HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Oct 1, 2026, 3:25 AM 42,094 active 1,506 known exploited

Catalog summary

42,094

Active CVEs

21,775

Critical + high

1,506

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,251–11,300 of 42,094 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-6431High
    User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field
    CVSS 7.2
    cozmoslabs/User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editorgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  2. CVE-2026-4945Medium
    Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypass
    CVSS 5.3
    themeisle/Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSEgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  3. CVE-2026-12853Medium
    Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search
    CVSS 5.4
    rocklobsterinc/Flamingogeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  4. CVE-2026-61410Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    Dell/Secure Connect Gateway 5.0 - Appliance, Dell/Secure Connect Gateway 5.0 - Applicationgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 11, 2026 Fix availableView HOL analysis
  5. CVE-2026-86416Medium
    ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods
    CVSS 5.4
    ILIAS-eLearning e.V./ILIASgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  6. CVE-2026-86418Medium
    MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users
    CVSS 4.3
    MISP/MISPgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 14, 2026View HOL analysis
  7. CVE-2026-61409High
    CISA ADP Vulnrichment
    CVSS 7.3
    Dell/Secure Connect Gateway (SCG) 5.0 Application, Dell/Secure Connect Gateway 5.0 - Appliancegeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-86417Medium
    MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users
    CVSS 4.3
    MISP/MISPgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  9. CVE-2026-86303High
    92181 markdown md.c lds out-of-bounds
    CVSS 7.3
    92181/markdowngeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  10. CVE-2026-86408Medium
    MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected Events
    CVSS 6.5
    MISP/MISPgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  11. CVE-2026-79678High
    Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service
    CVSS 8.1
    Red Hat/idm:DL1/ipa, Red Hat/idm:client/ipa +1generic
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 29, 2026View HOL analysis
  12. CVE-2026-76578Critical
    Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci
    CVSS 9.8
    Red Hat/idm:client/ipa, Red Hat/ipageneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 28, 2026View HOL analysis
  13. CVE-2026-86302Medium
    code-projects Hospital Information System SQL Database Backup File his.sql information disclosure
    CVSS 5.3
    code-projects/Hospital Information Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  14. CVE-2026-78325Medium
    XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import
    CVSS 6.9
    Standard Notes/Standard Notesgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  15. CVE-2026-86301Low
    code-projects Hospital Information System Patient Management editPatient.php cross site scripting
    CVSS 3.5
    code-projects/Hospital Information Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  16. CVE-2026-86404High
    Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default
    CVSS 8.8
    Red Hat/artemis-core-client, Red Hat/artemis-jms-client +3generic
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 25, 2026View HOL analysis
  17. CVE-2026-86300High
    Tenda AC9 Web Management R7WebsSecurityHandler improper authentication
    CVSS 7.3
    Tenda/AC9generic
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  18. CVE-2026-2390Medium
    Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Load Image Processing
    CVSS 6.4
    codesupplyco/Powerkit – Supercharge your WordPress Sitegeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  19. CVE-2026-86299Critical
    Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection
    CVSS 9.9
    Linksys/RE7000generic
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 11, 2026View HOL analysis
  20. CVE-2026-82325Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    OpenVPN/ovpn-dco-wingeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  21. CVE-2026-86298High
    SourceCodester Class and Exam Timetabling System delete_subject.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  22. CVE-2026-77697Medium
    Privilege Escalation
    CVSS 6.3
    Zohocorp/ManageEngine Endpoint Centralgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-86297High
    D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one
    CVSS 8.1
    D-Link/DIR-605generic
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  24. CVE-2026-85640Medium
    Privilege Escalation
    CVSS 6.3
    Zohocorp/ManageEngine Endpoint Centralgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  25. CVE-2025-52657Low
    HCL MyXalytics is affected by multiple security vulnerabilities.
    CVSS 3.5
    HCL Software/MyXalyticsgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  26. CVE-2025-52652Low
    HCL MyXalytics is affected by multiple security vulnerabilities.
    CVSS 3.5
    HCL Software/MyXalyticsgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  27. CVE-2025-52651Low
    HCL MyXalytics is affected by multiple security vulnerabilities.
    CVSS 3.5
    HCL Software/MyXalyticsgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  28. CVE-2026-77699Medium
    Privilege Escalation
    CVSS 5.0
    Zohocorp/ManageEngine Endpoint Centralgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-86296Critical
    D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow
    CVSS 10.0
    D-Link/DIR-822Ageneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  30. CVE-2026-19204High
    CISA ADP Vulnrichment
    CVSS 8.7
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  31. CVE-2026-86295High
    D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection
    CVSS 8.3
    D-Link/DIR-895Lgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  32. CVE-2026-85201Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Eclipse Foundation/Eclipse Ankaiosgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  33. CVE-2026-86294Medium
    SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting
    CVSS 4.3
    SourceCodester/Simple Traffic Offense Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 11, 2026View HOL analysis
  34. CVE-2026-86351Medium
    MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL
    CVSS 6.1
    MISP/MISPgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  35. CVE-2026-77698Medium
    Privilege Escalation
    CVSS 5.7
    Zohocorp/ManageEngine Endpoint Centralgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-86293Medium
    SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authentication
    CVSS 6.5
    SourceCodester/Simple Traffic Offense Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  37. CVE-2026-84173High
    CISA ADP Vulnrichment
    CVSS 8.3
    Eclipse Foundation/Eclipse Ankaiosgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  38. CVE-2026-86347Medium
    MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion
    CVSS 6.5
    MISP/MISPgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  39. CVE-2026-86292High
    SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentication
    CVSS 7.3
    SourceCodester/Simple Traffic Offense Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  40. CVE-2026-86291Medium
    itsourcecode Sales and Inventory System us_edit1.php sql injection
    CVSS 6.3
    itsourcecode/Sales and Inventory Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  41. CVE-2026-86342Medium
    MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Information
    CVSS 4.3
    MISP/MISPgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  42. CVE-2026-86290High
    SourceCodester Online Voting System ajax.php save_category sql injection
    CVSS 7.3
    SourceCodester/Online Voting Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  43. CVE-2026-86289Medium
    Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow
    CVSS 4.3
    n/a/Ollamageneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 11, 2026View HOL analysis
  44. CVE-2026-84186Medium
    Incorrect access control in PrestaShop
    CVSS 6.9
    PrestaShop/PrestaShopgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-86332Medium
    Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  46. CVE-2026-86288Medium
    ModelCloud GPTQModel Triton dequantization kernel tritonv2.py out-of-bounds
    CVSS 6.3
    ModelCloud/GPTQModelgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  47. CVE-2026-84732High
    CISA ADP Vulnrichment
    CVSS 8.7
    OpenVPN/OpenVPNgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  48. CVE-2026-86285Medium
    BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access control
    CVSS 4.3
    n/a/BookStackgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  49. CVE-2026-18796Medium
    QSPI flash encryption side-channel leakage
    CVSS 6.8
    Nordic Semiconductor ASA/nRF5340generic
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 10, 2026View HOL analysis
  50. CVE-2026-14297High
    The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.
    CVSS 8.7
    Nordic Semiconductor ASA/nRF Connect SDKgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
Page 226 of 842
Previous224225226227228Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard