HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Oct 1, 2026, 9:17 AM 42,173 active 1,506 known exploited

Catalog summary

42,173

Active CVEs

21,823

Critical + high

1,506

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,001–12,050 of 42,173 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-85673High
    LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding
    CVSS 7.5
    hiyouga/LlamaFactorygeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 24, 2026View HOL analysis
  2. CVE-2026-85672Critical
    zerox 1.1.20 OS Command Injection via Document URL File Extension
    CVSS 9.8
    getomni-ai/zeroxgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  3. CVE-2026-85671High
    QAnything 2.0.0 Unauthenticated Cross-User File Disclosure
    CVSS 7.5
    netease-youdao/QAnythinggeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  4. CVE-2026-85670Medium
    tokenizers BpeBuilder Buffer Overflow via merge token
    CVSS 6.5
    huggingface/tokenizersgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 24, 2026View HOL analysis
  5. CVE-2026-85669Medium
    potpie through 2.0.0 Missing Ownership Check via code-changes sync
    CVSS 6.5
    potpie-ai/potpiegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  6. CVE-2026-85668High
    Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register
    CVSS 7.5
    xorbitsai/inferencegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 24, 2026View HOL analysis
  7. CVE-2026-85667Critical
    xiaobei through 5.5.2 Unauthenticated Webhook Message Injection
    CVSS 9.1
    TeamWiseFlow/xiaobeigeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  8. CVE-2026-85666High
    ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url
    CVSS 7.5
    ogx-ai/ogxgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  9. CVE-2026-85665Medium
    Bruno through 4.1.0 Arbitrary File Read via Unconfined Body File Path
    CVSS 6.5
    usebruno/brunogeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  10. CVE-2026-85664High
    Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion
    CVSS 7.5
    chroma-core/chromageneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  11. CVE-2026-85663Critical
    Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch
    CVSS 9.8
    aimhubio/aimgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  12. CVE-2026-85662Medium
    Marqo 2.26.0 Server-Side Request Forgery via Media URLs
    CVSS 5.3
    marqo-ai/marqogeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  13. CVE-2026-85661Critical
    excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode
    CVSS 9.8
    haris-musa/excel-mcp-servergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  14. CVE-2026-85660High
    cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution
    CVSS 8.1
    MladenSU/cli-mcp-servergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 24, 2026View HOL analysis
  15. CVE-2026-85651High
    Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay
    CVSS 8.5
    triggerdotdev/trigger.devgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  16. CVE-2026-85650Medium
    Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel
    CVSS 5.4
    triggerdotdev/trigger.devgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  17. CVE-2026-85626High
    git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters
    CVSS 7.5
    cyanheads/git-mcp-servergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  18. CVE-2026-85625High
    sift 17.1.3 Prototype Pollution Remote Code Execution via $where
    CVSS 8.1
    crcn/sift.jsgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 14, 2026View HOL analysis
  19. CVE-2026-85624Medium
    Blinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceList
    CVSS 6.5
    blinkospace/blinkogeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  20. CVE-2026-85623High
    goose 1.37.0 Arbitrary Command Execution via Recipe Extensions
    CVSS 8.8
    aaif-goose/goosegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  21. CVE-2026-85622Medium
    AppFlowy-Cloud through 0.9.64 Cross-Workspace Collab Read via WebSocket
    CVSS 5.3
    AppFlowy-IO/AppFlowy-Cloudgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  22. CVE-2026-85621Medium
    LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
    CVSS 6.5
    lobehub/lobehubgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 24, 2026View HOL analysis
  23. CVE-2026-85620High
    Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function
    CVSS 8.6
    crystaldba/postgres-mcpgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 24, 2026View HOL analysis
  24. CVE-2026-85619High
    AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API
    CVSS 7.5
    AppFlowy-IO/AppFlowy-Cloudgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  25. CVE-2026-85618Medium
    ConvertX 0.17.0 Arbitrary File Read via LaTeX Input Directives
    CVSS 6.5
    C4illin/ConvertXgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  26. CVE-2026-85608High
    Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter
    CVSS 7.5
    Evil0ctal/Douyin_TikTok_Download_APIgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  27. CVE-2026-85607High
    Blinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC Router
    CVSS 8.8
    blinkospace/blinkogeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  28. CVE-2026-85606High
    firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath
    CVSS 7.5
    firecrawl/firecrawl-mcp-servergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026View HOL analysis
  29. CVE-2026-85605Medium
    Slink before 1.12.3 Missing Authorization on Image Comment Endpoints
    CVSS 5.3
    andrii-kryvoviaz/slinkgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  30. CVE-2026-82728High
    Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS
    CVSS 8.2
    elixir-mint/mintgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-82729Medium
    Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS
    CVSS 6.3
    elixir-mint/mintgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-14466Medium
    Possible XSS in the SNS web administration panel
    CVSS 4.3
    Stormshield/Stormshield Network Securitygeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  33. CVE-2026-9138Medium
    Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  34. CVE-2026-8447Medium
    Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust
    CVSS 6.1
    IBM/Langflow OSSgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  35. CVE-2026-9186Medium
    Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  36. CVE-2026-19205High
    User Enumeration in GastroMenum's GastroMenum Web Panel
    CVSS 7.5
    GastroMenum/GastroMenum Web Panelgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  37. CVE-2026-19727Medium
    HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation System
    CVSS 6.1
    Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc./Library Information and Document Automation Programgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-19081Medium
    Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum's Gastromenum Ticket and QR Menu System
    CVSS 4.3
    Gastromenum/Gastromenum Ticket and QR Menu Systemgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-19057Medium
    Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System
    CVSS 5.4
    Gastromenum/Gastromenum Ticket and QR Menu Systemgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-85522Medium
    valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds
    CVSS 5.3
    valkey-io/valkeygeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  41. CVE-2026-77818Medium
    Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation System
    CVSS 6.1
    Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc./Library Information and Document Automation Programgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-52691High
    Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module
    CVSS 8.8
    Apache Software Foundation/Apache Griffin Hive Metastore Module, Apache Software Foundation/org.apache.griffin:servicegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  43. CVE-2026-85517Medium
    code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql information disclosure
    CVSS 5.3
    code-projects/Vehicle Management Systemgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  44. CVE-2026-12483High
    LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler
    CVSS 7.5
    StellarWP/LearnDash LMSgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  45. CVE-2026-85516High
    code-projects Vehicle Management System busprofile.php sql injection
    CVSS 7.3
    code-projects/Vehicle Management Systemgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 11, 2026View HOL analysis
  46. CVE-2026-85649High
    CISA ADP Vulnrichment
    CVSS 7.9
    chewkeanho/software-actualizergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  47. CVE-2026-85514Medium
    StackStorm st2 API Key auth.py privileges management
    CVSS 6.3
    StackStorm/st2generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026View HOL analysis
  48. CVE-2026-85513Medium
    StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management
    CVSS 6.3
    StackStorm/st2generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  49. CVE-2026-74237Medium
    GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client
    CVSS 6.5
    GFI Software/GFI ClearView, GFI Software/GFI Exinda AIgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  50. CVE-2026-74236Medium
    GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler
    CVSS 6.5
    GFI Software/GFI ClearView, GFI Software/GFI Exinda AIgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
Page 241 of 844
Previous239240241242243Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard