1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 7:30 PM 20,228 active 1,448 known exploited

Catalog summary

20,228

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 7:30 PM 20,228 active 1,448 known exploited

Catalog summary

20,228

Active CVEs

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,451–12,500 of 20,228 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-1528High
    undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client
    CVSS 7.5
    undici/undicigeneric
    PublishedMar 12, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  2. CVE-2026-1526High
    undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression
    CVSS 7.5
    undici/undicigeneric
    PublishedMar 12, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  3. CVE-2026-3497High
    CISA ADP Vulnrichment
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 12, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-32141High
    flatted: Unbounded recursion DoS in parse() revive phase
    CVSS 7.5
    WebReflection/flatted, flattedgeneric · npm
    PublishedMar 12, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  5. CVE-2025-13462Low
    tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
    CVSS 3.3
    Python Software Foundation/CPythongeneric
    PublishedMar 12, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-28356High
    ReDoS in multipart 1.3.0 - `parse_options_header()`
    CVSS 7.5
    defnull/multipartgeneric
    PublishedMar 12, 2026First seen at HOL Jul 10, 2026Updated Jul 21, 2026View HOL analysis
  7. CVE-2023-43010High
    CISA ADP Vulnrichment
    CVSS 8.8
    Apple/Safari, Apple/iOS and iPadOS +1generic
    PublishedMar 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2025-66955Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMar 12, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  9. CVE-2026-20117Medium
    Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities
    CVSS 6.1
    Cisco/Cisco Unified Contact Center Expressgeneric
    PublishedMar 11, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  10. CVE-2026-20046High
    Cisco IOS XR Software CLI Privilege Escalation Vulnerability
    CVSS 8.8
    Cisco/Cisco IOS XR Softwaregeneric
    PublishedMar 11, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  11. CVE-2026-20074High
    Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
    CVSS 7.4
    Cisco/Cisco IOS XR Softwaregeneric
    PublishedMar 11, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  12. CVE-2026-20040High
    Cisco IOS XR Software CLI Privilege Escalation Vulnerability
    CVSS 8.8
    Cisco/Cisco IOS XR Softwaregeneric
    PublishedMar 11, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  13. CVE-2026-31892High
    WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
    CVSS 8.1
    argoproj/argo-workflowsgeneric
    PublishedMar 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-28229Critical
    Argo Workflows has unauthorized access to Argo Workflows Template
    CVSS 9.8
    argoproj/argo-workflowsgeneric
    PublishedMar 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-3904Medium
    CVE Program Container
    CVSS 6.2
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 11, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-31844High
    Authenticated SQL Injection in Koha displayby parameter of suggestion.pl
    CVSS 8.8
    Koha Community/Kohageneric
    PublishedMar 11, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2025-66956Critical
    CISA ADP Vulnrichment
    CVSS 9.9
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  18. CVE-2025-67034High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  19. CVE-2025-67035Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  20. CVE-2025-67036High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  21. CVE-2025-67037High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  22. CVE-2025-67038Critical
    CISA ADP Vulnrichment
    CVSS 9.8 Known exploited
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 6, 2026View HOL analysis
  23. CVE-2025-67039Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2025-67041Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2025-70082Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2025-70330Low
    CISA ADP Vulnrichment
    CVSS 3.3
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2026-31837High
    Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch fails.
    CVSS 7.5
    istio/istiogeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  28. CVE-2026-31812Medium
    Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
    CVSS 5.3
    quinn-rs/quinngeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  29. CVE-2026-30951High
    Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
    CVSS 7.5
    sequelize/sequelizegeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-23868Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    giflib/giflibgeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-28292Critical
    simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE
    CVSS 9.8
    steveukx/simple-gitgeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-2273High
    CISA ADP Vulnrichment
    CVSS 8.2
    Schneider Electric/EcoStruxure™ Automation Expertgeneric
    PublishedMar 10, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  33. CVE-2026-1286Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Schneider Electric/EcoStruxure™ Foxboro DCSgeneric
    PublishedMar 10, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026View HOL analysis
  34. CVE-2025-13902Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Schneider Electric/Modicon Controllers M241/M251, Schneider Electric/Modicon Controllers M258/LMC058generic
    PublishedMar 10, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  35. CVE-2026-26130High
    ASP.NET Core Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/ASP.NET Core 10.0, Microsoft/ASP.NET Core 8.0 +1generic
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2025-13901Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Schneider Electric/Modicon M241/M251, Schneider Electric/Modicon M262generic
    PublishedMar 10, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  37. CVE-2025-11739High
    CISA ADP Vulnrichment
    CVSS 7.8
    Schneider Electric/EcoStruxure™ Power Monitoring Expert (PME), Schneider Electric/EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Modulegeneric
    PublishedMar 10, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026View HOL analysis
  38. CVE-2026-3843Critical
    SQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution
    CVSS 9.8
    Nefteprodukttekhnika LLC/BUK TS-G Gas Station Automation Systemgeneric
    PublishedMar 10, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  39. CVE-2025-56421High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2025-56422Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2026-28693High
    ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write
    CVSS 8.1
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-28691High
    ImageMagick has an uninitialized pointer dereference in JBIG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2024-14027Medium
    xattr: switch to CLASS(fd)
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 9, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  44. CVE-2026-25604Medium
    Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
    CVSS 5.4
    Apache Software Foundation/Apache Airflow Providers Amazongeneric
    PublishedMar 9, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  45. CVE-2026-3823Critical
    Atop Technologies|EHG2408 series switch - Stack-based Buffer Overflow
    CVSS 9.8
    Atop Technologies/EHG2408, Atop Technologies/EHG2408-2SFPgeneric
    PublishedMar 9, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-29786Medium
    node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
    CVSS 6.3
    isaacs/node-targeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-29186High
    @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
    CVSS 7.7
    backstage/backstagegeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-24308High
    Apache ZooKeeper: Sensitive information disclosure in client configuration handling
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  49. CVE-2026-24281High
    Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
    CVSS 7.4
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-25679High
    Incorrect parsing of IPv6 host literals in net/url
    CVSS 7.5
    Go standard library/net/url, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jun 30, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
Page 250 of 405
Previous248249250251252Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,118

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,451–12,500 of 20,228 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-1528High
    undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client
    CVSS 7.5
    undici/undicigeneric
    PublishedMar 12, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  2. CVE-2026-1526High
    undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression
    CVSS 7.5
    undici/undicigeneric
    PublishedMar 12, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026View HOL analysis
  3. CVE-2026-3497High
    CISA ADP Vulnrichment
    CVSS 7.5
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 12, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-32141High
    flatted: Unbounded recursion DoS in parse() revive phase
    CVSS 7.5
    WebReflection/flatted, flattedgeneric · npm
    PublishedMar 12, 2026First seen at HOL Jul 2, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  5. CVE-2025-13462Low
    tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
    CVSS 3.3
    Python Software Foundation/CPythongeneric
    PublishedMar 12, 2026First seen at HOL Aug 13, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-28356High
    ReDoS in multipart 1.3.0 - `parse_options_header()`
    CVSS 7.5
    defnull/multipartgeneric
    PublishedMar 12, 2026First seen at HOL Jul 10, 2026Updated Jul 21, 2026View HOL analysis
  7. CVE-2023-43010High
    CISA ADP Vulnrichment
    CVSS 8.8
    Apple/Safari, Apple/iOS and iPadOS +1generic
    PublishedMar 12, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2025-66955Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedMar 12, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  9. CVE-2026-20117Medium
    Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities
    CVSS 6.1
    Cisco/Cisco Unified Contact Center Expressgeneric
    PublishedMar 11, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  10. CVE-2026-20046High
    Cisco IOS XR Software CLI Privilege Escalation Vulnerability
    CVSS 8.8
    Cisco/Cisco IOS XR Softwaregeneric
    PublishedMar 11, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  11. CVE-2026-20074High
    Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
    CVSS 7.4
    Cisco/Cisco IOS XR Softwaregeneric
    PublishedMar 11, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  12. CVE-2026-20040High
    Cisco IOS XR Software CLI Privilege Escalation Vulnerability
    CVSS 8.8
    Cisco/Cisco IOS XR Softwaregeneric
    PublishedMar 11, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  13. CVE-2026-31892High
    WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
    CVSS 8.1
    argoproj/argo-workflowsgeneric
    PublishedMar 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-28229Critical
    Argo Workflows has unauthorized access to Argo Workflows Template
    CVSS 9.8
    argoproj/argo-workflowsgeneric
    PublishedMar 11, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-3904Medium
    CVE Program Container
    CVSS 6.2
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMar 11, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2026-31844High
    Authenticated SQL Injection in Koha displayby parameter of suggestion.pl
    CVSS 8.8
    Koha Community/Kohageneric
    PublishedMar 11, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  17. CVE-2025-66956Critical
    CISA ADP Vulnrichment
    CVSS 9.9
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  18. CVE-2025-67034High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  19. CVE-2025-67035Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  20. CVE-2025-67036High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  21. CVE-2025-67037High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  22. CVE-2025-67038Critical
    CISA ADP Vulnrichment
    CVSS 9.8 Known exploited
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 6, 2026View HOL analysis
  23. CVE-2025-67039Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2025-67041Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2025-70082Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jun 23, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2025-70330Low
    CISA ADP Vulnrichment
    CVSS 3.3
    n/a/n/ageneric
    PublishedMar 11, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2026-31837High
    Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch fails.
    CVSS 7.5
    istio/istiogeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  28. CVE-2026-31812Medium
    Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
    CVSS 5.3
    quinn-rs/quinngeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Aug 11, 2026View HOL analysis
  29. CVE-2026-30951High
    Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
    CVSS 7.5
    sequelize/sequelizegeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2026-23868Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    giflib/giflibgeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  31. CVE-2026-28292Critical
    simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE
    CVSS 9.8
    steveukx/simple-gitgeneric
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  32. CVE-2026-2273High
    CISA ADP Vulnrichment
    CVSS 8.2
    Schneider Electric/EcoStruxure™ Automation Expertgeneric
    PublishedMar 10, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  33. CVE-2026-1286Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Schneider Electric/EcoStruxure™ Foxboro DCSgeneric
    PublishedMar 10, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026View HOL analysis
  34. CVE-2025-13902Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Schneider Electric/Modicon Controllers M241/M251, Schneider Electric/Modicon Controllers M258/LMC058generic
    PublishedMar 10, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  35. CVE-2026-26130High
    ASP.NET Core Denial of Service Vulnerability
    CVSS 7.5
    Microsoft/ASP.NET Core 10.0, Microsoft/ASP.NET Core 8.0 +1generic
    PublishedMar 10, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2025-13901Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Schneider Electric/Modicon M241/M251, Schneider Electric/Modicon M262generic
    PublishedMar 10, 2026First seen at HOL Jun 23, 2026Updated Jun 23, 2026View HOL analysis
  37. CVE-2025-11739High
    CISA ADP Vulnrichment
    CVSS 7.8
    Schneider Electric/EcoStruxure™ Power Monitoring Expert (PME), Schneider Electric/EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Modulegeneric
    PublishedMar 10, 2026First seen at HOL Jun 24, 2026Updated Jun 24, 2026View HOL analysis
  38. CVE-2026-3843Critical
    SQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution
    CVSS 9.8
    Nefteprodukttekhnika LLC/BUK TS-G Gas Station Automation Systemgeneric
    PublishedMar 10, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026View HOL analysis
  39. CVE-2025-56421High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2025-56422Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMar 10, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  41. CVE-2026-28693High
    ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write
    CVSS 8.1
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-28691High
    ImageMagick has an uninitialized pointer dereference in JBIG decoder
    CVSS 7.5
    ImageMagick/ImageMagickgeneric
    PublishedMar 9, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2024-14027Medium
    xattr: switch to CLASS(fd)
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedMar 9, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  44. CVE-2026-25604Medium
    Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
    CVSS 5.4
    Apache Software Foundation/Apache Airflow Providers Amazongeneric
    PublishedMar 9, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  45. CVE-2026-3823Critical
    Atop Technologies|EHG2408 series switch - Stack-based Buffer Overflow
    CVSS 9.8
    Atop Technologies/EHG2408, Atop Technologies/EHG2408-2SFPgeneric
    PublishedMar 9, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-29786Medium
    node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
    CVSS 6.3
    isaacs/node-targeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-29186High
    @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
    CVSS 7.7
    backstage/backstagegeneric
    PublishedMar 7, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  48. CVE-2026-24308High
    Apache ZooKeeper: Sensitive information disclosure in client configuration handling
    CVSS 7.5
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  49. CVE-2026-24281High
    Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
    CVSS 7.4
    Apache Software Foundation/Apache ZooKeeper, org.apache.zookeeper:zookeepergeneric · maven
    PublishedMar 7, 2026First seen at HOL Jul 3, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-25679High
    Incorrect parsing of IPv6 host literals in net/url
    CVSS 7.5
    Go standard library/net/url, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jun 30, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
Page 250 of 405
Previous248249250251252Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard