HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 7:19 AM 38,756 active 1,498 known exploited

Catalog summary

38,756

Active CVEs

19,689

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,151–1,200 of 38,757 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-65651Unknown severity
    temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal
    Not scoredSource severity not reported
    Temporal Technologies, Inc./Temporal Server, Temporal Technologies, Inc./temporalio/sqlparsergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  2. CVE-2026-16651Unknown severity
    temporalio/sqlparser malformed MySQL version comments can cause a panic
    Not scoredSource severity not reported
    Temporal Technologies, Inc./Temporal Server, Temporal Technologies, Inc./temporalio/sqlparsergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  3. CVE-2026-94210Unknown severity
    Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting
    Not scoredSource severity not reported
    Hyve5/Leantimegeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  4. CVE-2026-91867Unknown severity
    Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Neethigeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  5. CVE-2026-91866Unknown severity
    Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Neethigeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  6. CVE-2026-91865Unknown severity
    Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Neethigeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  7. CVE-2026-91864Unknown severity
    Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Neethigeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  8. CVE-2026-91863Unknown severity
    Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service
    Not scoredSource severity not reported
    Apache Software Foundation/Apache Neethigeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  9. CVE-2026-16652Unknown severity
    Temporal Server Schedule exclusion search can cause excessive CPU consumption
    Not scoredSource severity not reported
    Temporal Technologies, Inc./Temporal Servergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  10. CVE-2026-77021Unknown severity
    Missing decompression size limit in agent receiver allows memory exhaustion via push agent data
    Not scoredSource severity not reported
    Checkmk GmbH/Checkmkgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  11. CVE-2026-92612Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Eclipse Foundation/Eclipse iceoryx™, iceoryx2-bb-containercrates.io · generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  12. CVE-2026-92574Unknown severity
    Cri-o: cri-o checkpoint restore bypasses destination security context
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  13. CVE-2026-91921Unknown severity
    Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform
    Not scoredSource severity not reported
    1millionbot/AI Chatbot Platform (SaaS) de 1millionbot.generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  14. CVE-2026-94277Unknown severity
    Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Galaxy Name
    Not scoredSource severity not reported
    MISP/MISPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  15. CVE-2025-12999Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Eclipse Foundation/Eclipse Open VSXgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  16. CVE-2026-92400Unknown severity
    Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion
    Not scoredSource severity not reported
    Unknown/Payment Gateway for PayPal on WooCommercegeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  17. CVE-2026-86802Unknown severity
    To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import
    Not scoredSource severity not reported
    Unknown/To Do List Membergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  18. CVE-2026-85113Unknown severity
    GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name
    Not scoredSource severity not reported
    Unknown/GiveWPgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  19. CVE-2026-85010Unknown severity
    RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons
    Not scoredSource severity not reported
    Unknown/RestroPressgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  20. CVE-2026-94152Medium
    Omega Solution FBP Fulfillment by People User Profile API user authorization
    CVSS 5.3
    Omega Solution/FBP Fulfillment by Peoplegeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  21. CVE-2026-15801High
    Cri-o: cri-o: insufficient validation during container checkpoint restore
    CVSS 8.0
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  22. CVE-2026-94151Unknown severity
    Omega Solution HRM OS Role Permission API permission missing authentication
    Not scoredSource severity not reported
    Omega Solution/HRM OSgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  23. CVE-2026-94150Unknown severity
    Omega Solution HRM OS SVG File Upload view cross site scripting
    Not scoredSource severity not reported
    Omega Solution/HRM OSgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  24. CVE-2026-94149Unknown severity
    Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection
    Not scoredSource severity not reported
    Omega Solution/HRM OSgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  25. CVE-2026-47321Unknown severity
    Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate
    Not scoredSource severity not reported
    Apache Software Foundation/Apache MINAgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  26. CVE-2026-94148Unknown severity
    ScadaBR Export Project Endpoint export_project.htm EmportDwr.createExportJSON information disclosure
    Not scoredSource severity not reported
    n/a/ScadaBRgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  27. CVE-2026-94146Critical
    BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where
    CVSS 9.3
    BioStar/BIOS Update Utilitygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  28. CVE-2026-94218Unknown severity
    Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpoint
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  29. CVE-2026-94217Unknown severity
    Keycloak-services: keycloak-services: uma scope merge across resource owners via resource name collision
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  30. CVE-2026-94145Unknown severity
    xuxueli xxl-job Task Management JobInfoController.java cross site scripting
    Not scoredSource severity not reported
    xuxueli/xxl-jobgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  31. CVE-2026-90860Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Canva/Canvageneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  32. CVE-2026-94144Unknown severity
    drogonframework drogon ORM Criteria.cc makeCriteria sql injection
    Not scoredSource severity not reported
    drogonframework/drogongeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  33. CVE-2026-94215Unknown severity
    Keycloak-services: keycloak-services: cross-realm client read/write via request-level cache missing realm ownership check
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  34. CVE-2026-94213Unknown severity
    Keycloak-services: keycloak-services: authorization services policy evaluation endpoint leaks user identity
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  35. CVE-2026-82187Unknown severity
    WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Upload
    Not scoredSource severity not reported
    Unknown/Web to Print Online Designergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  36. CVE-2026-94143Unknown severity
    drogonframework drogon ORM Mapper Mapper.h orderBy sql injection
    Not scoredSource severity not reported
    drogonframework/drogongeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  37. CVE-2026-94142Unknown severity
    BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where
    Not scoredSource severity not reported
    BioStar/Temperature Monitor Utilitygeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  38. CVE-2026-94139Medium
    Chengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injection
    CVSS 5.3
    Chengdu Feiyuxing Technology/Feiyu Star Routergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  39. CVE-2026-94138Unknown severity
    Chengdu Feiyuxing Technology Feiyu Star Router send_order.cgi command injection
    Not scoredSource severity not reported
    Chengdu Feiyuxing Technology/Feiyu Star Routergeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  40. CVE-2026-94137Unknown severity
    Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of service
    Not scoredSource severity not reported
    Hangzhou Shunwang Technology/shzhgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  41. CVE-2026-94185Unknown severity
    nvm alias resolution follows `..` and discloses files outside $NVM_DIR/alias
    Not scoredSource severity not reported
    nvm-sh/nvmgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  42. CVE-2026-94129Unknown severity
    BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where
    Not scoredSource severity not reported
    BioStar/VALKYRIE AURORAgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  43. CVE-2026-94128Unknown severity
    BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where
    Not scoredSource severity not reported
    BioStar/VIVID LED DJgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  44. CVE-2026-94110Medium
    QCMS Content Detail Controllers.php self_Tmp sql injection
    CVSS 6.9
    n/a/QCMSgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  45. CVE-2026-94103Unknown severity
    RooCMS Frontend Rendering site_pagePHP.php eval code injection
    Not scoredSource severity not reported
    n/a/RooCMSgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  46. CVE-2026-94102Unknown severity
    WuzhiCMS Login index.php redirect
    Not scoredSource severity not reported
    n/a/WuzhiCMSgeneric
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  47. CVE-2026-94101Unknown severity
    Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow
    Not scoredSource severity not reported
    Netcore/NBR200V2generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  48. CVE-2026-94100Unknown severity
    Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow
    Not scoredSource severity not reported
    Netcore/NBR200V2generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
  49. CVE-2026-94099Critical
    Netcore NBR200V2 Backup Restore restore.cgi command injection
    CVSS 9.4
    Netcore/NBR200V2generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 22, 2026View HOL analysis
  50. CVE-2026-94098Unknown severity
    Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection
    Not scoredSource severity not reported
    Netcore/NBR200V2generic
    PublishedSep 21, 2026First seen at HOL Sep 21, 2026Updated Sep 21, 2026View HOL analysis
Page 24 of 776
Previous2223242526Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard