1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 3:23 PM 20,217 active 1,448 known exploited

Catalog summary

20,217

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 3:23 PM 20,217 active 1,448 known exploited

Catalog summary

20,217

Active CVEs

10,110

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,051–12,100 of 20,217 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-34481High
    Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
    CVSS 7.5
    Apache Software Foundation/Apache Log4j JSON Template Layout, org.apache.logging.log4j:log4j-layout-template-jsongeneric · maven
    PublishedApr 10, 2026First seen at HOL Jul 11, 2026Updated Jul 11, 2026 Fix availableView HOL analysis
  2. CVE-2026-40217High
    CISA ADP Vulnrichment
    CVSS 8.8
    BerriAI/LiteLLMgeneric
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-39304High
    Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
    CVSS 7.5
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +2generic
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-39848Medium
    Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation
    CVSS 6.5
    10ij/dockyardgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  5. CVE-2026-33784Critical
    JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
    CVSS 9.8
    Juniper Networks/JSI LWCgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-33774Medium
    Junos OS: MX Series: Firewall filters on lo0.<non-0> in the default routing instance are not in effect
    CVSS 6.5
    Juniper Networks/Junos OSgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-33771High
    CTP OS: Configuring password requirements does not work which permits the use of weak passwords
    CVSS 7.4
    Juniper Networks/CTP OSgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2025-13914High
    Apstra: SSH host key validation vulnerability for managed devices
    CVSS 8.7
    Juniper Networks/Apstrageneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-33788High
    Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs
    CVSS 7.8
    Juniper Networks/Junos OS Evolvedgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-21915Medium
    JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root
    CVSS 6.7
    Juniper Networks/JSI LWCgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-21904Medium
    Junos Space: ilpFilter field on nLegacy.jsp is vulnerable to reflected cross-site script injection
    CVSS 6.1
    Juniper Networks/Junos Spacegeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-34486High
    Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
    CVSS 7.5 Known exploited
    Apache Software Foundation/Apache Tomcat, org.apache.tomcat:tomcat +1generic · maven
    PublishedApr 9, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-29146High
    Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
    CVSS 7.5
    Apache Software Foundation/Apache Tomcat, org.apache.tomcat:tomcat +1generic · maven
    PublishedApr 9, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-34734High
    HDF5: H5T__conv_struct Use After Free
    CVSS 7.8
    HDFGroup/hdf5generic
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-34971High
    Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
    CVSS 7.8
    bytecodealliance/wasmtimegeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-1584High
    Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-39987High
    marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
    Not scored Known exploited
    marimo-team/marimogeneric
    PublishedApr 9, 2026First seen at HOL May 24, 2026Updated May 7, 2026View HOL analysis
  18. CVE-2026-39983High
    FTP Command Injection via CRLF in basic-ftp
    CVSS 8.6
    patrickjuchli/basic-ftpgeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-39962Critical
    LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
    CVSS 9.6
    MISP/MISPgeneric
    PublishedApr 9, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  20. CVE-2026-35205High
    Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
    CVSS 7.8
    helm/helmgeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-35204High
    Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
    CVSS 8.6
    helm/helmgeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-4878Medium
    Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()
    CVSS 6.7
    Affected software not mappedEcosystem not listed
    PublishedApr 9, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  23. CVE-2025-62718Critical
    Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
    CVSS 9.9
    axios/axiosgeneric
    PublishedApr 9, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  24. CVE-2026-4660High
    Go-getter may allow to arbitrary filesystem reads through git operations
    CVSS 7.5
    HashiCorp/Toolinggeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-34185High
    SQL Injection in AlanWeb SCADA
    CVSS 8.8
    Control System/AlanWeb SCADAgeneric
    PublishedApr 9, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  26. CVE-2026-34184Critical
    Missing Authorization inAlanWeb SCADA
    CVSS 9.1
    Control System/AlanWeb SCADAgeneric
    PublishedApr 9, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-4901Medium
    Insertion of Sesitive Information into Log File in AlanWeb SCADA
    CVSS 6.5
    Control System/AlanWeb SCADAgeneric
    PublishedApr 9, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  28. CVE-2025-70364High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 9, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  29. CVE-2025-70365Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 9, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2026-39892Critical
    cryptography has a buffer overflow if non-contiguous buffers were passed to APIs
    CVSS 9.8
    cryptography, pyca/cryptographygeneric · pip
    PublishedApr 8, 2026First seen at HOL Jun 11, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  31. CVE-2026-39883High
    OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijacking
    CVSS 7.0
    open-telemetry/opentelemetry-gogeneric
    PublishedApr 8, 2026First seen at HOL Jul 10, 2026Updated Aug 14, 2026View HOL analysis
  32. CVE-2026-23869High
    CISA ADP Vulnrichment
    CVSS 7.5
    Meta/react-server-dom-parcel, Meta/react-server-dom-turbopack +1generic
    PublishedApr 8, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-32591Medium
    Mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
    CVSS 5.2
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jul 15, 2026Updated Aug 12, 2026View HOL analysis
  34. CVE-2026-32590High
    Mirror-registry: remote code execution using pickle deserialization
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jun 23, 2026Updated Aug 11, 2026View HOL analysis
  35. CVE-2026-32589High
    Mirror-registry: quay: insecure direct object reference in blobupload
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jun 23, 2026Updated Aug 12, 2026View HOL analysis
  36. CVE-2026-2377Medium
    Mirror-registry: quay: quay: server-side request forgery via log export functionality
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jun 25, 2026Updated Aug 12, 2026View HOL analysis
  37. CVE-2025-57847Medium
    Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2026-5795High
    CISA ADP Vulnrichment
    CVSS 7.4
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedApr 8, 2026First seen at HOL Jul 2, 2026Updated Aug 14, 2026View HOL analysis
  39. CVE-2026-31411Medium
    net: atm: fix crash due to unvalidated vcc pointer in sigd_send()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 8, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-1672Medium
    BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification
    CVSS 6.5
    realmag777/BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Netgeneric
    PublishedApr 8, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  41. CVE-2026-32280High
    Unexpected work during chain building in crypto/x509
    CVSS 7.5
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedApr 8, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-27140High
    Code execution vulnerability in SWIG code generation in cmd/go
    CVSS 8.8
    Go toolchain/cmd/gogeneric
    PublishedApr 8, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2026-32283High
    Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
    CVSS 7.5
    Go standard library/crypto/tls, stdlibgeneric · go
    PublishedApr 8, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-33810High
    Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
    CVSS 8.2
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedApr 8, 2026First seen at HOL Jun 30, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-31017Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedApr 8, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-34078Critical
    Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
    CVSS 10.0
    flatpak/flatpakgeneric
    PublishedApr 7, 2026First seen at HOL Jul 6, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-34582Critical
    Botan has a TLS 1.3 certificate authentication bypass
    CVSS 9.1
    randombit/botangeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-34580High
    Botan has a certificate authentication bypass due to trust anchor confusion
    CVSS 7.5
    randombit/botangeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-34045High
    Podman Desktop WebView Server Exposed
    CVSS 8.2
    podman-desktop/podman-desktopgeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-29181High
    OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
    CVSS 7.5
    open-telemetry/opentelemetry-gogeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Aug 12, 2026View HOL analysis
Page 242 of 405
Previous240241242243244Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,110

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,051–12,100 of 20,217 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-34481High
    Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
    CVSS 7.5
    Apache Software Foundation/Apache Log4j JSON Template Layout, org.apache.logging.log4j:log4j-layout-template-jsongeneric · maven
    PublishedApr 10, 2026First seen at HOL Jul 11, 2026Updated Jul 11, 2026 Fix availableView HOL analysis
  2. CVE-2026-40217High
    CISA ADP Vulnrichment
    CVSS 8.8
    BerriAI/LiteLLMgeneric
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-39304High
    Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
    CVSS 7.5
    Apache Software Foundation/Apache ActiveMQ, Apache Software Foundation/Apache ActiveMQ All +2generic
    PublishedApr 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-39848Medium
    Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation
    CVSS 6.5
    10ij/dockyardgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  5. CVE-2026-33784Critical
    JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
    CVSS 9.8
    Juniper Networks/JSI LWCgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-33774Medium
    Junos OS: MX Series: Firewall filters on lo0.<non-0> in the default routing instance are not in effect
    CVSS 6.5
    Juniper Networks/Junos OSgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-33771High
    CTP OS: Configuring password requirements does not work which permits the use of weak passwords
    CVSS 7.4
    Juniper Networks/CTP OSgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2025-13914High
    Apstra: SSH host key validation vulnerability for managed devices
    CVSS 8.7
    Juniper Networks/Apstrageneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-33788High
    Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs
    CVSS 7.8
    Juniper Networks/Junos OS Evolvedgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-21915Medium
    JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root
    CVSS 6.7
    Juniper Networks/JSI LWCgeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-21904Medium
    Junos Space: ilpFilter field on nLegacy.jsp is vulnerable to reflected cross-site script injection
    CVSS 6.1
    Juniper Networks/Junos Spacegeneric
    PublishedApr 9, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-34486High
    Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
    CVSS 7.5 Known exploited
    Apache Software Foundation/Apache Tomcat, org.apache.tomcat:tomcat +1generic · maven
    PublishedApr 9, 2026First seen at HOL Jun 11, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-29146High
    Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
    CVSS 7.5
    Apache Software Foundation/Apache Tomcat, org.apache.tomcat:tomcat +1generic · maven
    PublishedApr 9, 2026First seen at HOL Jul 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-34734High
    HDF5: H5T__conv_struct Use After Free
    CVSS 7.8
    HDFGroup/hdf5generic
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-34971High
    Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
    CVSS 7.8
    bytecodealliance/wasmtimegeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-1584High
    Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-39987High
    marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
    Not scored Known exploited
    marimo-team/marimogeneric
    PublishedApr 9, 2026First seen at HOL May 24, 2026Updated May 7, 2026View HOL analysis
  18. CVE-2026-39983High
    FTP Command Injection via CRLF in basic-ftp
    CVSS 8.6
    patrickjuchli/basic-ftpgeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-39962Critical
    LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
    CVSS 9.6
    MISP/MISPgeneric
    PublishedApr 9, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  20. CVE-2026-35205High
    Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
    CVSS 7.8
    helm/helmgeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-35204High
    Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
    CVSS 8.6
    helm/helmgeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-4878Medium
    Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()
    CVSS 6.7
    Affected software not mappedEcosystem not listed
    PublishedApr 9, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  23. CVE-2025-62718Critical
    Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
    CVSS 9.9
    axios/axiosgeneric
    PublishedApr 9, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  24. CVE-2026-4660High
    Go-getter may allow to arbitrary filesystem reads through git operations
    CVSS 7.5
    HashiCorp/Toolinggeneric
    PublishedApr 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-34185High
    SQL Injection in AlanWeb SCADA
    CVSS 8.8
    Control System/AlanWeb SCADAgeneric
    PublishedApr 9, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  26. CVE-2026-34184Critical
    Missing Authorization inAlanWeb SCADA
    CVSS 9.1
    Control System/AlanWeb SCADAgeneric
    PublishedApr 9, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-4901Medium
    Insertion of Sesitive Information into Log File in AlanWeb SCADA
    CVSS 6.5
    Control System/AlanWeb SCADAgeneric
    PublishedApr 9, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  28. CVE-2025-70364High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedApr 9, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  29. CVE-2025-70365Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 9, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2026-39892Critical
    cryptography has a buffer overflow if non-contiguous buffers were passed to APIs
    CVSS 9.8
    cryptography, pyca/cryptographygeneric · pip
    PublishedApr 8, 2026First seen at HOL Jun 11, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  31. CVE-2026-39883High
    OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijacking
    CVSS 7.0
    open-telemetry/opentelemetry-gogeneric
    PublishedApr 8, 2026First seen at HOL Jul 10, 2026Updated Aug 14, 2026View HOL analysis
  32. CVE-2026-23869High
    CISA ADP Vulnrichment
    CVSS 7.5
    Meta/react-server-dom-parcel, Meta/react-server-dom-turbopack +1generic
    PublishedApr 8, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-32591Medium
    Mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
    CVSS 5.2
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jul 15, 2026Updated Aug 12, 2026View HOL analysis
  34. CVE-2026-32590High
    Mirror-registry: remote code execution using pickle deserialization
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jun 23, 2026Updated Aug 11, 2026View HOL analysis
  35. CVE-2026-32589High
    Mirror-registry: quay: insecure direct object reference in blobupload
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jun 23, 2026Updated Aug 12, 2026View HOL analysis
  36. CVE-2026-2377Medium
    Mirror-registry: quay: quay: server-side request forgery via log export functionality
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Jun 25, 2026Updated Aug 12, 2026View HOL analysis
  37. CVE-2025-57847Medium
    Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedApr 8, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2026-5795High
    CISA ADP Vulnrichment
    CVSS 7.4
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedApr 8, 2026First seen at HOL Jul 2, 2026Updated Aug 14, 2026View HOL analysis
  39. CVE-2026-31411Medium
    net: atm: fix crash due to unvalidated vcc pointer in sigd_send()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 8, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  40. CVE-2026-1672Medium
    BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification
    CVSS 6.5
    realmag777/BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Netgeneric
    PublishedApr 8, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  41. CVE-2026-32280High
    Unexpected work during chain building in crypto/x509
    CVSS 7.5
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedApr 8, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-27140High
    Code execution vulnerability in SWIG code generation in cmd/go
    CVSS 8.8
    Go toolchain/cmd/gogeneric
    PublishedApr 8, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2026-32283High
    Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
    CVSS 7.5
    Go standard library/crypto/tls, stdlibgeneric · go
    PublishedApr 8, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-33810High
    Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
    CVSS 8.2
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedApr 8, 2026First seen at HOL Jun 30, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-31017Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedApr 8, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2026-34078Critical
    Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
    CVSS 10.0
    flatpak/flatpakgeneric
    PublishedApr 7, 2026First seen at HOL Jul 6, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-34582Critical
    Botan has a TLS 1.3 certificate authentication bypass
    CVSS 9.1
    randombit/botangeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-34580High
    Botan has a certificate authentication bypass due to trust anchor confusion
    CVSS 7.5
    randombit/botangeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-34045High
    Podman Desktop WebView Server Exposed
    CVSS 8.2
    podman-desktop/podman-desktopgeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-29181High
    OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
    CVSS 7.5
    open-telemetry/opentelemetry-gogeneric
    PublishedApr 7, 2026First seen at HOL Jul 15, 2026Updated Aug 12, 2026View HOL analysis
Page 242 of 405
Previous240241242243244Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard