HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 7:18 AM 38,756 active 1,498 known exploited

Catalog summary

38,756

Active CVEs

19,689

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,101–1,150 of 38,756 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-55625Medium
    GoCD is vulnerable to authorization bypass via material connection test APIs
    CVSS 4.9
    gocd/gocdgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  2. CVE-2026-52740Medium
    GoCD is vulnerable to pipeline template view API authorization bypass
    CVSS 5.3
    gocd/gocdgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  3. CVE-2026-55060Low
    GoCD is vulnerable to authorization bypass via support process list API
    CVSS 3.7
    gocd/gocdgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  4. CVE-2026-52741High
    GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages
    CVSS 7.5
    gocd/gocdgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  5. CVE-2026-68919Unknown severity
    GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages
    Not scoredSource severity not reported
    gocd/gocdgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  6. CVE-2026-61628High
    nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition
    CVSS 8.1
    github.com/lucasdillmann/nginx-ignition, lucasdillmann/nginx-ignitiongeneric · go
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  7. CVE-2026-94301Unknown severity
    Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232
    Not scoredSource severity not reported
    Apache Software Foundation/Apache MINAgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  8. CVE-2026-86473Unknown severity
    Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Airflowgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  9. CVE-2026-75158Unknown severity
    Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Airflowgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  10. CVE-2026-82355Unknown severity
    Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Airflowgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  11. CVE-2026-93339Unknown severity
    Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute
    Not scoredSource severity not reported
    Metaphor Creations/Dittygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  12. CVE-2026-52743Medium
    GoCD before 26.1.0 is vulnerable to authorization bypass via job status API
    CVSS 4.3
    gocd/gocdgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  13. CVE-2026-55074High
    Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
    Not scored
    ansible-jailexec, chofstede/ansible_jailexecgeneric · pip · pypi
    PublishedSep 21, 2026First seen at HOL Aug 13, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  14. CVE-2026-55567High
    BleachBit: Exploit File Delete to Escalate Privilege
    CVSS 7.8
    bleachbit/bleachbitgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  15. CVE-2026-61629High
    nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware
    CVSS 7.5
    github.com/lucasdillmann/nginx-ignition, lucasdillmann/nginx-ignitiongeneric · go
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  16. CVE-2026-94184High
    Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 23, 2026View HOL analysis
  17. CVE-2026-61630Medium
    nginx ignition has TOTP Reuse During Validity Window
    CVSS 4.2
    github.com/lucasdillmann/nginx-ignition, lucasdillmann/nginx-ignitiongeneric · go
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  18. CVE-2026-55071High
    MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
    CVSS 8.4
    SepineTam/mcp-for-stata, stata-mcpgeneric · pip · pypi
    PublishedSep 21, 2026First seen at HOL Aug 12, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  19. CVE-2026-54584Medium
    mport trusts environment-controlled temporary directories in privileged metadata extraction
    CVSS 5.3
    MidnightBSD/mportgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  20. CVE-2026-80110Unknown severity
    Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw profile creation endpoint
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  21. CVE-2026-75939Unknown severity
    Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  22. CVE-2026-94404Unknown severity
    MISP CSRF vulnerability allows unauthorized attribute modification
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  23. CVE-2026-88807Unknown severity
    libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow
    Not scoredSource severity not reported
    X.org/libXrendergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  24. CVE-2026-94387Unknown severity
    Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log
    Not scoredSource severity not reported
    aureuserp/aureuserpgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  25. CVE-2025-71421Unknown severity
    UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent
    Not scoredSource severity not reported
    uvdesk/community-skeleton, uvdesk/core-frameworkgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  26. CVE-2025-71420Unknown severity
    UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply
    Not scoredSource severity not reported
    uvdesk/community-skeleton, uvdesk/core-frameworkgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  27. CVE-2025-71419Unknown severity
    UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer
    Not scoredSource severity not reported
    uvdesk/community-skeleton, uvdesk/core-frameworkgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  28. CVE-2026-88806Unknown severity
    libX11 XkbGetMap Reply Heap-based Buffer Overflow
    Not scoredSource severity not reported
    x.org/libX11generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  29. CVE-2026-94401Unknown severity
    MISP Arbitrary Local File Read and SSRF via MISP Export Upload
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  30. CVE-2026-94394Unknown severity
    MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object References
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  31. CVE-2026-94393Unknown severity
    MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  32. CVE-2026-85220Unknown severity
    Denial-of-Service in the Thinkst Canary Redis service
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  33. CVE-2026-94382Unknown severity
    Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts
    Not scoredSource severity not reported
    henrygd/beszelgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  34. CVE-2026-94383Unknown severity
    MISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted File Extension
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  35. CVE-2026-94216Unknown severity
    ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header webserver authorize redirect
    Not scoredSource severity not reported
    ST Engineering iDirect/Evolution, ST Engineering iDirect/Velocity WebServer Evolutiongeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  36. CVE-2026-94381Unknown severity
    MISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via updateLoginTime
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  37. CVE-2026-94379Unknown severity
    MISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP)
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  38. CVE-2026-94374Unknown severity
    MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparenting and Overwriting of Other Events' Reports
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  39. CVE-2026-94373Unknown severity
    MISP DOM-based Cross-Site Scripting via innerHTML in Contextual Menu
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  40. CVE-2026-94214Unknown severity
    ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect
    Not scoredSource severity not reported
    ST Engineering iDirect/Evolution, ST Engineering iDirect/Velocity WebServer Evolutiongeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  41. CVE-2026-84285Unknown severity
    OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5
    Not scoredSource severity not reported
    Dassault Systèmes/Tuleap Enterprise Editiongeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  42. CVE-2026-94372Unknown severity
    Stored Cross-Site Scripting via Unescaped Galaxy Cluster Tag Names in MISP Default Theme Galaxies Index
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  43. CVE-2026-94211Unknown severity
    Hyve5 Leantime Project Dashboard show.blade.php cross site scripting
    Not scoredSource severity not reported
    Hyve5/Leantimegeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  44. CVE-2026-94368Unknown severity
    Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-copy-source header
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  45. CVE-2026-89139Unknown severity
    Temporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service host
    Not scoredSource severity not reported
    Temporal Technologies, Inc./Temporal Servergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  46. CVE-2026-87858Unknown severity
    Temporal Server completion callback source header can direct attacker-chosen requests to the internal frontend with administrator authorization
    Not scoredSource severity not reported
    Temporal Technologies, Inc./Temporal Servergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  47. CVE-2026-65654Unknown severity
    temporalio/ringpop-go fails to enforce configured label limits on inbound membership gossip
    Not scoredSource severity not reported
    Temporal Technologies, Inc./temporalio/ringpop-gogeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  48. CVE-2026-65653Unknown severity
    temporalio/tchannel-go zero-chunk call fragment causes process termination
    Not scoredSource severity not reported
    Temporal Technologies, Inc./temporalio/tchannel-gogeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  49. CVE-2026-65652Unknown severity
    temporalio/tchannel-go malformed checksum type causes process termination
    Not scoredSource severity not reported
    Temporal Technologies, Inc./temporalio/tchannel-gogeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  50. CVE-2026-65651Unknown severity
    temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal
    Not scoredSource severity not reported
    Temporal Technologies, Inc./Temporal Server, Temporal Technologies, Inc./temporalio/sqlparsergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
Page 23 of 776
Previous2122232425Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard