HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Oct 1, 2026, 11:20 AM 42,244 active 1,506 known exploited

Catalog summary

42,244

Active CVEs

21,873

Critical + high

1,506

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,151–12,200 of 42,244 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-85590High
    phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
    CVSS 7.1
    thorsten/phpMyFAQgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  2. CVE-2026-85589Medium
    phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API
    CVSS 5.3
    thorsten/phpMyFAQgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  3. CVE-2026-85588Medium
    phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export
    CVSS 5.3
    thorsten/phpMyFAQgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-85587Medium
    phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages
    CVSS 5.3
    thorsten/phpMyFAQgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  5. CVE-2026-85586Medium
    phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
    CVSS 6.9
    thorsten/phpMyFAQgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  6. CVE-2026-85585High
    SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency
    CVSS 7.5
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-85584High
    SiYuan before v3.8.2 Denial of Service via Auth Throttle
    CVSS 7.5
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-85583Medium
    SiYuan before v3.8.2 Path Traversal via symlink in file API
    CVSS 6.5
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-85582Medium
    SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth
    CVSS 6.5
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-85581High
    SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration
    CVSS 7.5
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  11. CVE-2026-85580Medium
    SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch
    CVSS 6.5
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-85579Medium
    SiYuan before v3.8.2 Information Disclosure via undoState
    CVSS 4.3
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-85578Medium
    SiYuan through 3.8.1 Authorization Bypass via getFile
    CVSS 6.5
    siyuan-note/siyuangeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 14, 2026View HOL analysis
  14. CVE-2026-85577Medium
    AVideo userLogin.php Reflected XSS via error parameter
    CVSS 5.4
    WWBN/AVideogeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  15. CVE-2026-27347Medium
    WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability
    CVSS 5.3
    Crocoblock/JetPopupgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026View HOL analysis
  16. CVE-2026-84428High
    fastify vulnerable to header validation bypass via incomplete schema case normalization
    CVSS 7.5
    fastify, fastify/fastifygeneric · npm
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Oct 1, 2026 Fix availableView HOL analysis
  17. CVE-2026-85534Medium
    Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  18. CVE-2026-4644High
    Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover
    CVSS 8.5
    Google Cloud/Integration Connectorsgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-85512High
    SourceCodester Class and Exam Timetabling System session.php authorization
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026View HOL analysis
  20. CVE-2026-79707High
    Arbitrary File Read in Google Agent Development Kit (ADK)
    CVSS 8.7
    Google Cloud/Agent Development Kit (ADK)generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  21. CVE-2026-84045Medium
    E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation via mptbm_add_to_cart
    CVSS 5.3
    Unknown/E-cab Taxi Booking Manager for Woocommercegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  22. CVE-2026-84044Medium
    Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPN
    CVSS 5.3
    Unknown/Restaurant Menu and Food Orderinggeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-84043Medium
    ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Bypass
    CVSS 5.3
    Unknown/ePayco Payment Gateway for WooCommercegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  24. CVE-2026-82923Critical
    AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes
    CVSS 9.8
    Unknown/AI Website Builder (GitHub build)generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  25. CVE-2026-84469High
    fastify vulnerable to request validation bypass via skipped boolean false schemas
    CVSS 7.5
    fastify, fastify/fastifygeneric · npm
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Oct 1, 2026 Fix availableView HOL analysis
  26. CVE-2026-76169High
    fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
    CVSS 7.5
    fastify, fastify/fastifygeneric · npm
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Oct 1, 2026 Fix availableView HOL analysis
  27. CVE-2026-81666Medium
    Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  28. CVE-2026-13148Medium
    Memory leak in scan method
    CVSS 6.3
    Softing/smartLink HW-PNgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  29. CVE-2026-85547Medium
    Cross-Site Request Forgery via Attacker-Controlled REST Detection in MISP
    CVSS 6.2
    misp/mispgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  30. CVE-2026-84504High
    fastify vulnerable to request body replacement via an async validation result collision
    CVSS 8.1
    fastify, fastify/fastifygeneric · npm
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Oct 1, 2026 Fix availableView HOL analysis
  31. CVE-2026-85541Medium
    Interinfo|DreamMaker - Reflected Cross-site Scripting
    CVSS 5.4
    Interinfo/DreamMakergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  32. CVE-2026-85540High
    Interinfo|DreamMaker - SQL Injection
    CVSS 8.8
    Interinfo/DreamMakergeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  33. CVE-2026-85546High
    MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Requests
    CVSS 8.6
    misp/mispgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026View HOL analysis
  34. CVE-2026-27086Medium
    WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Xtemos/WoodMartgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-85184Critical
    @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
    CVSS 9.1
    @fastify/middie/@fastify/middiegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-85538High
    MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete Attributes
    CVSS 8.3
    misp/mispgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  37. CVE-2026-81665High
    Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly
    CVSS 7.5
    Red Hat/openshift/ose-rhel-coreos-9generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 30, 2026View HOL analysis
  38. CVE-2026-81302High
    CISA ADP Vulnrichment
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  39. CVE-2026-85533High
    MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter
    CVSS 7.6
    misp/mispgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  40. CVE-2026-27432Medium
    WordPress WP Rentals theme < 3.16.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 5.4
    sc Internet Vivoo/WP Rentalsgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026 Fix availableView HOL analysis
  41. CVE-2026-85528Medium
    Snowflake JDBC Driver auto-configuration account validation permits credential redirection
    CVSS 5.3
    Snowflake/Snowflake JDBC Driver, Snowflake/Snowflake JDBC Driver (FIPS) +1generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  42. CVE-2026-15937Medium
    Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint
    CVSS 5.3
    Checkmk GmbH/Checkmkgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  43. CVE-2026-85525High
    Improper OCSP response validation in Snowflake drivers
    CVSS 7.4
    Snowflake/Snowflake Connector for Python, Snowflake/Snowflake Go Driver +4generic
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-57777High
    WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability
    CVSS 7.6
    Automattic/WooCommercegeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026 Fix availableView HOL analysis
  45. CVE-2026-85311Medium
    WordPress MarketKing plugin <= 2.1.60 - Broken Access Control vulnerability
    CVSS 5.3
    Kings Plugins/MarketKinggeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 7, 2026View HOL analysis
  46. CVE-2026-32480Medium
    WordPress WCFM Membership plugin <= 2.11.11 - Broken Access Control vulnerability
    CVSS 5.3
    WC Lovers/WCFM Membershipgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 4, 2026View HOL analysis
  47. CVE-2026-85197High
    Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload
    CVSS 7.6
    Affected software not mappedEcosystem not listed
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 16, 2026View HOL analysis
  48. CVE-2026-6217Medium
    Information Disclosure in Pik Online Software's Portal
    CVSS 6.3
    Pik Online Software Solutions Inc./Pik Online Portalgeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  49. CVE-2026-80190Medium
    Apache Allura: Stored XSS via code repositories
    CVSS 6.1
    Apache Software Foundation/Apache Allurageneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
  50. CVE-2026-85229Medium
    Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
    CVSS 6.1
    Apache Software Foundation/Apache SkyWalkinggeneric
    PublishedSep 4, 2026First seen at HOL Sep 4, 2026Updated Sep 8, 2026View HOL analysis
Page 244 of 845
Previous242243244245246Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard