1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 13, 2026, 2:10 PM 18,545 active 1,448 known exploited

Catalog summary

18,545

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 13, 2026, 2:10 PM 18,545 active 1,448 known exploited

Catalog summary

18,545

Active CVEs

9,427

Critical + high

1,448

Known exploited

13

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,601–10,650 of 18,545 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-35385High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenBSD/OpenSSHgeneric
    PublishedApr 2, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  2. CVE-2026-32871Critical
    FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
    CVSS 10.0
    PrefectHQ/fastmcpgeneric
    PublishedApr 2, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-2737Medium
    Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application
    CVSS 6.1
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  4. CVE-2026-3692High
    Unintended command execution during report generation in Progress Flowmon
    CVSS 8.8
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  5. CVE-2026-4636High
    Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-4634High
    Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-4282High
    Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-3872High
    Keycloak: keycloak: information disclosure due to redirect_uri validation bypass
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-23414High
    tls: Purge async_hold in tls_decrypt_async_wait()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 2, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-26895Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-30603Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  12. CVE-2026-3987High
    WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI
    CVSS 8.6
    WatchGuard/Fireware OSgeneric
    PublishedApr 1, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-34545High
    OpenEXR: integer overflow lead to OOB in HTJ2K decoder
    CVSS 7.3
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-27489High
    ONNX: Path Traversal via Symlink
    CVSS 7.5
    onnx/onnxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-20160Critical
    Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
    CVSS 9.8
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2026-20174Medium
    Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
    CVSS 4.9
    Cisco/Cisco Nexus Dashboard, Cisco/Cisco Nexus Dashboard Insightsgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  17. CVE-2026-20151High
    Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
    CVSS 7.3
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-20155High
    Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
    CVSS 8.0
    Cisco/Cisco Evolved Programmable Network Manager (EPNM)generic
    PublishedApr 1, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2026-20042Medium
    Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
    CVSS 6.5
    Cisco/Cisco Nexus Dashboardgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-35093High
    Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-23898Unknown severity
    Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate
    Not scoredSource severity not reported
    Joomla! Project/Joomla! CMSgeneric
    PublishedApr 1, 2026First seen at HOL Aug 12, 2026Updated Aug 12, 2026View HOL analysis
  22. CVE-2026-23401Medium
    KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-29598Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 1, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2021-23337High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  25. CVE-2026-4800High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  26. CVE-2026-34881Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    OpenStack/Glancegeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-34070High
    LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
    CVSS 7.5
    langchain-ai/langchain, langchain-coregeneric · pypi
    PublishedMar 31, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-33997Medium
    Moby: Off-by-one error in plugin privilege validation
    CVSS 6.8
    moby/mobygeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026View HOL analysis
  29. CVE-2026-30277High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2026-30278Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  31. CVE-2026-30279High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  32. CVE-2026-30282Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2026-30283Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2026-30284High
    CISA ADP Vulnrichment
    CVSS 8.6
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2026-33986High
    FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-33984High
    FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-33983Medium
    FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-21710High
    CISA ADP Vulnrichment
    CVSS 7.5
    nodejs/nodegeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  39. CVE-2026-34714Critical
    CISA ADP Vulnrichment
    CVSS 9.2
    Vim/Vimgeneric
    PublishedMar 30, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  40. CVE-2026-3502High
    TrueConf Client Update Integrity Verification Bypass
    Not scored Known exploited
    TrueConf/TrueConf Clientgeneric
    PublishedMar 30, 2026First seen at HOL May 24, 2026Updated Apr 16, 2026View HOL analysis
  41. CVE-2026-4046High
    iconv crash due to assertion failure with untrusted input
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-4315High
    WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI
    CVSS 7.1
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  43. CVE-2026-4266High
    WatchGuard Firebox Insecure Deserialization in Fireware Access Portal
    CVSS 8.4
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-5121High
    Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
    CVSS 7.5
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  45. CVE-2025-15379Critical
    Command Injection in mlflow/mlflow
    CVSS 9.8
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  46. CVE-2026-3945High
    tinyproxy Integer Overflow in HTTP Chunked Transfer-Encoding Parser Leading to Denial of Service
    CVSS 7.5
    tinyproxy/tinyproxygeneric
    PublishedMar 30, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  47. CVE-2025-15036Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 10.0
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  48. CVE-2026-29597Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  49. CVE-2026-30082Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  50. CVE-2026-2370High
    Improper Handling of Parameters in GitLab
    CVSS 8.1
    GitLab/GitLabgeneric
    PublishedMar 29, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 213 of 371
Previous211212213214215Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,427

Critical + high

1,448

Known exploited

13

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 10,601–10,650 of 18,545 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-35385High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenBSD/OpenSSHgeneric
    PublishedApr 2, 2026First seen at HOL Jul 2, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  2. CVE-2026-32871Critical
    FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
    CVSS 10.0
    PrefectHQ/fastmcpgeneric
    PublishedApr 2, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-2737Medium
    Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application
    CVSS 6.1
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  4. CVE-2026-3692High
    Unintended command execution during report generation in Progress Flowmon
    CVSS 8.8
    Progress Software/Flowmongeneric
    PublishedApr 2, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  5. CVE-2026-4636High
    Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-4634High
    Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  7. CVE-2026-4282High
    Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-3872High
    Keycloak: keycloak: information disclosure due to redirect_uri validation bypass
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedApr 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-23414High
    tls: Purge async_hold in tls_decrypt_async_wait()
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 2, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-26895Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-30603Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedApr 2, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  12. CVE-2026-3987High
    WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI
    CVSS 8.6
    WatchGuard/Fireware OSgeneric
    PublishedApr 1, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-34545High
    OpenEXR: integer overflow lead to OOB in HTJ2K decoder
    CVSS 7.3
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-27489High
    ONNX: Path Traversal via Symlink
    CVSS 7.5
    onnx/onnxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-20160Critical
    Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
    CVSS 9.8
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2026-20174Medium
    Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
    CVSS 4.9
    Cisco/Cisco Nexus Dashboard, Cisco/Cisco Nexus Dashboard Insightsgeneric
    PublishedApr 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  17. CVE-2026-20151High
    Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
    CVSS 7.3
    Cisco/Cisco Smart Software Manager On-Premgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-20155High
    Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
    CVSS 8.0
    Cisco/Cisco Evolved Programmable Network Manager (EPNM)generic
    PublishedApr 1, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2026-20042Medium
    Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
    CVSS 6.5
    Cisco/Cisco Nexus Dashboardgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-35093High
    Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedApr 1, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-23898Unknown severity
    Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate
    Not scoredSource severity not reported
    Joomla! Project/Joomla! CMSgeneric
    PublishedApr 1, 2026First seen at HOL Aug 12, 2026Updated Aug 12, 2026View HOL analysis
  22. CVE-2026-23401Medium
    KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedApr 1, 2026First seen at HOL Jul 8, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-29598Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 1, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2021-23337High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  25. CVE-2026-4800High
    lodash vulnerable to Code Injection via `_.template` imports key names
    CVSS 8.1
    lodash, lodash-amd +8generic · npm · rubygems
    PublishedMar 31, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  26. CVE-2026-34881Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    OpenStack/Glancegeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  27. CVE-2026-34070High
    LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
    CVSS 7.5
    langchain-ai/langchain, langchain-coregeneric · pypi
    PublishedMar 31, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-33997Medium
    Moby: Off-by-one error in plugin privilege validation
    CVSS 6.8
    moby/mobygeneric
    PublishedMar 31, 2026First seen at HOL Jul 15, 2026Updated Aug 10, 2026View HOL analysis
  29. CVE-2026-30277High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2026-30278Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  31. CVE-2026-30279High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  32. CVE-2026-30282Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2026-30283Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2026-30284High
    CISA ADP Vulnrichment
    CVSS 8.6
    n/a/n/ageneric
    PublishedMar 31, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2026-33986High
    FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-33984High
    FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-33983Medium
    FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS
    CVSS 6.5
    FreeRDP/FreeRDPgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-21710High
    CISA ADP Vulnrichment
    CVSS 7.5
    nodejs/nodegeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  39. CVE-2026-34714Critical
    CISA ADP Vulnrichment
    CVSS 9.2
    Vim/Vimgeneric
    PublishedMar 30, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  40. CVE-2026-3502High
    TrueConf Client Update Integrity Verification Bypass
    Not scored Known exploited
    TrueConf/TrueConf Clientgeneric
    PublishedMar 30, 2026First seen at HOL May 24, 2026Updated Apr 16, 2026View HOL analysis
  41. CVE-2026-4046High
    iconv crash due to assertion failure with untrusted input
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-4315High
    WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI
    CVSS 7.1
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  43. CVE-2026-4266High
    WatchGuard Firebox Insecure Deserialization in Fireware Access Portal
    CVSS 8.4
    WatchGuard/Fireware OSgeneric
    PublishedMar 30, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-5121High
    Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
    CVSS 7.5
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedMar 30, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  45. CVE-2025-15379Critical
    Command Injection in mlflow/mlflow
    CVSS 9.8
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  46. CVE-2026-3945High
    tinyproxy Integer Overflow in HTTP Chunked Transfer-Encoding Parser Leading to Denial of Service
    CVSS 7.5
    tinyproxy/tinyproxygeneric
    PublishedMar 30, 2026First seen at HOL Aug 5, 2026Updated Aug 10, 2026View HOL analysis
  47. CVE-2025-15036Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 10.0
    mlflow/mlflow/mlflowgeneric
    PublishedMar 30, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  48. CVE-2026-29597Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  49. CVE-2026-30082Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 30, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  50. CVE-2026-2370High
    Improper Handling of Parameters in GitLab
    CVSS 8.1
    GitLab/GitLabgeneric
    PublishedMar 29, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
Page 213 of 371
Previous211212213214215Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard