1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 8:45 AM 17,763 active 1,445 known exploited

Catalog summary

17,763

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 8:45 AM 17,763 active 1,445 known exploited

Catalog summary

17,763

Active CVEs

9,096

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,251–10,300 of 17,763 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-2795Critical
    Use-after-free in the JavaScript: GC component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-2794High
    Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-2793Critical
    Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-2792Critical
    Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-2778Critical
    Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-2777Critical
    Privilege escalation in the Messaging System component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-2776Critical
    Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-2775Critical
    Mitigation bypass in the DOM: HTML Parser component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-2774Critical
    Integer overflow in the Audio/Video component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-2773Critical
    Incorrect boundary conditions in the Web Audio component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-2772Critical
    Use-after-free in the Audio/Video: Playback component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-2771Critical
    Undefined behavior in the DOM: Core & HTML component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2026-2770Critical
    Use-after-free in the DOM: Bindings (WebIDL) component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-2769High
    Use-after-free in the Storage: IndexedDB component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-2768Critical
    Sandbox escape in the Storage: IndexedDB component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-2767Critical
    Use-after-free in the JavaScript: WebAssembly component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-2766Critical
    Use-after-free in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-2765Critical
    Use-after-free in the JavaScript Engine component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-2764Critical
    JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-2763Critical
    Use-after-free in the JavaScript Engine component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-2762Critical
    Integer overflow in the JavaScript: Standard Library component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-2761Critical
    Sandbox escape in the Graphics: WebRender component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-2760Critical
    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-2759Critical
    Incorrect boundary conditions in the Graphics: ImageLib component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-2758Critical
    Use-after-free in the JavaScript: GC component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-2757Critical
    Incorrect boundary conditions in the WebRTC: Audio/Video component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-25985High
    Memory allocation with excessive without limits in the internal SVG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-25969Medium
    ImageMagick has Memory Leak in coders/ashlar.c
    CVSS 5.3
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  29. CVE-2026-25968High
    ImageMagick has MSL attribute stack buffer overflow that leads to out of bounds write.
    CVSS 7.4
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  30. CVE-2026-25965High
    ImageMagick's policy bypass through path traversal allows reading restricted content despite secured policy
    CVSS 8.6
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-25794High
    ImageMagick has heap-buffer-overflow via signed integer overflow in `WriteUHDRImage` when writing UHDR images with large dimensions
    CVSS 8.2
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2025-63409High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedFeb 24, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2025-67445High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedFeb 24, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2026-27623High
    Valkey has Pre-Authentication DOS from malformed RESP request
    CVSS 7.5
    valkey-io/valkeygeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-21863High
    Malformed Valkey Cluster bus message can lead to Remote DoS
    CVSS 7.5
    valkey-io/valkeygeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2025-67733High
    Valkey Affected by RESP Protocol Injection via Lua error_reply
    CVSS 8.5
    valkey-io/valkeygeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2025-14905High
    389-ds-base: 389-ds-base: remote code execution and denial of service via heap buffer overflow
    CVSS 7.2
    Affected software not mappedEcosystem not listed
    PublishedFeb 23, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  38. CVE-2026-25747High
    Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB
    CVSS 8.8
    Apache Software Foundation/Apache Camel LevelDBgeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  39. CVE-2025-71056High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedFeb 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-27134High
    Strimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autentication
    CVSS 8.1
    strimzi/strimzi-kafka-operatorgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2019-25434High
    SpotAuditor 5.3.1.0 Denial of Service via Registration Name Field
    CVSS 7.5
    Nsasoft/Nsauditor SpotAuditorgeneric
    PublishedFeb 20, 2026First seen at HOL Jun 29, 2026Updated Jul 28, 2026View HOL analysis
  42. CVE-2026-2635High
    MLflow Use of Default Password Authentication Bypass Vulnerability
    CVSS 7.3
    MLflow/MLflowgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-2048High
    GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-2047High
    GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-2045High
    GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    CVSS 7.3
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-2044High
    GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability
    CVSS 8.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-2492High
    TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    CVSS 7.8
    TensorFlow/TensorFlowgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-2033High
    MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
    CVSS 7.3
    MLflow/MLflowgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-0797High
    GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 8.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-25896Critical
    fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
    CVSS 9.3
    NaturalIntelligence/fast-xml-parsergeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026View HOL analysis
Page 206 of 356
Previous204205206207208Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,096

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,251–10,300 of 17,763 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-2795Critical
    Use-after-free in the JavaScript: GC component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-2794High
    Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-2793Critical
    Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-2792Critical
    Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-2778Critical
    Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-2777Critical
    Privilege escalation in the Messaging System component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-2776Critical
    Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-2775Critical
    Mitigation bypass in the DOM: HTML Parser component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-2774Critical
    Integer overflow in the Audio/Video component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-2773Critical
    Incorrect boundary conditions in the Web Audio component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-2772Critical
    Use-after-free in the Audio/Video: Playback component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-2771Critical
    Undefined behavior in the DOM: Core & HTML component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2026-2770Critical
    Use-after-free in the DOM: Bindings (WebIDL) component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-2769High
    Use-after-free in the Storage: IndexedDB component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-2768Critical
    Sandbox escape in the Storage: IndexedDB component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-2767Critical
    Use-after-free in the JavaScript: WebAssembly component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-2766Critical
    Use-after-free in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-2765Critical
    Use-after-free in the JavaScript Engine component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-2764Critical
    JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-2763Critical
    Use-after-free in the JavaScript Engine component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-2762Critical
    Integer overflow in the JavaScript: Standard Library component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-2761Critical
    Sandbox escape in the Graphics: WebRender component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-2760Critical
    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-2759Critical
    Incorrect boundary conditions in the Graphics: ImageLib component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-2758Critical
    Use-after-free in the JavaScript: GC component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-2757Critical
    Incorrect boundary conditions in the WebRTC: Audio/Video component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-25985High
    Memory allocation with excessive without limits in the internal SVG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-25969Medium
    ImageMagick has Memory Leak in coders/ashlar.c
    CVSS 5.3
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  29. CVE-2026-25968High
    ImageMagick has MSL attribute stack buffer overflow that leads to out of bounds write.
    CVSS 7.4
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  30. CVE-2026-25965High
    ImageMagick's policy bypass through path traversal allows reading restricted content despite secured policy
    CVSS 8.6
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-25794High
    ImageMagick has heap-buffer-overflow via signed integer overflow in `WriteUHDRImage` when writing UHDR images with large dimensions
    CVSS 8.2
    ImageMagick/ImageMagickgeneric
    PublishedFeb 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2025-63409High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedFeb 24, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2025-67445High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedFeb 24, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2026-27623High
    Valkey has Pre-Authentication DOS from malformed RESP request
    CVSS 7.5
    valkey-io/valkeygeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-21863High
    Malformed Valkey Cluster bus message can lead to Remote DoS
    CVSS 7.5
    valkey-io/valkeygeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2025-67733High
    Valkey Affected by RESP Protocol Injection via Lua error_reply
    CVSS 8.5
    valkey-io/valkeygeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2025-14905High
    389-ds-base: 389-ds-base: remote code execution and denial of service via heap buffer overflow
    CVSS 7.2
    Affected software not mappedEcosystem not listed
    PublishedFeb 23, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  38. CVE-2026-25747High
    Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB
    CVSS 8.8
    Apache Software Foundation/Apache Camel LevelDBgeneric
    PublishedFeb 23, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  39. CVE-2025-71056High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedFeb 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-27134High
    Strimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autentication
    CVSS 8.1
    strimzi/strimzi-kafka-operatorgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2019-25434High
    SpotAuditor 5.3.1.0 Denial of Service via Registration Name Field
    CVSS 7.5
    Nsasoft/Nsauditor SpotAuditorgeneric
    PublishedFeb 20, 2026First seen at HOL Jun 29, 2026Updated Jul 28, 2026View HOL analysis
  42. CVE-2026-2635High
    MLflow Use of Default Password Authentication Bypass Vulnerability
    CVSS 7.3
    MLflow/MLflowgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-2048High
    GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-2047High
    GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-2045High
    GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
    CVSS 7.3
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-2044High
    GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability
    CVSS 8.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-2492High
    TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    CVSS 7.8
    TensorFlow/TensorFlowgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-2033High
    MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
    CVSS 7.3
    MLflow/MLflowgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-0797High
    GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 8.8
    GIMP/GIMPgeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-25896Critical
    fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
    CVSS 9.3
    NaturalIntelligence/fast-xml-parsergeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026View HOL analysis
Page 206 of 356
Previous204205206207208Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard