1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 6:20 PM 20,224 active 1,448 known exploited

Catalog summary

20,224

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 6:20 PM 20,224 active 1,448 known exploited

Catalog summary

20,224

Active CVEs

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,301–12,350 of 20,224 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-23319High
    bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-23310Medium
    bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 25, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  3. CVE-2026-23304Medium
    ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-23300Medium
    net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-23293Medium
    net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-23290Medium
    net: usb: pegasus: validate USB endpoints
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-23287Medium
    irqchip/sifive-plic: Fix frozen interrupt due to affinity setting
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-23284Medium
    net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-3608High
    Stack overflow in Kea daemons
    CVSS 7.5
    ISC/Keageneric
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-20664Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  11. CVE-2026-28859Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-28861Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-28857Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2025-67030High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 25, 2026First seen at HOL Jul 7, 2026Updated Aug 12, 2026View HOL analysis
  15. CVE-2026-4371High
    Out of bounds read in IMAP parsing
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-33412Medium
    Vim affected by Command injection via newline in glob()
    CVSS 5.6
    vim/vimgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-4775High
    Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-27651High
    NGINX ngx_mail_auth_http_module vulnerability
    CVSS 7.5
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-27654High
    NGINX ngx_http_dav_module vulnerability
    CVSS 8.2
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-32647High
    NGINX ngx_http_mp4_module vulnerability
    CVSS 7.8
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  21. CVE-2026-27784High
    NGINX ngx_http_mp4_module vulnerability
    CVSS 7.8
    F5/NGINX Open Sourcegeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2026-4721Critical
    Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-4729Critical
    Memory safety bugs fixed in Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-4720Critical
    Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-4700Critical
    Mitigation bypass in the Networking: HTTP component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-4699High
    Incorrect boundary conditions in the Layout: Text and Fonts component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-4698Critical
    JIT miscompilation in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-4697High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-4696Critical
    Use-after-free in the Layout: Text and Fonts component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-4695High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-4694High
    Incorrect boundary conditions, integer overflow in the Graphics component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-4693High
    Incorrect boundary conditions in the Audio/Video: Playback component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-4692Critical
    Sandbox escape in the Responsive Design Mode component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-4691Critical
    Use-after-free in the CSS Parsing and Computation component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-4690High
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-4689Critical
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-4688Critical
    Sandbox escape due to use-after-free in the Disability Access APIs component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-4687High
    Sandbox escape due to incorrect boundary conditions in the Telemetry component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-4686High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-4685High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-4684High
    Race condition, use-after-free in the Graphics: WebRender component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-33211Critical
    Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod
    CVSS 9.6
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedMar 23, 2026First seen at HOL Jul 9, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  43. CVE-2026-33195Critical
    Rails Active Storage has possible Path Traversal in DiskService
    CVSS 9.8
    activestorage, rails/activestoragegeneric · rubygems
    PublishedMar 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-33634High
    Trivy ecosystem supply chain briefly compromised
    Not scored Known exploited
    BerriAI/LiteLLM, aquasecurity/setup-trivy +4generic · github actions · go
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Jun 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-3055High
    Insufficient input validation leading to memory overread
    Not scored Known exploited
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  46. CVE-2026-32845High
    jkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer Overflow
    CVSS 8.4
    jkuhlmann/cgltfgeneric
    PublishedMar 23, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  47. CVE-2026-4647Medium
    Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 23, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-31851Unknown severity
    Nexxt Nebula 300+ - Lack of Rate Limiting Enables Brute-Force Attacks
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  49. CVE-2026-31850Unknown severity
    Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  50. CVE-2026-31849Unknown severity
    Missing CSRF Protection on Administrative Endpoints in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
Page 247 of 405
Previous245246247248249Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,301–12,350 of 20,224 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-23319High
    bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-23310Medium
    bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 25, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  3. CVE-2026-23304Medium
    ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  4. CVE-2026-23300Medium
    net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-23293Medium
    net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-23290Medium
    net: usb: pegasus: validate USB endpoints
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-23287Medium
    irqchip/sifive-plic: Fix frozen interrupt due to affinity setting
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-23284Medium
    net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 25, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-3608High
    Stack overflow in Kea daemons
    CVSS 7.5
    ISC/Keageneric
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-20664Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  11. CVE-2026-28859Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-28861Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  13. CVE-2026-28857Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +2generic
    PublishedMar 25, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2025-67030High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 25, 2026First seen at HOL Jul 7, 2026Updated Aug 12, 2026View HOL analysis
  15. CVE-2026-4371High
    Out of bounds read in IMAP parsing
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-33412Medium
    Vim affected by Command injection via newline in glob()
    CVSS 5.6
    vim/vimgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-4775High
    Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jun 25, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-27651High
    NGINX ngx_mail_auth_http_module vulnerability
    CVSS 7.5
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-27654High
    NGINX ngx_http_dav_module vulnerability
    CVSS 8.2
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-32647High
    NGINX ngx_http_mp4_module vulnerability
    CVSS 7.8
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  21. CVE-2026-27784High
    NGINX ngx_http_mp4_module vulnerability
    CVSS 7.8
    F5/NGINX Open Sourcegeneric
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  22. CVE-2026-4721Critical
    Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-4729Critical
    Memory safety bugs fixed in Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-4720Critical
    Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-4700Critical
    Mitigation bypass in the Networking: HTTP component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-4699High
    Incorrect boundary conditions in the Layout: Text and Fonts component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-4698Critical
    JIT miscompilation in the JavaScript Engine: JIT component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-4697High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-4696Critical
    Use-after-free in the Layout: Text and Fonts component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-4695High
    Incorrect boundary conditions in the Audio/Video: Web Codecs component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-4694High
    Incorrect boundary conditions, integer overflow in the Graphics component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-4693High
    Incorrect boundary conditions in the Audio/Video: Playback component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-4692Critical
    Sandbox escape in the Responsive Design Mode component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-4691Critical
    Use-after-free in the CSS Parsing and Computation component
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-4690High
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-4689Critical
    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-4688Critical
    Sandbox escape due to use-after-free in the Disability Access APIs component
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-4687High
    Sandbox escape due to incorrect boundary conditions in the Telemetry component
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-4686High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-4685High
    Incorrect boundary conditions in the Graphics: Canvas2D component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-4684High
    Race condition, use-after-free in the Graphics: WebRender component
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 24, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-33211Critical
    Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod
    CVSS 9.6
    github.com/tektoncd/pipeline, tektoncd/pipelinegeneric · go
    PublishedMar 23, 2026First seen at HOL Jul 9, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  43. CVE-2026-33195Critical
    Rails Active Storage has possible Path Traversal in DiskService
    CVSS 9.8
    activestorage, rails/activestoragegeneric · rubygems
    PublishedMar 23, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-33634High
    Trivy ecosystem supply chain briefly compromised
    Not scored Known exploited
    BerriAI/LiteLLM, aquasecurity/setup-trivy +4generic · github actions · go
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Jun 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-3055High
    Insufficient input validation leading to memory overread
    Not scored Known exploited
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedMar 23, 2026First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  46. CVE-2026-32845High
    jkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer Overflow
    CVSS 8.4
    jkuhlmann/cgltfgeneric
    PublishedMar 23, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  47. CVE-2026-4647Medium
    Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedMar 23, 2026First seen at HOL Jun 30, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-31851Unknown severity
    Nexxt Nebula 300+ - Lack of Rate Limiting Enables Brute-Force Attacks
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  49. CVE-2026-31850Unknown severity
    Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  50. CVE-2026-31849Unknown severity
    Missing CSRF Protection on Administrative Endpoints in Nexxt Nebula 300+
    Not scoredSource severity not reported
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
Page 247 of 405
Previous245246247248249Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard