HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Oct 1, 2026, 5:57 AM 42,123 active 1,506 known exploited

Catalog summary

42,123

Active CVEs

21,789

Critical + high

1,506

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,601–11,650 of 42,123 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-77233High
    iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite
    CVSS 7.2
    iubenda/iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + moregeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  2. CVE-2025-14945Medium
    Events Manager - Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes
    CVSS 5.4
    netweblogic/Events Manager – Calendar, Bookings, Tickets, and more!generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  3. CVE-2026-8625Medium
    Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML
    CVSS 6.4
    dearhive/DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewergeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  4. CVE-2026-83628Medium
    Theme My Login <= 7.1.15 - Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage
    CVSS 4.3
    jfarthing84/Theme My Logingeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  5. CVE-2026-83627Critical
    Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log
    CVSS 9.8
    wpmudev/Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDNgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  6. CVE-2026-13447Critical
    MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery
    CVSS 9.8
    inspireui/MStore API – Create Native Android & iOS Apps On The Cloudgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  7. CVE-2026-8623Medium
    Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute
    CVSS 6.4
    dearhive/DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewergeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  8. CVE-2026-86145High
    CVE Program Container
    CVSS 8.2
    PCRE/PCRE2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  9. CVE-2026-86144Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  10. CVE-2026-86143Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  11. CVE-2026-86142Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-86141Low
    CISA ADP Vulnrichment
    CVSS 2.9
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-86140High
    CISA ADP Vulnrichment
    CVSS 8.0
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  14. CVE-2026-86139Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  15. CVE-2026-86138Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-86137Low
    CISA ADP Vulnrichment
    CVSS 2.9
    xmlsoft/libxml2generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  17. CVE-2026-52777Critical
    YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize
    CVSS 9.4
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-52775High
    YesWiki Authenticated SQL Injection in ReactionManager
    CVSS 8.8
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-52774Medium
    Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
    CVSS 6.1
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  20. CVE-2026-52773Medium
    Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki
    CVSS 6.1
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  21. CVE-2026-52772Medium
    YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)
    CVSS 5.5
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  22. CVE-2026-52771High
    YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
    CVSS 8.3
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-52770High
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki
    CVSS 7.5
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  24. CVE-2026-52769High
    YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
    CVSS 8.3
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  25. CVE-2026-52767High
    YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
    CVSS 8.2
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-52766Critical
    YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
    CVSS 9.1
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  27. CVE-2026-52763Medium
    YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read
    CVSS 6.5
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  28. CVE-2026-52762High
    YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
    CVSS 7.1
    YesWiki/yeswiki, yeswiki/yeswikicomposer · generic
    PublishedSep 4, 2026First seen at HOL Jul 10, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-86100Medium
    Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL
    CVSS 6.4
    owen2345/CamaleonCMSgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-86098High
    ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape
    CVSS 7.4
    ntop/nDPIgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  31. CVE-2026-86097Medium
    PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select
    CVSS 6.5
    PX4/PX4-Autopilotgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  32. CVE-2026-86096Medium
    PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup
    CVSS 5.9
    PX4/PX4-Autopilotgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  33. CVE-2026-86095High
    Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name
    CVSS 7.8
    Unidata/netcdf-cgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 24, 2026View HOL analysis
  34. CVE-2026-48019High
    CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay
    CVSS 8.9
    laravel/frameworkcomposer · generic · packagist
    PublishedSep 4, 2026First seen at HOL Jun 19, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-46636High
    Twig: Sandbox method allowlist bypass via `Markup` subclass
    CVSS 8.7
    twigphp/Twiggeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  36. CVE-2026-86091High
    ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler
    CVSS 7.1
    ntop/ntopnggeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  37. CVE-2026-86090High
    ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers
    CVSS 7.1
    ntop/ntopnggeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  38. CVE-2026-75925Critical
    IXON VPN Client CRLF Injection
    CVSS 9.6
    IXON/IXON VPN Clientgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-77393High
    Inductive Automation Ignition Incorrect Default Permissions
    CVSS 8.8
    Inductive Automation/Ignitiongeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  40. CVE-2026-76925Medium
    Flatpak: flatpak: toctou race condition allows symlink redirection
    CVSS 5.8
    Affected software not mappedEcosystem not listed
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  41. CVE-2026-82684High
    Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization
    CVSS 8.1
    Tycon Systems/TPDIN-Monitor-WEB3generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  42. CVE-2026-85704Low
    ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition
    CVSS 3.7
    ramon-victor/freegpt-webuigeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  43. CVE-2026-82712High
    Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery
    CVSS 8.8
    Tycon Systems/TPDIN-Monitor-WEB3generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  44. CVE-2026-77847Medium
    Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials
    CVSS 6.5
    Tycon Systems/TPDIN-Monitor-WEB3generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 9, 2026View HOL analysis
  45. CVE-2026-63733Medium
    SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
    CVSS 4.3
    surrealdb-corerust
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026 Fix availableView HOL analysis
  46. CVE-2026-85703Medium
    ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources
    CVSS 6.5
    ramon-victor/freegpt-webuigeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 11, 2026View HOL analysis
  47. CVE-2026-85702High
    ramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing authentication
    CVSS 7.3
    ramon-victor/freegpt-webuigeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  48. CVE-2026-85701Medium
    ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authentication
    CVSS 5.3
    ramon-victor/freegpt-webuigeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  49. CVE-2026-63735High
    SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
    CVSS 8.1
    surrealdbrust
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026 Fix availableView HOL analysis
  50. CVE-2026-85787Medium
    An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server
    CVSS 6.5
    Amazon/postgres-mcp-servergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
Page 233 of 843
Previous231232233234235Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard