2026-3823Critical
    Atop Technologies|EHG2408 series switch - Stack-based Buffer Overflow
    CVSS 9.8
    Atop Technologies/EHG2408, Atop Technologies/EHG2408-2SFPgeneric
    PublishedMar 9, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-29786Medium
    node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
    CVSS 6.3
    isaacs/node-targeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-29186High
    @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
    CVSS 7.7
    backstage/backstagegeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-24308High
    Apache ZooKeeper: Sensitive information disclosure in client configuration handling
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-24281High
    Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
    CVSS 7.4
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2026-25679High
    Incorrect parsing of IPv6 host literals in net/url
    CVSS 7.5
    Go standard library/net/url, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jun 30, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  15. CVE-2026-27137High
    Incorrect enforcement of email constraints in crypto/x509
    CVSS 7.5
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jul 2, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  16. CVE-2026-29063Critical
    Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
    CVSS 9.8
    immutable-js/immutable-jsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2026-29091High
    Locutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code Injection
    CVSS 8.1
    locutusjs/locutusgeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-26017High
    CoreDNS ACL Bypass
    CVSS 7.7
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-26018High
    CoreDNS Loop Detection Denial of Service Vulnerability
    CVSS 7.5
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-1468Medium
    Cross-Site Request Forgery in QuickCMS
    CVSS 5.1
    OpenSolution/QuickCMSgeneric
    PublishedMar 6, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  21. CVE-2026-29074High
    SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
    CVSS 7.5
    svg/svgogeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  22. CVE-2026-29062High
    jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
    CVSS 7.5
    FasterXML/jackson-coregeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-28802Critical
    Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification
    CVSS 9.8
    authlib/authlibgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Jul 20, 2026View HOL analysis
  24. CVE-2025-70363High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 6, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2026-3047High
    Org.keycloak.broker.saml: keycloak saml broker: authentication bypass due to disabled saml client completing idp-initiated login
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-3009High
    Org.keycloak/keycloak-services: improper enforcement of disabled identity provider in identitybrokerservice (authentication bypass)
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  27. CVE-2026-24457Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Eclipse Foundation/Eclipse GlassFish, Eclipse Foundation/Eclipse OpenMQgeneric
    PublishedMar 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-29054High
    Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-26999High
    Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-30783Critical
    RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  31. CVE-2026-30789Critical
    RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2026-30798High
    RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  33. CVE-2026-25048High
    xgrammar: Multi-layer nesting causes DoS
    CVSS 7.5
    mlc-ai/xgrammargeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  34. CVE-2026-30796High
    RustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jul 19, 2026View HOL analysis
  35. CVE-2026-30792High
    RustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings
    CVSS 8.1
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  36. CVE-2026-1605High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  37. CVE-2025-45691High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-2297Medium
    SourcelessFileLoader does not use io.open_code()
    CVSS 5.7
    Python Software Foundation/CPythongeneric
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-66024High
    XWiki Blog Application home page vulnerable to Stored XSS via Post Title
    CVSS 9.0
    org.xwiki.contrib.blog:application-blog-ui, xwiki-contrib/application-blog-uigeneric · maven
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-20131High
    Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
    Not scored Known exploited
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL May 24, 2026Updated Mar 25, 2026View HOL analysis
  41. CVE-2026-20079Unknown severity
    Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-3520High
    Multer vulnerable to Denial of Service via uncontrolled recursion
    CVSS 7.5
    expressjs/multergeneric
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2025-15558High
    Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    CVSS 8.0
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2025-12801Medium
    Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  45. CVE-2025-40894Unknown severity
    HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMar 4, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  46. CVE-2026-23231High
    netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
    CVSS 7.8
    Linux/Linux, Siemens/RUGGEDCOM RST2428P +3generic
    PublishedMar 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-27446Critical
    Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
    CVSS 9.8
    Apache Software Foundation/Apache ActiveMQ Artemis, Apache Software Foundation/Apache Artemis +1generic
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  48. CVE-2026-27622High
    OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
    CVSS 7.8
    AcademySoftwareFoundation/openexrgeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-3437High
    Improper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engineering Toolkits
    CVSS 8.8
    Portwell/Portwell Engineering Toolkitsgeneric
    PublishedMar 3, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  50. CVE-2026-25673High
    Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows
    CVSS 7.5
    djangoproject/Djangogeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 204 of 356
Previous202203204205206Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard