1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 9:15 AM 17,763 active 1,445 known exploited

Catalog summary

17,763

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 9:15 AM 17,763 active 1,445 known exploited

Catalog summary

17,763

Active CVEs

9,096

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,301–10,350 of 17,763 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-2472High
    Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization
    CVSS 8.1
    Google Cloud/Vertex AI SDK for Pythongeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  2. CVE-2026-2818High
    Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)
    CVSS 8.2
    VMware/Spring Data Gemfire, VMware/Spring Data Geodegeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-26318High
    systeminformation has Command Injection via Unsanitized `locate` Output in `versions()`
    CVSS 8.8
    sebhildebrandt/systeminformationgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-26280High
    Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path
    CVSS 8.4
    sebhildebrandt/systeminformationgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-26278High
    fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
    CVSS 7.5
    NaturalIntelligence/fast-xml-parsergeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  6. CVE-2026-26200High
    HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow
    CVSS 7.8
    HDFGroup/hdf5generic
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-25940High
    jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
    CVSS 8.1
    parallax/jsPDFgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  8. CVE-2026-25755High
    jsPDF has PDF Object Injection via Unsanitized Input in addJS Method
    CVSS 8.1
    parallax/jsPDFgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-25535High
    jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
    CVSS 7.5
    parallax/jsPDFgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  10. CVE-2025-9953Critical
    SQLi in Database Software's Databank Accreditation Software
    CVSS 9.8
    DATABASE Software Training Consulting Ltd./Databank Accreditation Softwaregeneric
    PublishedFeb 19, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  11. CVE-2026-22860High
    Rack has a Directory Traversal via Rack:Directory
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedFeb 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2025-33240High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedFeb 18, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  13. CVE-2025-33239High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedFeb 18, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  14. CVE-2026-24708High
    CISA ADP Vulnrichment
    CVSS 8.2
    OpenStack/Novageneric
    PublishedFeb 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  15. CVE-2026-22769High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Dell/RecoverPoint for Virtual Machinesgeneric
    PublishedFeb 17, 2026First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  16. CVE-2026-24734High
    Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
    CVSS 7.5
    Apache Software Foundation/Apache Tomcat, Apache Software Foundation/Apache Tomcat Native +2generic · maven
    PublishedFeb 17, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2025-65753High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedFeb 17, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  18. CVE-2025-70397High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedFeb 17, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  19. CVE-2026-2447High
    Heap buffer overflow in libvpx
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-23204High
    net/sched: cls_u32: use skb_header_pointer_careful()
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-23185High
    wifi: iwlwifi: mld: cancel mlo_scan_start_wk
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedFeb 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2025-71221High
    dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
    CVSS 7.0
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  23. CVE-2026-23154Medium
    net: fix segmentation of forwarding fraglist GRO
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-23113Medium
    io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-2441High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Chromegeneric
    PublishedFeb 13, 2026First seen at HOL May 24, 2026Updated Mar 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-23111High
    netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
    CVSS 7.8
    Linux/Linux, Siemens/RUGGEDCOM RST2428P +3generic
    PublishedFeb 13, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-25108High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Soliton Systems K.K./FileZengeneric
    PublishedFeb 13, 2026First seen at HOL May 24, 2026Updated Mar 17, 2026View HOL analysis
  28. CVE-2026-2007High
    PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
    CVSS 8.2
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-2006High
    PostgreSQL missing validation of multibyte character length executes arbitrary code
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-2005High
    PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2026-2004High
    PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  32. CVE-2025-41117Unknown severity
    XSS in Grafana Explore stack trace
    Not scoredSource severity not reported
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedFeb 12, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-21722Unknown severity
    Public Dashboards time range restriction on annotations can be bypassed
    Not scoredSource severity not reported
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedFeb 12, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  34. CVE-2025-69752Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedFeb 12, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2026-20644Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-20652High
    CISA ADP Vulnrichment
    CVSS 7.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  37. CVE-2026-20608Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  38. CVE-2026-20700High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedFeb 11, 2026First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  39. CVE-2026-20635Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  40. CVE-2026-20636Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  41. CVE-2026-1669High
    Arbitrary File Read in Keras via HDF5 External Datasets
    CVSS 7.5
    Google/Kerasgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-25990High
    Pillow has an out-of-bounds write when loading PSD images
    CVSS 7.5
    python-pillow/Pillowgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 1, 2026Updated Jul 27, 2026View HOL analysis
  43. CVE-2020-37212High
    SpotMSN 2.4.6 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotMSNgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2020-37211High
    SpotIM 2.2 - 'Name' Denial Of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotIMgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2020-37210High
    SpotIE 2.9.5 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotIEgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2020-37209High
    SpotFTP FTP Password Recovery 3.0.0.0 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotFTP FTP Password Recoverygeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  47. CVE-2020-37208High
    SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotFTP FTP Password Recoverygeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  48. CVE-2020-37207High
    SpotDialup 1.6.7 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotDialupgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2020-37206High
    ShareAlarmPro Advanced Network Access Control - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor ShareAlarmPro Advanced Network Access Controlgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jul 28, 2026View HOL analysis
  50. CVE-2020-37205High
    RemShutdown 2.9.0.0 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor RemShutdowngeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
Page 207 of 356
Previous205206207208209Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,096

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,301–10,350 of 17,763 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-2472High
    Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization
    CVSS 8.1
    Google Cloud/Vertex AI SDK for Pythongeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  2. CVE-2026-2818High
    Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)
    CVSS 8.2
    VMware/Spring Data Gemfire, VMware/Spring Data Geodegeneric
    PublishedFeb 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-26318High
    systeminformation has Command Injection via Unsanitized `locate` Output in `versions()`
    CVSS 8.8
    sebhildebrandt/systeminformationgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-26280High
    Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path
    CVSS 8.4
    sebhildebrandt/systeminformationgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-26278High
    fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
    CVSS 7.5
    NaturalIntelligence/fast-xml-parsergeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  6. CVE-2026-26200High
    HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow
    CVSS 7.8
    HDFGroup/hdf5generic
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-25940High
    jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
    CVSS 8.1
    parallax/jsPDFgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  8. CVE-2026-25755High
    jsPDF has PDF Object Injection via Unsanitized Input in addJS Method
    CVSS 8.1
    parallax/jsPDFgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-25535High
    jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
    CVSS 7.5
    parallax/jsPDFgeneric
    PublishedFeb 19, 2026First seen at HOL Jul 15, 2026Updated Aug 3, 2026View HOL analysis
  10. CVE-2025-9953Critical
    SQLi in Database Software's Databank Accreditation Software
    CVSS 9.8
    DATABASE Software Training Consulting Ltd./Databank Accreditation Softwaregeneric
    PublishedFeb 19, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  11. CVE-2026-22860High
    Rack has a Directory Traversal via Rack:Directory
    CVSS 7.5
    rack, rack/rackgeneric · rubygems
    PublishedFeb 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2025-33240High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedFeb 18, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  13. CVE-2025-33239High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedFeb 18, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  14. CVE-2026-24708High
    CISA ADP Vulnrichment
    CVSS 8.2
    OpenStack/Novageneric
    PublishedFeb 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  15. CVE-2026-22769High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Dell/RecoverPoint for Virtual Machinesgeneric
    PublishedFeb 17, 2026First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  16. CVE-2026-24734High
    Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
    CVSS 7.5
    Apache Software Foundation/Apache Tomcat, Apache Software Foundation/Apache Tomcat Native +2generic · maven
    PublishedFeb 17, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2025-65753High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedFeb 17, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  18. CVE-2025-70397High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedFeb 17, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  19. CVE-2026-2447High
    Heap buffer overflow in libvpx
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedFeb 16, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  20. CVE-2026-23204High
    net/sched: cls_u32: use skb_header_pointer_careful()
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-23185High
    wifi: iwlwifi: mld: cancel mlo_scan_start_wk
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedFeb 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2025-71221High
    dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
    CVSS 7.0
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  23. CVE-2026-23154Medium
    net: fix segmentation of forwarding fraglist GRO
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-23113Medium
    io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-2441High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Chromegeneric
    PublishedFeb 13, 2026First seen at HOL May 24, 2026Updated Mar 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-23111High
    netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
    CVSS 7.8
    Linux/Linux, Siemens/RUGGEDCOM RST2428P +3generic
    PublishedFeb 13, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-25108High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Soliton Systems K.K./FileZengeneric
    PublishedFeb 13, 2026First seen at HOL May 24, 2026Updated Mar 17, 2026View HOL analysis
  28. CVE-2026-2007High
    PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
    CVSS 8.2
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2026-2006High
    PostgreSQL missing validation of multibyte character length executes arbitrary code
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-2005High
    PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2026-2004High
    PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
    CVSS 8.8
    n/a/PostgreSQLgeneric
    PublishedFeb 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  32. CVE-2025-41117Unknown severity
    XSS in Grafana Explore stack trace
    Not scoredSource severity not reported
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedFeb 12, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  33. CVE-2026-21722Unknown severity
    Public Dashboards time range restriction on annotations can be bypassed
    Not scoredSource severity not reported
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedFeb 12, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  34. CVE-2025-69752Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedFeb 12, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2026-20644Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-20652High
    CISA ADP Vulnrichment
    CVSS 7.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  37. CVE-2026-20608Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  38. CVE-2026-20700High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedFeb 11, 2026First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  39. CVE-2026-20635Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  40. CVE-2026-20636Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  41. CVE-2026-1669High
    Arbitrary File Read in Keras via HDF5 External Datasets
    CVSS 7.5
    Google/Kerasgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-25990High
    Pillow has an out-of-bounds write when loading PSD images
    CVSS 7.5
    python-pillow/Pillowgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 1, 2026Updated Jul 27, 2026View HOL analysis
  43. CVE-2020-37212High
    SpotMSN 2.4.6 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotMSNgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2020-37211High
    SpotIM 2.2 - 'Name' Denial Of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotIMgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2020-37210High
    SpotIE 2.9.5 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotIEgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2020-37209High
    SpotFTP FTP Password Recovery 3.0.0.0 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotFTP FTP Password Recoverygeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  47. CVE-2020-37208High
    SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotFTP FTP Password Recoverygeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  48. CVE-2020-37207High
    SpotDialup 1.6.7 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor SpotDialupgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2020-37206High
    ShareAlarmPro Advanced Network Access Control - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor ShareAlarmPro Advanced Network Access Controlgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jul 28, 2026View HOL analysis
  50. CVE-2020-37205High
    RemShutdown 2.9.0.0 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor RemShutdowngeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
Page 207 of 356
Previous205206207208209Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard