1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 9:30 AM 17,765 active 1,445 known exploited

Catalog summary

17,765

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 9:30 AM 17,765 active 1,445 known exploited

Catalog summary

17,765

Active CVEs

9,096

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,351–10,400 of 17,765 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2020-37206High
    ShareAlarmPro Advanced Network Access Control - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor ShareAlarmPro Advanced Network Access Controlgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jul 28, 2026View HOL analysis
  2. CVE-2020-37205High
    RemShutdown 2.9.0.0 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor RemShutdowngeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2020-37204High
    RemShutdown 2.9.0.0 - 'Key' Denial of Service
    CVSS 7.5
    NSAuditor/Nsauditor RemShutdowngeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2020-37201High
    NetShareWatcher 1.5.8.0 - 'Name' Denial Of Service
    CVSS 7.5
    Nsasoft/Nsauditor NetShareWatchergeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2020-37200High
    NetShareWatcher 1.5.8.0 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor NetShareWatchergeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2020-37199High
    NBMonitor 1.6.6.0 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor NBMonitorgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  7. CVE-2020-37197High
    Dnss Domain Name Search Software - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor Dnss Domain Name Search Softwaregeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  8. CVE-2020-37196High
    Dnss Domain Name Search Software - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor Dnss Domain Name Search Softwaregeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  9. CVE-2026-26158High
    Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entries
    CVSS 7.0
    Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  10. CVE-2026-26157High
    Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization
    CVSS 7.0
    Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  11. CVE-2026-1837High
    libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
    CVSS 7.5
    Google/libjxlgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2025-65480High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedFeb 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  13. CVE-2025-69872Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedFeb 11, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2025-69873Low
    CISA ADP Vulnrichment
    CVSS 2.9
    ajv.js/ajvgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-26007Medium
    cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
    CVSS 6.5
    pyca/cryptographygeneric
    PublishedFeb 10, 2026First seen at HOL Jul 1, 2026Updated Jul 27, 2026View HOL analysis
  16. CVE-2026-25506High
    MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
    CVSS 7.7
    dun/mungegeneric
    PublishedFeb 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-0651High
    Path Traversal on TP-Link Tapo D235, C211, C520WS and C260 via Local https
    CVSS 7.8
    TP Link Systems Inc./Tapo C211 v2, TP Link Systems Inc./Tapo C520WS v2.6 +2generic
    PublishedFeb 10, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  18. CVE-2026-0653Unknown severity
    Insecure Access Control on TP-Link Tapo D235 and C260
    Not scoredSource severity not reported
    TP-Link Systems Inc./Tapo C260 v1, TP-Link Systems Inc./Tapo D235 v1generic
    PublishedFeb 10, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  19. CVE-2026-25646High
    LIBPNG has a heap buffer overflow in png_set_quantize
    CVSS 8.1
    pnggroup/libpnggeneric
    PublishedFeb 10, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  20. CVE-2025-35998High
    CISA ADP Vulnrichment
    CVSS 7.9
    n/a/Intel(R) Platformsgeneric
    PublishedFeb 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2025-68686High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiOSgeneric
    PublishedFeb 10, 2026First seen at HOL Aug 2, 2026Updated Aug 10, 2026View HOL analysis
  22. CVE-2026-1603High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Affected software not mappedEcosystem not listed
    PublishedFeb 10, 2026First seen at HOL May 24, 2026Updated Mar 23, 2026View HOL analysis
  23. CVE-2026-25639High
    Axios affected by Denial of Service via __proto__ Key in mergeConfig
    CVSS 7.5
    axios/axiosgeneric
    PublishedFeb 9, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  24. CVE-2026-1529High
    Org.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validation
    CVSS 8.1
    org.keycloak:keycloak-servicesmaven
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-1486High
    Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant
    CVSS 8.8
    org.keycloak:keycloak-servicesmaven
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  26. CVE-2026-24678High
    FreeRDP has a Heap-use-after-free in cam_v4l_stream_capture_thread
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2025-14831Medium
    Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification
    CVSS 5.3
    Siemens/SIMATIC CN 4100generic
    PublishedFeb 9, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  28. CVE-2026-1615Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/jsonpath, n/a/org.webjars.npm:jsonpathgeneric
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Aug 2, 2026 Fix availableView HOL analysis
  29. CVE-2026-2141Medium
    WuKongOpenSource WukongCRM URL PermissionServiceImpl.java improper authorization
    CVSS 6.3
    WuKongOpenSource/WukongCRMgeneric
    PublishedFeb 8, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  30. CVE-2026-1731High
    Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
    Not scored Known exploited
    BeyondTrust/Remote Support(RS) & Privileged Remote Access(PRA)generic
    PublishedFeb 6, 2026First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  31. CVE-2026-25580High
    Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling
    CVSS 8.6
    pydantic/pydantic-aigeneric
    PublishedFeb 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-25640High
    Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL
    CVSS 7.1
    pydantic/pydantic-aigeneric
    PublishedFeb 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-21643High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiClientEMSgeneric
    PublishedFeb 6, 2026First seen at HOL May 24, 2026Updated Apr 16, 2026View HOL analysis
  34. CVE-2020-37131Medium
    Product Key Explorer 4.2.2.0 - 'Key' Denial of Service
    CVSS 6.2
    Nsauditor/Product Key Explorergeneric
    PublishedFeb 5, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  35. CVE-2020-37121Medium
    CODE::BLOCKS 16.01 - Buffer Overflow (SEH) UNICODE
    CVSS 5.5
    Code::Blocks/Code::Blocksgeneric
    PublishedFeb 5, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2025-61732High
    Potential code smuggling via doc comments in cmd/cgo
    CVSS 8.6
    Go toolchain/cmd/cgogeneric
    PublishedFeb 5, 2026First seen at HOL Jul 8, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  37. CVE-2025-69619Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedFeb 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  38. CVE-2026-25536High
    @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
    CVSS 7.1
    modelcontextprotocol/typescript-sdkgeneric
    PublishedFeb 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-25521High
    Locutus is vulnerable to Prototype Pollution
    CVSS 8.8
    locutusjs/locutusgeneric
    PublishedFeb 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-20111Medium
    Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
    CVSS 4.8
    Cisco/Cisco Prime Infrastructuregeneric
    PublishedFeb 4, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  41. CVE-2026-20123Medium
    Cisco Prime Infrastructure and Evolved Programmable Network Manager Open Redirect Vulnerability
    CVSS 4.3
    Cisco/Cisco Evolved Programmable Network Manager (EPNM), Cisco/Cisco Prime Infrastructuregeneric
    PublishedFeb 4, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-23110Medium
    scsi: core: Wake up the error handler when final completions race against each other
    CVSS 4.7
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-23103High
    ipvlan: Make the addrs_lock be per port
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-23100Medium
    mm/hugetlb: fix hugetlb_pmd_shared()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-23099High
    bonding: limit BOND_MODE_8023AD to Ethernet devices
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedFeb 4, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  46. CVE-2026-23095High
    gue: Fix skb memleak with inner IP protocol 0.
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-23087Medium
    scsi: xen: scsiback: Fix potential memory leak in scsiback_remove()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-23086Medium
    vsock/virtio: cap TX credit to local buffer size
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-23084Medium
    be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2026-23083High
    fou: Don't allow 0 for FOU_ATTR_IPPROTO.
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 208 of 356
Previous206207208209210Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,096

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,351–10,400 of 17,765 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2020-37206High
    ShareAlarmPro Advanced Network Access Control - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor ShareAlarmPro Advanced Network Access Controlgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jul 28, 2026View HOL analysis
  2. CVE-2020-37205High
    RemShutdown 2.9.0.0 - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor RemShutdowngeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2020-37204High
    RemShutdown 2.9.0.0 - 'Key' Denial of Service
    CVSS 7.5
    NSAuditor/Nsauditor RemShutdowngeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2020-37201High
    NetShareWatcher 1.5.8.0 - 'Name' Denial Of Service
    CVSS 7.5
    Nsasoft/Nsauditor NetShareWatchergeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2020-37200High
    NetShareWatcher 1.5.8.0 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor NetShareWatchergeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2020-37199High
    NBMonitor 1.6.6.0 - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor NBMonitorgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  7. CVE-2020-37197High
    Dnss Domain Name Search Software - 'Name' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor Dnss Domain Name Search Softwaregeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  8. CVE-2020-37196High
    Dnss Domain Name Search Software - 'Key' Denial of Service
    CVSS 7.5
    Nsasoft/Nsauditor Dnss Domain Name Search Softwaregeneric
    PublishedFeb 11, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  9. CVE-2026-26158High
    Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entries
    CVSS 7.0
    Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  10. CVE-2026-26157High
    Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization
    CVSS 7.0
    Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  11. CVE-2026-1837High
    libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
    CVSS 7.5
    Google/libjxlgeneric
    PublishedFeb 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2025-65480High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedFeb 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  13. CVE-2025-69872Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedFeb 11, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2025-69873Low
    CISA ADP Vulnrichment
    CVSS 2.9
    ajv.js/ajvgeneric
    PublishedFeb 11, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-26007Medium
    cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
    CVSS 6.5
    pyca/cryptographygeneric
    PublishedFeb 10, 2026First seen at HOL Jul 1, 2026Updated Jul 27, 2026View HOL analysis
  16. CVE-2026-25506High
    MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
    CVSS 7.7
    dun/mungegeneric
    PublishedFeb 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-0651High
    Path Traversal on TP-Link Tapo D235, C211, C520WS and C260 via Local https
    CVSS 7.8
    TP Link Systems Inc./Tapo C211 v2, TP Link Systems Inc./Tapo C520WS v2.6 +2generic
    PublishedFeb 10, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  18. CVE-2026-0653Unknown severity
    Insecure Access Control on TP-Link Tapo D235 and C260
    Not scoredSource severity not reported
    TP-Link Systems Inc./Tapo C260 v1, TP-Link Systems Inc./Tapo D235 v1generic
    PublishedFeb 10, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  19. CVE-2026-25646High
    LIBPNG has a heap buffer overflow in png_set_quantize
    CVSS 8.1
    pnggroup/libpnggeneric
    PublishedFeb 10, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  20. CVE-2025-35998High
    CISA ADP Vulnrichment
    CVSS 7.9
    n/a/Intel(R) Platformsgeneric
    PublishedFeb 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2025-68686High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiOSgeneric
    PublishedFeb 10, 2026First seen at HOL Aug 2, 2026Updated Aug 10, 2026View HOL analysis
  22. CVE-2026-1603High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Affected software not mappedEcosystem not listed
    PublishedFeb 10, 2026First seen at HOL May 24, 2026Updated Mar 23, 2026View HOL analysis
  23. CVE-2026-25639High
    Axios affected by Denial of Service via __proto__ Key in mergeConfig
    CVSS 7.5
    axios/axiosgeneric
    PublishedFeb 9, 2026First seen at HOL Jul 1, 2026Updated Aug 10, 2026View HOL analysis
  24. CVE-2026-1529High
    Org.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validation
    CVSS 8.1
    org.keycloak:keycloak-servicesmaven
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-1486High
    Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant
    CVSS 8.8
    org.keycloak:keycloak-servicesmaven
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  26. CVE-2026-24678High
    FreeRDP has a Heap-use-after-free in cam_v4l_stream_capture_thread
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2025-14831Medium
    Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification
    CVSS 5.3
    Siemens/SIMATIC CN 4100generic
    PublishedFeb 9, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  28. CVE-2026-1615Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/jsonpath, n/a/org.webjars.npm:jsonpathgeneric
    PublishedFeb 9, 2026First seen at HOL Jul 15, 2026Updated Aug 2, 2026 Fix availableView HOL analysis
  29. CVE-2026-2141Medium
    WuKongOpenSource WukongCRM URL PermissionServiceImpl.java improper authorization
    CVSS 6.3
    WuKongOpenSource/WukongCRMgeneric
    PublishedFeb 8, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  30. CVE-2026-1731High
    Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
    Not scored Known exploited
    BeyondTrust/Remote Support(RS) & Privileged Remote Access(PRA)generic
    PublishedFeb 6, 2026First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  31. CVE-2026-25580High
    Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling
    CVSS 8.6
    pydantic/pydantic-aigeneric
    PublishedFeb 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-25640High
    Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL
    CVSS 7.1
    pydantic/pydantic-aigeneric
    PublishedFeb 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-21643High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiClientEMSgeneric
    PublishedFeb 6, 2026First seen at HOL May 24, 2026Updated Apr 16, 2026View HOL analysis
  34. CVE-2020-37131Medium
    Product Key Explorer 4.2.2.0 - 'Key' Denial of Service
    CVSS 6.2
    Nsauditor/Product Key Explorergeneric
    PublishedFeb 5, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  35. CVE-2020-37121Medium
    CODE::BLOCKS 16.01 - Buffer Overflow (SEH) UNICODE
    CVSS 5.5
    Code::Blocks/Code::Blocksgeneric
    PublishedFeb 5, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2025-61732High
    Potential code smuggling via doc comments in cmd/cgo
    CVSS 8.6
    Go toolchain/cmd/cgogeneric
    PublishedFeb 5, 2026First seen at HOL Jul 8, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  37. CVE-2025-69619Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedFeb 5, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  38. CVE-2026-25536High
    @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
    CVSS 7.1
    modelcontextprotocol/typescript-sdkgeneric
    PublishedFeb 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-25521High
    Locutus is vulnerable to Prototype Pollution
    CVSS 8.8
    locutusjs/locutusgeneric
    PublishedFeb 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-20111Medium
    Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
    CVSS 4.8
    Cisco/Cisco Prime Infrastructuregeneric
    PublishedFeb 4, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  41. CVE-2026-20123Medium
    Cisco Prime Infrastructure and Evolved Programmable Network Manager Open Redirect Vulnerability
    CVSS 4.3
    Cisco/Cisco Evolved Programmable Network Manager (EPNM), Cisco/Cisco Prime Infrastructuregeneric
    PublishedFeb 4, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-23110Medium
    scsi: core: Wake up the error handler when final completions race against each other
    CVSS 4.7
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-23103High
    ipvlan: Make the addrs_lock be per port
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-23100Medium
    mm/hugetlb: fix hugetlb_pmd_shared()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-23099High
    bonding: limit BOND_MODE_8023AD to Ethernet devices
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedFeb 4, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  46. CVE-2026-23095High
    gue: Fix skb memleak with inner IP protocol 0.
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-23087Medium
    scsi: xen: scsiback: Fix potential memory leak in scsiback_remove()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-23086Medium
    vsock/virtio: cap TX credit to local buffer size
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-23084Medium
    be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2026-23083High
    fou: Don't allow 0 for FOU_ATTR_IPPROTO.
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedFeb 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 208 of 356
Previous206207208209210Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard