1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 8:30 PM 20,228 active 1,448 known exploited

Catalog summary

20,228

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 15, 2026, 8:30 PM 20,228 active 1,448 known exploited

Catalog summary

20,228

Active CVEs

10,130

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,501–12,550 of 20,228 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-27137High
    Incorrect enforcement of email constraints in crypto/x509
    CVSS 7.5
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jul 2, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-29063Critical
    Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
    CVSS 9.8
    immutable-js/immutable-jsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  3. CVE-2026-29091High
    Locutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code Injection
    CVSS 8.1
    locutusjs/locutusgeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-26017High
    CoreDNS ACL Bypass
    CVSS 7.7
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-26018High
    CoreDNS Loop Detection Denial of Service Vulnerability
    CVSS 7.5
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-1468Medium
    Cross-Site Request Forgery in QuickCMS
    CVSS 5.1
    OpenSolution/QuickCMSgeneric
    PublishedMar 6, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  7. CVE-2026-29074High
    SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
    CVSS 7.5
    svg/svgogeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026View HOL analysis
  8. CVE-2026-29062High
    jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
    CVSS 7.5
    FasterXML/jackson-coregeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-28802Critical
    Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification
    CVSS 9.8
    authlib/authlibgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026View HOL analysis
  10. CVE-2025-70363High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 6, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-3047High
    Org.keycloak.broker.saml: keycloak saml broker: authentication bypass due to disabled saml client completing idp-initiated login
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-3009High
    Org.keycloak/keycloak-services: improper enforcement of disabled identity provider in identitybrokerservice (authentication bypass)
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  13. CVE-2026-24457Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Eclipse Foundation/Eclipse GlassFish, Eclipse Foundation/Eclipse OpenMQgeneric
    PublishedMar 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-29054High
    Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  15. CVE-2026-26999High
    Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-30783Critical
    RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2026-30789Critical
    RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  18. CVE-2026-30798High
    RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  19. CVE-2026-25048High
    xgrammar: Multi-layer nesting causes DoS
    CVSS 7.5
    mlc-ai/xgrammargeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  20. CVE-2026-30796High
    RustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jul 19, 2026View HOL analysis
  21. CVE-2026-30792High
    RustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings
    CVSS 8.1
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  22. CVE-2026-1605High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  23. CVE-2025-45691High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-2297Medium
    SourcelessFileLoader does not use io.open_code()
    CVSS 5.7
    Python Software Foundation/CPythongeneric
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  25. CVE-2025-66024High
    XWiki Blog Application home page vulnerable to Stored XSS via Post Title
    CVSS 9.0
    org.xwiki.contrib.blog:application-blog-ui, xwiki-contrib/application-blog-uigeneric · maven
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-20131High
    Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
    Not scored Known exploited
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL May 24, 2026Updated Aug 14, 2026View HOL analysis
  27. CVE-2026-20079Unknown severity
    Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-3520High
    Multer vulnerable to Denial of Service via uncontrolled recursion
    CVSS 7.5
    expressjs/multergeneric
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2025-15558High
    Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    CVSS 8.0
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2025-12801Medium
    Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2025-40894Unknown severity
    HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMar 4, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-23231High
    netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
    CVSS 7.8
    Linux/Linux, Siemens/RUGGEDCOM RST2428P +3generic
    PublishedMar 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  33. CVE-2026-27446Critical
    Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
    CVSS 9.8
    Apache Software Foundation/Apache ActiveMQ Artemis, Apache Software Foundation/Apache Artemis +1generic
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  34. CVE-2026-27622High
    OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
    CVSS 7.8
    AcademySoftwareFoundation/openexrgeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-3437High
    Improper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engineering Toolkits
    CVSS 8.8
    Portwell/Portwell Engineering Toolkitsgeneric
    PublishedMar 3, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  36. CVE-2026-25673High
    Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows
    CVSS 7.5
    djangoproject/Djangogeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  37. CVE-2026-3344Medium
    WatchGuard Firebox System Integrity Check Bypass
    CVSS 4.9
    WatchGuard/Fireware OSgeneric
    PublishedMar 3, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  38. CVE-2026-3343Medium
    WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI
    CVSS 6.1
    WatchGuard/Fireware OSgeneric
    PublishedMar 3, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-3338High
    PKCS7_verify Signature Validation Bypass in AWS-LC
    CVSS 7.5
    AWS/AWS-LCgeneric
    PublishedMar 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  40. CVE-2026-3336High
    PKCS7_verify Certificate Chain Validation Bypass in AWS-LC
    CVSS 7.5
    AWS/AWS-LCgeneric
    PublishedMar 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  41. CVE-2026-21385High
    Integer Overflow or Wraparound in Graphics
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedMar 2, 2026First seen at HOL May 24, 2026Updated Mar 24, 2026View HOL analysis
  42. CVE-2026-28406High
    kaniko has tar archive path traversal in build context extraction allows writing files outside destination directory
    CVSS 8.2
    chainguard-forks/kanikogeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-2293Critical
    NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass
    CVSS 9.8
    nest.js/nest.jsgeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-3304High
    Multer vulnerable to Denial of Service via incomplete cleanup
    CVSS 7.5
    expressjs/multergeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  45. CVE-2026-2359High
    Multer vulnerable to Denial of Service via resource exhaustion
    CVSS 7.5
    expressjs/multergeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  46. CVE-2024-49761High
    Rexml: rexml: denial of service via inefficient regex parsing
    CVSS 7.5
    rexmlrubygems
    PublishedFeb 27, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  47. CVE-2025-10990High
    Rexml: rexml: denial of service via inefficient regex parsing
    CVSS 7.5
    rexmlrubygems
    PublishedFeb 27, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  48. CVE-2025-12150Low
    Org.keycloak/keycloak-services: webauthn attestation statement verification bypass
    CVSS 3.1
    Keycloak/keycloakgeneric
    PublishedFeb 27, 2026First seen at HOL Aug 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  49. CVE-2026-28364High
    CISA ADP Vulnrichment
    CVSS 7.9
    OCaml/OCamlgeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-1698Medium
    HTTP Host header vulnerability in WebClient and WebScheduler web apps
    CVSS 6.1
    arcinfo/PcVuegeneric
    PublishedFeb 26, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 251 of 405
Previous249250251252253Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,130

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,501–12,550 of 20,228 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-27137High
    Incorrect enforcement of email constraints in crypto/x509
    CVSS 7.5
    Go standard library/crypto/x509, stdlibgeneric · go
    PublishedMar 6, 2026First seen at HOL Jul 2, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  2. CVE-2026-29063Critical
    Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
    CVSS 9.8
    immutable-js/immutable-jsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 14, 2026View HOL analysis
  3. CVE-2026-29091High
    Locutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code Injection
    CVSS 8.1
    locutusjs/locutusgeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-26017High
    CoreDNS ACL Bypass
    CVSS 7.7
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-26018High
    CoreDNS Loop Detection Denial of Service Vulnerability
    CVSS 7.5
    coredns/corednsgeneric
    PublishedMar 6, 2026First seen at HOL Jul 9, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-1468Medium
    Cross-Site Request Forgery in QuickCMS
    CVSS 5.1
    OpenSolution/QuickCMSgeneric
    PublishedMar 6, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  7. CVE-2026-29074High
    SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
    CVSS 7.5
    svg/svgogeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026View HOL analysis
  8. CVE-2026-29062High
    jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
    CVSS 7.5
    FasterXML/jackson-coregeneric
    PublishedMar 6, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-28802Critical
    Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification
    CVSS 9.8
    authlib/authlibgeneric
    PublishedMar 6, 2026First seen at HOL Jul 1, 2026Updated Aug 12, 2026View HOL analysis
  10. CVE-2025-70363High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 6, 2026First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  11. CVE-2026-3047High
    Org.keycloak.broker.saml: keycloak saml broker: authentication bypass due to disabled saml client completing idp-initiated login
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-3009High
    Org.keycloak/keycloak-services: improper enforcement of disabled identity provider in identitybrokerservice (authentication bypass)
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  13. CVE-2026-24457Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Eclipse Foundation/Eclipse GlassFish, Eclipse Foundation/Eclipse OpenMQgeneric
    PublishedMar 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-29054High
    Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  15. CVE-2026-26999High
    Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS)
    CVSS 7.5
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  16. CVE-2026-30783Critical
    RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2026-30789Critical
    RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
    CVSS 9.8
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  18. CVE-2026-30798High
    RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  19. CVE-2026-25048High
    xgrammar: Multi-layer nesting causes DoS
    CVSS 7.5
    mlc-ai/xgrammargeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  20. CVE-2026-30796High
    RustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync
    CVSS 7.5
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jul 19, 2026View HOL analysis
  21. CVE-2026-30792High
    RustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings
    CVSS 8.1
    rustdesk-client/RustDesk Clientgeneric
    PublishedMar 5, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  22. CVE-2026-1605High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse Jettygeneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026View HOL analysis
  23. CVE-2025-45691High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedMar 5, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-2297Medium
    SourcelessFileLoader does not use io.open_code()
    CVSS 5.7
    Python Software Foundation/CPythongeneric
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 13, 2026 Fix availableView HOL analysis
  25. CVE-2025-66024High
    XWiki Blog Application home page vulnerable to Stored XSS via Post Title
    CVSS 9.0
    org.xwiki.contrib.blog:application-blog-ui, xwiki-contrib/application-blog-uigeneric · maven
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-20131High
    Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
    Not scored Known exploited
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL May 24, 2026Updated Aug 14, 2026View HOL analysis
  27. CVE-2026-20079Unknown severity
    Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedMar 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-3520High
    Multer vulnerable to Denial of Service via uncontrolled recursion
    CVSS 7.5
    expressjs/multergeneric
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  29. CVE-2025-15558High
    Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    CVSS 8.0
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  30. CVE-2025-12801Medium
    Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMar 4, 2026First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2025-40894Unknown severity
    HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0
    Not scoredSource severity not reported
    Nozomi Networks/CMC, Nozomi Networks/Guardian +1generic
    PublishedMar 4, 2026First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  32. CVE-2026-23231High
    netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
    CVSS 7.8
    Linux/Linux, Siemens/RUGGEDCOM RST2428P +3generic
    PublishedMar 4, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  33. CVE-2026-27446Critical
    Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
    CVSS 9.8
    Apache Software Foundation/Apache ActiveMQ Artemis, Apache Software Foundation/Apache Artemis +1generic
    PublishedMar 4, 2026First seen at HOL Jul 15, 2026Updated Aug 12, 2026 Fix availableView HOL analysis
  34. CVE-2026-27622High
    OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
    CVSS 7.8
    AcademySoftwareFoundation/openexrgeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-3437High
    Improper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engineering Toolkits
    CVSS 8.8
    Portwell/Portwell Engineering Toolkitsgeneric
    PublishedMar 3, 2026First seen at HOL Jun 25, 2026Updated Jun 25, 2026View HOL analysis
  36. CVE-2026-25673High
    Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows
    CVSS 7.5
    djangoproject/Djangogeneric
    PublishedMar 3, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  37. CVE-2026-3344Medium
    WatchGuard Firebox System Integrity Check Bypass
    CVSS 4.9
    WatchGuard/Fireware OSgeneric
    PublishedMar 3, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  38. CVE-2026-3343Medium
    WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI
    CVSS 6.1
    WatchGuard/Fireware OSgeneric
    PublishedMar 3, 2026First seen at HOL Aug 10, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-3338High
    PKCS7_verify Signature Validation Bypass in AWS-LC
    CVSS 7.5
    AWS/AWS-LCgeneric
    PublishedMar 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  40. CVE-2026-3336High
    PKCS7_verify Certificate Chain Validation Bypass in AWS-LC
    CVSS 7.5
    AWS/AWS-LCgeneric
    PublishedMar 2, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  41. CVE-2026-21385High
    Integer Overflow or Wraparound in Graphics
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedMar 2, 2026First seen at HOL May 24, 2026Updated Mar 24, 2026View HOL analysis
  42. CVE-2026-28406High
    kaniko has tar archive path traversal in build context extraction allows writing files outside destination directory
    CVSS 8.2
    chainguard-forks/kanikogeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-2293Critical
    NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass
    CVSS 9.8
    nest.js/nest.jsgeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-3304High
    Multer vulnerable to Denial of Service via incomplete cleanup
    CVSS 7.5
    expressjs/multergeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  45. CVE-2026-2359High
    Multer vulnerable to Denial of Service via resource exhaustion
    CVSS 7.5
    expressjs/multergeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  46. CVE-2024-49761High
    Rexml: rexml: denial of service via inefficient regex parsing
    CVSS 7.5
    rexmlrubygems
    PublishedFeb 27, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  47. CVE-2025-10990High
    Rexml: rexml: denial of service via inefficient regex parsing
    CVSS 7.5
    rexmlrubygems
    PublishedFeb 27, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  48. CVE-2025-12150Low
    Org.keycloak/keycloak-services: webauthn attestation statement verification bypass
    CVSS 3.1
    Keycloak/keycloakgeneric
    PublishedFeb 27, 2026First seen at HOL Aug 9, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  49. CVE-2026-28364High
    CISA ADP Vulnrichment
    CVSS 7.9
    OCaml/OCamlgeneric
    PublishedFeb 27, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-1698Medium
    HTTP Host header vulnerability in WebClient and WebScheduler web apps
    CVSS 6.1
    arcinfo/PcVuegeneric
    PublishedFeb 26, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 251 of 405
Previous249250251252253Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard