1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:10 PM 18,081 active 1,448 known exploited

Catalog summary

18,081

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 12, 2026, 7:10 PM 18,081 active 1,448 known exploited

Catalog summary

18,081

Active CVEs

9,164

Critical + high

1,448

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,351–11,400 of 18,081 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-60687Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2025-60688Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-60689Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 22, 2026View HOL analysis
  4. CVE-2025-60690High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2025-60691High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  6. CVE-2025-60692High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  7. CVE-2025-60693Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  8. CVE-2025-60694High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  9. CVE-2025-60695Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  10. CVE-2025-60696High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2025-40206Unknown severity
    netfilter: nft_objref: validate objref and objrefmap expressions
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-40205Unknown severity
    btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-40204Unknown severity
    sctp: Fix MAC comparison to be constant-time
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-40203Unknown severity
    listmount: don't call path_put() under namespace semaphore
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-40202Unknown severity
    ipmi: Rework user message limit handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2025-40201Unknown severity
    kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2025-40199Unknown severity
    page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2025-40198Unknown severity
    ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2025-40190Unknown severity
    ext4: guard against EA inode refcount underflow in xattr update
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2025-40187Unknown severity
    net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2025-40186Unknown severity
    tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2025-40183Unknown severity
    bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6}
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2025-40182Unknown severity
    crypto: skcipher - Fix reqsize handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2025-59089Medium
    Python-kdcproxy: remote dos via unbounded tcp upstream buffering
    CVSS 5.9
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  25. CVE-2025-59088High
    Python-kdcproxy: unauthenticated ssrf via realm‑controlled dns srv
    CVSS 8.6
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  26. CVE-2025-40176Unknown severity
    tls: wait for pending async decryptions if tls_strp_msg_hold fails
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2025-40174Unknown severity
    x86/mm: Fix SMP ordering in switch_mm_irqs_off()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2025-40173Unknown severity
    net/ip6_tunnel: Prevent perpetual tunnel growth
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2025-40172Unknown severity
    accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-40171Unknown severity
    nvmet-fc: move lsop put work to nvmet_fc_ls_req_op
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-40170Unknown severity
    net: use dst_dev_rcu() in sk_setup_caps()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-40169Unknown severity
    bpf: Reject negative offsets for ALU ops
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2025-40168Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2025-40167Unknown severity
    ext4: detect invalid INLINE_DATA + EXTENTS flag combination
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2025-40166Unknown severity
    drm/xe/guc: Check GuC running state before deregistering exec queue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2025-40165Unknown severity
    media: nxp: imx8-isi: m2m: Fix streaming cleanup on release
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-40164Medium
    usbnet: Fix using smp_processor_id() in preemptible code warnings
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  38. CVE-2025-40159Unknown severity
    xsk: Harden userspace-supplied xdp_desc validation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-40158Unknown severity
    ipv6: use RCU in ip6_output()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-40155Unknown severity
    iommu/vt-d: debugfs: Fix legacy mode page table dump logic
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-40151Unknown severity
    LoongArch: BPF: No support of struct argument in trampoline programs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-40149High
    tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2025-40141Unknown severity
    Bluetooth: ISO: Fix possible UAF on iso_conn_free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-40140Unknown severity
    net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2025-40139Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2025-40135Unknown severity
    ipv6: use RCU in ip6_xmit()
    Not scoredSource severity not reported
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2025-40133Unknown severity
    mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-40129Unknown severity
    sunrpc: fix null pointer dereference on zero-length checksum
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2025-40124Unknown severity
    sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-40123Unknown severity
    bpf: Enforce expected_attach_type for tailcall compatibility
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 228 of 362
Previous226227228229230Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

9,164

Critical + high

1,448

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,351–11,400 of 18,081 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-60687Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2025-60688Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-60689Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 22, 2026View HOL analysis
  4. CVE-2025-60690High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2025-60691High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  6. CVE-2025-60692High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  7. CVE-2025-60693Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  8. CVE-2025-60694High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  9. CVE-2025-60695Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  10. CVE-2025-60696High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedNov 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2025-40206Unknown severity
    netfilter: nft_objref: validate objref and objrefmap expressions
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-40205Unknown severity
    btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-40204Unknown severity
    sctp: Fix MAC comparison to be constant-time
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-40203Unknown severity
    listmount: don't call path_put() under namespace semaphore
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-40202Unknown severity
    ipmi: Rework user message limit handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2025-40201Unknown severity
    kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2025-40199Unknown severity
    page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2025-40198Unknown severity
    ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2025-40190Unknown severity
    ext4: guard against EA inode refcount underflow in xattr update
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2025-40187Unknown severity
    net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2025-40186Unknown severity
    tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2025-40183Unknown severity
    bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6}
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2025-40182Unknown severity
    crypto: skcipher - Fix reqsize handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2025-59089Medium
    Python-kdcproxy: remote dos via unbounded tcp upstream buffering
    CVSS 5.9
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  25. CVE-2025-59088High
    Python-kdcproxy: unauthenticated ssrf via realm‑controlled dns srv
    CVSS 8.6
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  26. CVE-2025-40176Unknown severity
    tls: wait for pending async decryptions if tls_strp_msg_hold fails
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2025-40174Unknown severity
    x86/mm: Fix SMP ordering in switch_mm_irqs_off()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2025-40173Unknown severity
    net/ip6_tunnel: Prevent perpetual tunnel growth
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2025-40172Unknown severity
    accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-40171Unknown severity
    nvmet-fc: move lsop put work to nvmet_fc_ls_req_op
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-40170Unknown severity
    net: use dst_dev_rcu() in sk_setup_caps()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-40169Unknown severity
    bpf: Reject negative offsets for ALU ops
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2025-40168Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2025-40167Unknown severity
    ext4: detect invalid INLINE_DATA + EXTENTS flag combination
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2025-40166Unknown severity
    drm/xe/guc: Check GuC running state before deregistering exec queue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2025-40165Unknown severity
    media: nxp: imx8-isi: m2m: Fix streaming cleanup on release
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-40164Medium
    usbnet: Fix using smp_processor_id() in preemptible code warnings
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  38. CVE-2025-40159Unknown severity
    xsk: Harden userspace-supplied xdp_desc validation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-40158Unknown severity
    ipv6: use RCU in ip6_output()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-40155Unknown severity
    iommu/vt-d: debugfs: Fix legacy mode page table dump logic
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-40151Unknown severity
    LoongArch: BPF: No support of struct argument in trampoline programs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-40149High
    tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2025-40141Unknown severity
    Bluetooth: ISO: Fix possible UAF on iso_conn_free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-40140Unknown severity
    net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2025-40139Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2025-40135Unknown severity
    ipv6: use RCU in ip6_xmit()
    Not scoredSource severity not reported
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2025-40133Unknown severity
    mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-40129Unknown severity
    sunrpc: fix null pointer dereference on zero-length checksum
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2025-40124Unknown severity
    sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-40123Unknown severity
    bpf: Enforce expected_attach_type for tailcall compatibility
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 228 of 362
Previous226227228229230Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard