HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Oct 1, 2026, 4:19 AM 42,099 active 1,506 known exploited

Catalog summary

42,099

Active CVEs

21,777

Critical + high

1,506

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,351–11,400 of 42,099 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-20509Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  2. CVE-2026-20508Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  3. CVE-2026-20507Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  4. CVE-2026-20506Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  5. CVE-2026-20516Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 22, 2026View HOL analysis
  6. CVE-2026-20504Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  7. CVE-2026-20503Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  8. CVE-2026-20502High
    CISA ADP Vulnrichment
    CVSS 8.4
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  9. CVE-2026-20501High
    CISA ADP Vulnrichment
    CVSS 8.4
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  10. CVE-2026-20500Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    MediaTek, Inc./MediaTek chipsetgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  11. CVE-2026-86245Medium
    itsourcecode Sales and Inventory System sup_transac.php sql injection
    CVSS 6.3
    itsourcecode/Sales and Inventory Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  12. CVE-2026-86244Medium
    FastAdmin User Controller User.php login cross site scripting
    CVSS 4.3
    n/a/FastAdmingeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  13. CVE-2026-86241Medium
    liufee FeehiCMS Cookie Validation main-local.php hard-coded key
    CVSS 4.3
    liufee/FeehiCMSgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 11, 2026View HOL analysis
  14. CVE-2026-86240Medium
    liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery
    CVSS 4.7
    liufee/FeehiCMSgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  15. CVE-2026-16876Critical
    CISA ADP Vulnrichment
    CVSS 9.3
    NEC Corporation/UNIVERGE IX-R/IX-Vgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  16. CVE-2026-86239Medium
    liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload
    CVSS 5.3
    liufee/FeehiCMSgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 9, 2026View HOL analysis
  17. CVE-2026-86238Medium
    projectworlds Online Examination System Feedback Form feedback.php cross site scripting
    CVSS 4.3
    projectworlds/Online Examination Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  18. CVE-2026-86237Medium
    openagents-org openagents http.py test_default_model server-side request forgery
    CVSS 5.3
    openagents-org/openagentsgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 8, 2026View HOL analysis
  19. CVE-2026-86236Medium
    itsourcecode Sales and Inventory System pro_transac.php add sql injection
    CVSS 6.3
    itsourcecode/Sales and Inventory Systemgeneric
    PublishedSep 7, 2026First seen at HOL Sep 7, 2026Updated Sep 11, 2026View HOL analysis
  20. CVE-2026-86235Medium
    itsourcecode Sales and Inventory System pos_transac.php add sql injection
    CVSS 6.3
    itsourcecode/Sales and Inventory Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  21. CVE-2026-86234Medium
    itsourcecode Sales and Inventory System cust_transac.php add sql injection
    CVSS 6.3
    itsourcecode/Sales and Inventory Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 9, 2026View HOL analysis
  22. CVE-2026-86233Medium
    itsourcecode Sales and Inventory System us_del.php sql injection
    CVSS 6.3
    itsourcecode/Sales and Inventory Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  23. CVE-2026-86232Medium
    itsourcecode Sales and Inventory System sup_del.php sql injection
    CVSS 6.3
    itsourcecode/Sales and Inventory Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  24. CVE-2026-86231Low
    mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
    CVSS 3.7
    mwiede/jschgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 11, 2026View HOL analysis
  25. CVE-2026-86228Medium
    JeecgBoot AiragModelController.java exportXls access control
    CVSS 4.3
    n/a/JeecgBootgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  26. CVE-2026-86304Critical
    MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  27. CVE-2026-86227Low
    valkey-io valkey kvstore.c kvstoreGetHashtable out-of-bounds
    CVSS 3.1
    valkey-io/valkeygeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 9, 2026View HOL analysis
  28. CVE-2026-86226Low
    Projectwolds Online Attendance System profile.php cross site scripting
    CVSS 3.5
    Projectwolds/Online Attendance Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  29. CVE-2026-86225High
    SourceCodester Class and Exam Timetabling System modal_add_room.php mysqli_query sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  30. CVE-2026-86224High
    SourceCodester Class and Exam Timetabling System modal_add_product.php mysqli_query sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 11, 2026View HOL analysis
  31. CVE-2026-86223High
    SourceCodester Class and Exam Timetabling System modal_add_coursea.php mysqli_query sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  32. CVE-2026-86222High
    SourceCodester Class and Exam Timetabling System modal_add_course2.php mysqli_query sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 9, 2026View HOL analysis
  33. CVE-2026-86221High
    SourceCodester Class and Exam Timetabling System modal_add_course1.php mysqli_query sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  34. CVE-2026-82209High
    domain-scoped PSL domain cookie
    CVSS 8.2
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  35. CVE-2026-82208High
    wolfSSL CA-cache hit overrides callback
    CVSS 7.5
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-80255High
    secure cookie attribute bypass with tab
    CVSS 7.5
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  37. CVE-2026-80231High
    native CA store conn reuse
    CVSS 7.5
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  38. CVE-2026-80230High
    OpenSSL pinning bypass
    CVSS 7.5
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  39. CVE-2026-80229High
    OpenSSL provider use-after-free
    CVSS 7.5
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  40. CVE-2026-19931Critical
    Negotiate ambient user conn reuse
    CVSS 9.8
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  41. CVE-2026-18924Critical
    HTTP/2 server push UAF
    CVSS 9.1
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-13608High
    OpenLDAP SASL authentication bypass
    CVSS 7.4
    curl/curlgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  43. CVE-2026-86219Critical
    Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  44. CVE-2026-86220High
    SourceCodester Class and Exam Timetabling System modal_add_course.php mysqli_query sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026View HOL analysis
  45. CVE-2026-82750High
    Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation
    CVSS 8.3
    ZenHive/mppgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  46. CVE-2026-82751High
    Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning
    CVSS 8.3
    ZenHive/mppgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  47. CVE-2026-83534Medium
    PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()
    CVSS 6.4
    DALIBO/PostgreSQL Anonymizergeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  48. CVE-2026-19634Medium
    PostgreSQL Anonymizer: SQL injection in import_database_rules() and import_roles_rules() via crafted object names / JSON
    CVSS 6.4
    DALIBO/PostgreSQL Anonymizergeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  49. CVE-2026-19633High
    PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain casts and view subqueries
    CVSS 8.8
    DALIBO/PostgreSQL Anonymizergeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-86217Medium
    code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure
    CVSS 5.3
    code-projects/Hotel and Tourism Reservation in PHPgeneric
    PublishedSep 6, 2026First seen at HOL Sep 6, 2026Updated Sep 11, 2026View HOL analysis
Page 228 of 842
Previous226227228229230Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard