1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 10:20 AM 17,771 active 1,445 known exploited

Catalog summary

17,771

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 10:20 AM 17,771 active 1,445 known exploited

Catalog summary

17,771

Active CVEs

9,101

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,451–10,500 of 17,771 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-65891High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2025-70999High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-71000High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2025-71001Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-24747High
    PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
    CVSS 8.8
    pytorch/pytorchgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-24858High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiAnalyzer, Fortinet/FortiManager +5generic
    PublishedJan 27, 2026First seen at HOL May 24, 2026Updated Jun 9, 2026 Fix availableView HOL analysis
  7. CVE-2026-24882High
    CISA ADP Vulnrichment
    CVSS 8.4
    GnuPG/GnuPGgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2026-24881High
    CISA ADP Vulnrichment
    CVSS 8.1
    GnuPG/GnuPGgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  9. CVE-2025-15467High
    Stack buffer overflow in CMS (Auth)EnvelopedData parsing
    CVSS 8.8
    OpenSSL/OpenSSL, Siemens/AI Lightweight Inference Server +122generic
    PublishedJan 27, 2026First seen at HOL Jul 14, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  10. CVE-2026-24869High
    Use-after-free in the Layout: Scrolling and Overflow component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-21721High
    Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation
    CVSS 8.1
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  12. CVE-2026-21720High
    Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out
    CVSS 7.5
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  13. CVE-2026-24486High
    Python-Multipart has Arbitrary File Write via Non-Default Configuration
    CVSS 8.6
    Kludex/python-multipartgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2025-9820Medium
    Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function
    CVSS 4.0
    Siemens/SIMATIC CN 4100generic
    PublishedJan 26, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  15. CVE-2025-9615Unknown severity
    Networkmanager: networkmanager file access
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedJan 26, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  16. CVE-2025-14459High
    Virt-cdi-controller: unauthorized pvc cloning via dataimportcron
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJan 26, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2025-11065Medium
    Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure
    CVSS 5.3
    github.com/go-viper/mapstructure/v2go
    PublishedJan 26, 2026First seen at HOL Jun 25, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-23864High
    CISA ADP Vulnrichment
    CVSS 7.5
    Meta/react-server-dom-parcel, Meta/react-server-dom-turbopack +1generic
    PublishedJan 26, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-23011Medium
    ipv4: ip_gre: make ipgre_header() robust
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-23010High
    ipv6: Fix use-after-free in inet6_addr_del().
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-23005Medium
    x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-23003High
    ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2025-71163Medium
    dmaengine: idxd: fix device leaks on compat bind and unbind
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2025-71162High
    dmaengine: tegra-adma: Fix use-after-free
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  25. CVE-2025-14843Medium
    Wizit Gateway for WooCommerce <= 1.3.1 - Missing Authentication to Unauthenticated Arbitrary Order Cancellation
    CVSS 5.3
    wizit/Wizit Gateway for WooCommercegeneric
    PublishedJan 24, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-24423Critical
    SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
    CVSS 9.8 Known exploited
    SmarterTools/SmarterMailgeneric
    PublishedJan 23, 2026First seen at HOL May 24, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  27. CVE-2026-22994Medium
    bpf: Fix reference count leak in bpf_prog_test_run_xdp()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  28. CVE-2026-22992High
    libceph: return the handler error from mon_handle_auth_done()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  29. CVE-2026-22982Medium
    net: mscc: ocelot: Fix crash when adding interface under a lag
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  30. CVE-2026-22980High
    nfsd: provide locking for v4_end_grace
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  31. CVE-2026-22979Medium
    net: fix memory leak in skb_segment_list for GRO packets
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  32. CVE-2025-71161Medium
    dm-verity: disable recursive forward error correction
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  33. CVE-2026-0994High
    Denial of Service in Python Protobuf
    CVSS 7.5
    Python/Protobufgeneric
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-0603High
    Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 28, 2026View HOL analysis
  35. CVE-2026-0775High
    npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
    CVSS 7.0
    npm/cligeneric
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-0770High
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
    Not scored Known exploited
    Langflow/Langflowgeneric
    PublishedJan 23, 2026First seen at HOL Aug 2, 2026Updated Jul 24, 2026View HOL analysis
  37. CVE-2025-15059High
    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2025-52022Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2025-52023Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2025-52024Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2025-52025Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  42. CVE-2025-52026High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  43. CVE-2025-67264High
    CISA ADP Vulnrichment
    CVSS 7.8
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2026-20912Critical
    Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure
    CVSS 9.1
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-20897Critical
    Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)
    CVSS 9.1
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-20750Critical
    Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)
    CVSS 9.1
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-20736High
    Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check
    CVSS 7.5
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-1260High
    Invalid Memory Access in Sentencepiece,
    CVSS 7.8
    Google/Sentencepiecegeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2023-7335High
    EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics
    CVSS 8.7
    Hangzhou Kuozhi Network Technology Co., Ltd./EduSohogeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-23760Critical
    SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
    CVSS 9.8 Known exploited
    SmarterTools/SmarterMailgeneric
    PublishedJan 22, 2026First seen at HOL May 24, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
Page 210 of 356
Previous208209210211212Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,101

Critical + high

1,445

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,451–10,500 of 17,771 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-65891High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2025-70999High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-71000High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2025-71001Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJan 28, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2026-24747High
    PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
    CVSS 8.8
    pytorch/pytorchgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-24858High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiAnalyzer, Fortinet/FortiManager +5generic
    PublishedJan 27, 2026First seen at HOL May 24, 2026Updated Jun 9, 2026 Fix availableView HOL analysis
  7. CVE-2026-24882High
    CISA ADP Vulnrichment
    CVSS 8.4
    GnuPG/GnuPGgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2026-24881High
    CISA ADP Vulnrichment
    CVSS 8.1
    GnuPG/GnuPGgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  9. CVE-2025-15467High
    Stack buffer overflow in CMS (Auth)EnvelopedData parsing
    CVSS 8.8
    OpenSSL/OpenSSL, Siemens/AI Lightweight Inference Server +122generic
    PublishedJan 27, 2026First seen at HOL Jul 14, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  10. CVE-2026-24869High
    Use-after-free in the Layout: Scrolling and Overflow component
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-21721High
    Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation
    CVSS 8.1
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  12. CVE-2026-21720High
    Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out
    CVSS 7.5
    Grafana/grafana/grafana, Grafana/grafana/grafana-enterprisegeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  13. CVE-2026-24486High
    Python-Multipart has Arbitrary File Write via Non-Default Configuration
    CVSS 8.6
    Kludex/python-multipartgeneric
    PublishedJan 27, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2025-9820Medium
    Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function
    CVSS 4.0
    Siemens/SIMATIC CN 4100generic
    PublishedJan 26, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  15. CVE-2025-9615Unknown severity
    Networkmanager: networkmanager file access
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedJan 26, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  16. CVE-2025-14459High
    Virt-cdi-controller: unauthorized pvc cloning via dataimportcron
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJan 26, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2025-11065Medium
    Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure
    CVSS 5.3
    github.com/go-viper/mapstructure/v2go
    PublishedJan 26, 2026First seen at HOL Jun 25, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-23864High
    CISA ADP Vulnrichment
    CVSS 7.5
    Meta/react-server-dom-parcel, Meta/react-server-dom-turbopack +1generic
    PublishedJan 26, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-23011Medium
    ipv4: ip_gre: make ipgre_header() robust
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-23010High
    ipv6: Fix use-after-free in inet6_addr_del().
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-23005Medium
    x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-23003High
    ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2025-71163Medium
    dmaengine: idxd: fix device leaks on compat bind and unbind
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2025-71162High
    dmaengine: tegra-adma: Fix use-after-free
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 25, 2026First seen at HOL Jul 14, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  25. CVE-2025-14843Medium
    Wizit Gateway for WooCommerce <= 1.3.1 - Missing Authentication to Unauthenticated Arbitrary Order Cancellation
    CVSS 5.3
    wizit/Wizit Gateway for WooCommercegeneric
    PublishedJan 24, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-24423Critical
    SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
    CVSS 9.8 Known exploited
    SmarterTools/SmarterMailgeneric
    PublishedJan 23, 2026First seen at HOL May 24, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  27. CVE-2026-22994Medium
    bpf: Fix reference count leak in bpf_prog_test_run_xdp()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  28. CVE-2026-22992High
    libceph: return the handler error from mon_handle_auth_done()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  29. CVE-2026-22982Medium
    net: mscc: ocelot: Fix crash when adding interface under a lag
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  30. CVE-2026-22980High
    nfsd: provide locking for v4_end_grace
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  31. CVE-2026-22979Medium
    net: fix memory leak in skb_segment_list for GRO packets
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  32. CVE-2025-71161Medium
    dm-verity: disable recursive forward error correction
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedJan 23, 2026First seen at HOL Jul 14, 2026Updated Jul 30, 2026 Fix availableView HOL analysis
  33. CVE-2026-0994High
    Denial of Service in Python Protobuf
    CVSS 7.5
    Python/Protobufgeneric
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-0603High
    Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 28, 2026View HOL analysis
  35. CVE-2026-0775High
    npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
    CVSS 7.0
    npm/cligeneric
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-0770High
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
    Not scored Known exploited
    Langflow/Langflowgeneric
    PublishedJan 23, 2026First seen at HOL Aug 2, 2026Updated Jul 24, 2026View HOL analysis
  37. CVE-2025-15059High
    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
    CVSS 7.8
    GIMP/GIMPgeneric
    PublishedJan 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2025-52022Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2025-52023Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2025-52024Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2025-52025Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  42. CVE-2025-52026High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  43. CVE-2025-67264High
    CISA ADP Vulnrichment
    CVSS 7.8
    n/a/n/ageneric
    PublishedJan 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2026-20912Critical
    Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure
    CVSS 9.1
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-20897Critical
    Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)
    CVSS 9.1
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-20750Critical
    Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)
    CVSS 9.1
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-20736High
    Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check
    CVSS 7.5
    Gitea/Gitea Open Source Git Servergeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-1260High
    Invalid Memory Access in Sentencepiece,
    CVSS 7.8
    Google/Sentencepiecegeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2023-7335High
    EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics
    CVSS 8.7
    Hangzhou Kuozhi Network Technology Co., Ltd./EduSohogeneric
    PublishedJan 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-23760Critical
    SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
    CVSS 9.8 Known exploited
    SmarterTools/SmarterMailgeneric
    PublishedJan 22, 2026First seen at HOL May 24, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
Page 210 of 356
Previous208209210211212Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard