1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 6:20 PM 20,224 active 1,448 known exploited

Catalog summary

20,224

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 6:20 PM 20,224 active 1,448 known exploited

Catalog summary

20,224

Active CVEs

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,351–12,400 of 20,224 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-31848Critical
    Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+
    CVSS 9.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  2. CVE-2026-31847High
    Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+
    CVSS 8.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2026-31846Medium
    Unauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+
    CVSS 6.5
    Nexxt Solutions/Nebula 300+ / Tenda F3 V2.0 Firmwaregeneric
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  4. CVE-2026-4603Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  5. CVE-2026-4601High
    CISA ADP Vulnrichment
    CVSS 8.7
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-4599Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  7. CVE-2026-4598High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  8. CVE-2026-4602High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-4600High
    CISA ADP Vulnrichment
    CVSS 7.4
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  10. CVE-2025-52204Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-33228Critical
    flatted: Prototype Pollution via parse()
    CVSS 9.8
    WebReflection/flattedgeneric
    PublishedMar 20, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  12. CVE-2026-33210Critical
    Ruby JSON has a format string injection vulnerability
    CVSS 9.1
    json, ruby/jsongeneric · rubygems
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  13. CVE-2026-33236High
    NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
    CVSS 8.1
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 21, 2026View HOL analysis
  14. CVE-2026-33231High
    NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app
    CVSS 7.5
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-33186Critical
    gRPC-Go has an authorization bypass via missing leading slash in :path
    CVSS 9.1
    grpc/grpc-gogeneric
    PublishedMar 20, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  16. CVE-2026-33180High
    HAPI FHIR HTTP authentication leak in redirects
    CVSS 7.5
    ca.uhn.hapi.fhir:org.hl7.fhir.convertors, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 +11generic · maven
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2026-23536High
    Feast: unauthenticated arbitrary file read
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-33150High
    Use After Free in libfuse
    CVSS 7.8
    libfuse/libfusegeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-4438Medium
    gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
    CVSS 5.4
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-4437High
    gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2025-15608Critical
    Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53 + Archer AX55
    CVSS 9.8
    TP-Link Systems Inc./AX53 v1, TP-Link Systems Inc./AX55 v4 +1generic
    PublishedMar 20, 2026First seen at HOL Jul 13, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  22. CVE-2026-4519Low
    webbrowser.open() allows leading dashes in URLs
    CVSS 3.3
    Python Software Foundation/CPythongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  23. CVE-2026-32305Medium
    Traefik mTLS bypass via fragmented ClientHello SNI extraction failure
    CVSS 5.3
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-23277Medium
    net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-23274High
    netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  26. CVE-2026-23273High
    macvlan: observe an RCU grace period in macvlan_common_newlink() error path
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  27. CVE-2026-23271High
    perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  28. CVE-2026-32875High
    UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-32874High
    UltraJSON has a Memory Leak parsing large integers allows DoS
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-32829High
    lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
    CVSS 7.5
    PSeitz/lz4_flexgeneric
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Aug 11, 2026View HOL analysis
  31. CVE-2025-63260Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  32. CVE-2025-67260High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2026-3029High
    CVE-2026-3029
    CVSS 7.5
    Artifex Software Inc. *PyMuPDF*/PyMuPDFgeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  34. CVE-2026-4424High
    Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2025-71260High
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE
    CVSS 8.8
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  36. CVE-2025-71259Medium
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS
    CVSS 4.3
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  37. CVE-2025-71258Medium
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb
    CVSS 4.3
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  38. CVE-2025-71257High
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
    CVSS 7.3
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  39. CVE-2006-10003Critical
    XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack
    CVSS 9.8
    TODDR/XML::Parsergeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2025-15031Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 9.1
    mlflow/mlflow/mlflowgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-27135High
    nghttp2 Denial of service: Assertion failure due to the missing state validation
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-23270High
    net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-33001High
    CISA ADP Vulnrichment
    CVSS 8.8
    org.jenkins-ci.main:jenkins-coremaven
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-23247Medium
    tcp: secure_seq: add back ports to TS offset
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 18, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  45. CVE-2026-23245High
    net/sched: act_gate: snapshot parameters with RCU on replace
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-23243High
    RDMA/umad: Reject negative data_len in ib_umad_write
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-23242High
    RDMA/siw: Fix potential NULL pointer dereference in header processing
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2025-71267Medium
    fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-71266Medium
    fs: ntfs3: check return value of indx_find to avoid infinite loop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2025-71265Medium
    fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 248 of 405
Previous246247248249250Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,351–12,400 of 20,224 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-31848Critical
    Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+
    CVSS 9.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  2. CVE-2026-31847High
    Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+
    CVSS 8.8
    Nexxt Solutions/Nebula 300+generic
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  3. CVE-2026-31846Medium
    Unauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+
    CVSS 6.5
    Nexxt Solutions/Nebula 300+ / Tenda F3 V2.0 Firmwaregeneric
    PublishedMar 23, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  4. CVE-2026-4603Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    n/a/jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  5. CVE-2026-4601High
    CISA ADP Vulnrichment
    CVSS 8.7
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-4599Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  7. CVE-2026-4598High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  8. CVE-2026-4602High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-4600High
    CISA ADP Vulnrichment
    CVSS 7.4
    n/a/jsrsasign, n/a/org.webjars.npm:jsrsasigngeneric
    PublishedMar 23, 2026First seen at HOL Jun 22, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  10. CVE-2025-52204Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMar 23, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-33228Critical
    flatted: Prototype Pollution via parse()
    CVSS 9.8
    WebReflection/flattedgeneric
    PublishedMar 20, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  12. CVE-2026-33210Critical
    Ruby JSON has a format string injection vulnerability
    CVSS 9.1
    json, ruby/jsongeneric · rubygems
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  13. CVE-2026-33236High
    NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
    CVSS 8.1
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 21, 2026View HOL analysis
  14. CVE-2026-33231High
    NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app
    CVSS 7.5
    nltk/nltkgeneric
    PublishedMar 20, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-33186Critical
    gRPC-Go has an authorization bypass via missing leading slash in :path
    CVSS 9.1
    grpc/grpc-gogeneric
    PublishedMar 20, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  16. CVE-2026-33180High
    HAPI FHIR HTTP authentication leak in redirects
    CVSS 7.5
    ca.uhn.hapi.fhir:org.hl7.fhir.convertors, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 +11generic · maven
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2026-23536High
    Feast: unauthenticated arbitrary file read
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-33150High
    Use After Free in libfuse
    CVSS 7.8
    libfuse/libfusegeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-4438Medium
    gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
    CVSS 5.4
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-4437High
    gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2025-15608Critical
    Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53 + Archer AX55
    CVSS 9.8
    TP-Link Systems Inc./AX53 v1, TP-Link Systems Inc./AX55 v4 +1generic
    PublishedMar 20, 2026First seen at HOL Jul 13, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  22. CVE-2026-4519Low
    webbrowser.open() allows leading dashes in URLs
    CVSS 3.3
    Python Software Foundation/CPythongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  23. CVE-2026-32305Medium
    Traefik mTLS bypass via fragmented ClientHello SNI extraction failure
    CVSS 5.3
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-23277Medium
    net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-23274High
    netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  26. CVE-2026-23273High
    macvlan: observe an RCU grace period in macvlan_common_newlink() error path
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  27. CVE-2026-23271High
    perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  28. CVE-2026-32875High
    UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  29. CVE-2026-32874High
    UltraJSON has a Memory Leak parsing large integers allows DoS
    CVSS 7.5
    ultrajson/ultrajsongeneric
    PublishedMar 20, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-32829High
    lz4_flex: Decompression can leak information from uninitialized memory or reused output buffer
    CVSS 7.5
    PSeitz/lz4_flexgeneric
    PublishedMar 20, 2026First seen at HOL Jul 14, 2026Updated Aug 11, 2026View HOL analysis
  31. CVE-2025-63260Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  32. CVE-2025-67260High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 20, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  33. CVE-2026-3029High
    CVE-2026-3029
    CVSS 7.5
    Artifex Software Inc. *PyMuPDF*/PyMuPDFgeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  34. CVE-2026-4424High
    Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2025-71260High
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE
    CVSS 8.8
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  36. CVE-2025-71259Medium
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS
    CVSS 4.3
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  37. CVE-2025-71258Medium
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb
    CVSS 4.3
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  38. CVE-2025-71257High
    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
    CVSS 7.3
    BMC Software, Inc./FootPrintsgeneric
    PublishedMar 19, 2026First seen at HOL Aug 6, 2026Updated Aug 14, 2026View HOL analysis
  39. CVE-2006-10003Critical
    XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack
    CVSS 9.8
    TODDR/XML::Parsergeneric
    PublishedMar 19, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2025-15031Critical
    Path Traversal Vulnerability in mlflow/mlflow
    CVSS 9.1
    mlflow/mlflow/mlflowgeneric
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-27135High
    nghttp2 Denial of service: Assertion failure due to the missing state validation
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-23270High
    net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-33001High
    CISA ADP Vulnrichment
    CVSS 8.8
    org.jenkins-ci.main:jenkins-coremaven
    PublishedMar 18, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-23247Medium
    tcp: secure_seq: add back ports to TS offset
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 18, 2026First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  45. CVE-2026-23245High
    net/sched: act_gate: snapshot parameters with RCU on replace
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-23243High
    RDMA/umad: Reject negative data_len in ib_umad_write
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-23242High
    RDMA/siw: Fix potential NULL pointer dereference in header processing
    CVSS 7.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  48. CVE-2025-71267Medium
    fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-71266Medium
    fs: ntfs3: check return value of indx_find to avoid infinite loop
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  50. CVE-2025-71265Medium
    fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMar 18, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 248 of 405
Previous246247248249250Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard