1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 5:15 PM 20,221 active 1,448 known exploited

Catalog summary

20,221

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 5:15 PM 20,221 active 1,448 known exploited

Catalog summary

20,221

Active CVEs

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,901–11,950 of 20,221 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-31504High
    net: fix fanout UAF in packet_release() via NETDEV_UP race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-31503Medium
    udp: Fix wildcard bind conflict check when using hash2
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-31496Medium
    netfilter: nf_conntrack_expect: skip expectations in other netns via proc
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-31495Medium
    netfilter: ctnetlink: use netlink policy range checks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-31494High
    net: macb: use the current queue number for stats
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-31489High
    spi: meson-spicc: Fix double-put in remove path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  7. CVE-2026-31488High
    drm/amd/display: Do not skip unrelated mode changes in DSC validation
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 10, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  8. CVE-2026-31486High
    hwmon: (pmbus/core) Protect regulator operations with mutex
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  9. CVE-2026-31485High
    spi: spi-fsl-lpspi: fix teardown order issue (UAF)
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-31474High
    can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  11. CVE-2026-31469High
    virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  12. CVE-2026-31466Medium
    mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
    CVSS 4.7
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  13. CVE-2026-31452High
    ext4: convert inline data to extents when truncate exceeds inline size
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31450High
    ext4: publish jinode after initialization
    CVSS 8.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-31449High
    ext4: validate p_idx bounds in ext4_ext_correct_indexes
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  16. CVE-2026-31448Critical
    ext4: avoid infinite loops caused by residual data
    CVSS 9.4
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-31447High
    ext4: reject mount if bigalloc with s_first_data_block != 0
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-31446High
    ext4: fix use-after-free in update_super_work when racing with umount
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-31441Medium
    dmaengine: idxd: Fix memory leak when a wq is reset
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-41651High
    PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
    CVSS 8.8
    PackageKit/PackageKitgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-31432High
    ksmbd: fix OOB write in QUERY_INFO for compound requests
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  22. CVE-2026-31431High
    crypto: algif_aead - Revert to operating out-of-place
    CVSS 7.8 Known exploited
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedApr 22, 2026First seen at HOL May 24, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-6845Medium
    Binutils: binutils: denial of service via crafted elf file
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedApr 22, 2026First seen at HOL Jul 2, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-6235Critical
    Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests
    CVSS 9.8
    sendmachine/Sendmachine for WordPressgeneric
    PublishedApr 22, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-40542High
    Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
    CVSS 7.3
    Apache Software Foundation/Apache HttpClientgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  26. CVE-2026-22754High
    ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
    CVSS 7.5
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-22747Medium
    Unauthorized User Impersonation when Using X.509 Client Certificates
    CVSS 6.8
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-40575Critical
    OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
    CVSS 9.1
    oauth2-proxy/oauth2-proxygeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-40938High
    Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
    CVSS 7.5
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedApr 21, 2026First seen at HOL Jul 8, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  30. CVE-2026-34282High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-22016High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-40906Critical
    Electric: SQL Injection via ORDER BY Parameter in Shape API
    CVSS 9.9
    electric-sql/electricgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-40895High
    follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets
    CVSS 7.5
    follow-redirects/follow-redirectsgeneric
    PublishedApr 21, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  34. CVE-2026-33813High
    Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/webpgeneric
    PublishedApr 21, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  35. CVE-2026-40372Critical
    ASP.NET Core Elevation of Privilege Vulnerability
    CVSS 9.1
    Microsoft/ASP.NET Core 10.0, Microsoft/Microsoft Visual Studio 2026 version 18.5generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  36. CVE-2026-40611High
    Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
    CVSS 8.8
    go-acme/legogeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-3298High
    Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
    CVSS 8.8
    Python Software Foundation/CPythongeneric
    PublishedApr 21, 2026First seen at HOL Aug 5, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-40244High
    OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)
    CVSS 7.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-31018High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-31019High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2026-22051Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    NETAPP/StorageGRID (formerly StorageGRID Webscale)generic
    PublishedApr 20, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-5450Critical
    scanf %mc off-by-one heap buffer overflow
    CVSS 9.8
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-5928High
    Potential buffer under-read in ungetwc
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-35154Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    Dell/PowerProtect Data Domain appliancesgeneric
    PublishedApr 20, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  45. CVE-2026-41245Medium
    Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
    CVSS 5.9
    junrar/junrargeneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  46. CVE-2026-33557Critical
    Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
    CVSS 9.1
    Apache Software Foundation/Apache Kafkageneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-30266High
    CISA ADP Vulnrichment
    CVSS 7.8
    n/a/n/ageneric
    PublishedApr 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  48. CVE-2026-41242Critical
    protobufjs has an arbitrary code execution issue
    CVSS 9.8
    protobufjs/protobuf.jsgeneric
    PublishedApr 18, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-40478Critical
    Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  50. CVE-2026-40477Critical
    Improper restriction of the scope of accessible objects in Thymeleaf expressions
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
Page 239 of 405
Previous237238239240241Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,901–11,950 of 20,221 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-31504High
    net: fix fanout UAF in packet_release() via NETDEV_UP race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-31503Medium
    udp: Fix wildcard bind conflict check when using hash2
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  3. CVE-2026-31496Medium
    netfilter: nf_conntrack_expect: skip expectations in other netns via proc
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-31495Medium
    netfilter: ctnetlink: use netlink policy range checks
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-31494High
    net: macb: use the current queue number for stats
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-31489High
    spi: meson-spicc: Fix double-put in remove path
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  7. CVE-2026-31488High
    drm/amd/display: Do not skip unrelated mode changes in DSC validation
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 10, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  8. CVE-2026-31486High
    hwmon: (pmbus/core) Protect regulator operations with mutex
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  9. CVE-2026-31485High
    spi: spi-fsl-lpspi: fix teardown order issue (UAF)
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2026-31474High
    can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  11. CVE-2026-31469High
    virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  12. CVE-2026-31466Medium
    mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
    CVSS 4.7
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  13. CVE-2026-31452High
    ext4: convert inline data to extents when truncate exceeds inline size
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  14. CVE-2026-31450High
    ext4: publish jinode after initialization
    CVSS 8.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  15. CVE-2026-31449High
    ext4: validate p_idx bounds in ext4_ext_correct_indexes
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  16. CVE-2026-31448Critical
    ext4: avoid infinite loops caused by residual data
    CVSS 9.4
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-31447High
    ext4: reject mount if bigalloc with s_first_data_block != 0
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-31446High
    ext4: fix use-after-free in update_super_work when racing with umount
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-31441Medium
    dmaengine: idxd: Fix memory leak when a wq is reset
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 22, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-41651High
    PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
    CVSS 8.8
    PackageKit/PackageKitgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-31432High
    ksmbd: fix OOB write in QUERY_INFO for compound requests
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 22, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  22. CVE-2026-31431High
    crypto: algif_aead - Revert to operating out-of-place
    CVSS 7.8 Known exploited
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedApr 22, 2026First seen at HOL May 24, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-6845Medium
    Binutils: binutils: denial of service via crafted elf file
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedApr 22, 2026First seen at HOL Jul 2, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-6235Critical
    Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests
    CVSS 9.8
    sendmachine/Sendmachine for WordPressgeneric
    PublishedApr 22, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-40542High
    Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
    CVSS 7.3
    Apache Software Foundation/Apache HttpClientgeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  26. CVE-2026-22754High
    ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
    CVSS 7.5
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-22747Medium
    Unauthorized User Impersonation when Using X.509 Client Certificates
    CVSS 6.8
    Spring/Spring Securitygeneric
    PublishedApr 22, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-40575Critical
    OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
    CVSS 9.1
    oauth2-proxy/oauth2-proxygeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-40938High
    Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
    CVSS 7.5
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedApr 21, 2026First seen at HOL Jul 8, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  30. CVE-2026-34282High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-22016High
    CISA ADP Vulnrichment
    CVSS 7.5
    Oracle Corporation/Oracle GraalVM Enterprise Edition, Oracle Corporation/Oracle GraalVM for JDK +1generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-40906Critical
    Electric: SQL Injection via ORDER BY Parameter in Shape API
    CVSS 9.9
    electric-sql/electricgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-40895High
    follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets
    CVSS 7.5
    follow-redirects/follow-redirectsgeneric
    PublishedApr 21, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  34. CVE-2026-33813High
    Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image
    CVSS 7.5
    golang.org/x/image/golang.org/x/image/webpgeneric
    PublishedApr 21, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  35. CVE-2026-40372Critical
    ASP.NET Core Elevation of Privilege Vulnerability
    CVSS 9.1
    Microsoft/ASP.NET Core 10.0, Microsoft/Microsoft Visual Studio 2026 version 18.5generic
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  36. CVE-2026-40611High
    Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
    CVSS 8.8
    go-acme/legogeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-3298High
    Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
    CVSS 8.8
    Python Software Foundation/CPythongeneric
    PublishedApr 21, 2026First seen at HOL Aug 5, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-40244High
    OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)
    CVSS 7.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedApr 21, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-31018High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-31019High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 21, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2026-22051Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    NETAPP/StorageGRID (formerly StorageGRID Webscale)generic
    PublishedApr 20, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-5450Critical
    scanf %mc off-by-one heap buffer overflow
    CVSS 9.8
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-5928High
    Potential buffer under-read in ungetwc
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedApr 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-35154Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    Dell/PowerProtect Data Domain appliancesgeneric
    PublishedApr 20, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  45. CVE-2026-41245Medium
    Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
    CVSS 5.9
    junrar/junrargeneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  46. CVE-2026-33557Critical
    Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
    CVSS 9.1
    Apache Software Foundation/Apache Kafkageneric
    PublishedApr 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-30266High
    CISA ADP Vulnrichment
    CVSS 7.8
    n/a/n/ageneric
    PublishedApr 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  48. CVE-2026-41242Critical
    protobufjs has an arbitrary code execution issue
    CVSS 9.8
    protobufjs/protobuf.jsgeneric
    PublishedApr 18, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-40478Critical
    Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  50. CVE-2026-40477Critical
    Improper restriction of the scope of accessible objects in Thymeleaf expressions
    CVSS 9.0
    thymeleaf/org.thymeleaf:thymeleaf-spring5, thymeleaf/org.thymeleaf:thymeleaf-spring6 +1generic
    PublishedApr 17, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
Page 239 of 405
Previous237238239240241Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard