HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Oct 1, 2026, 3:43 PM 42,400 active 1,506 known exploited

Catalog summary

42,400

Active CVEs

21,999

Critical + high

1,506

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 12,551–12,600 of 42,400 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-85242Medium
    Server-Side Request Forgery via Favicon Redirect to Local Network Resources in PlaywrightCapture
    CVSS 6.9
    Lookyloo/PlaywrightCapturegeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  2. CVE-2026-84736High
    CISA ADP Vulnrichment
    CVSS 8.3
    Eclipse Foundation/Eclipse aeriOSgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 3, 2026 Fix availableView HOL analysis
  3. CVE-2026-85138High
    SeaCMS WeChat index.php addslashes sql injection
    CVSS 7.3
    n/a/SeaCMSgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 3, 2026View HOL analysis
  4. CVE-2026-85239High
    MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service
    CVSS 7.1
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 11, 2026View HOL analysis
  5. CVE-2026-85238High
    Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking
    CVSS 7.6
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 11, 2026View HOL analysis
  6. CVE-2026-53720Medium
    pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
    CVSS 5.1
    jetperch/pymonocypher, pymonocyphergeneric · pip
    PublishedSep 3, 2026First seen at HOL Jul 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  7. CVE-2026-83961High
    ColdFusion | Improper Authentication (CWE-287)
    CVSS 7.1
    Adobe/ColdFusion 2023, Adobe/ColdFusion 2025generic
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026View HOL analysis
  8. CVE-2026-50554Medium
    Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-mark
    CVSS 5.3
    enchant97/note-mark, github.com/enchant97/note-mark/backendgeneric · go
    PublishedSep 3, 2026First seen at HOL Jul 9, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  9. CVE-2026-85237High
    Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass
    CVSS 8.6
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 11, 2026View HOL analysis
  10. CVE-2026-48486High
    Signum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary miner reward inflation
    CVSS 7.5
    signum-network/signum-nodegeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026View HOL analysis
  11. CVE-2026-71963High
    Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection
    CVSS 8.8
    NousResearch/hermes-agentgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 8, 2026View HOL analysis
  12. CVE-2026-84967Medium
    Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal
    CVSS 4.3
    MongoDB/MongoDB for VS Codegeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  13. CVE-2026-53924High
    Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes
    CVSS 8.7
    1Hive/gardens-v2generic
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  14. CVE-2026-57445High
    Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
    CVSS 8.7
    1Hive/gardens-v2generic
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  15. CVE-2026-55658High
    Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the permissionless claim()
    CVSS 7.7
    1Hive/gardens-v2generic
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  16. CVE-2026-82525Medium
    Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
    CVSS 5.5
    Exterro/FTK Imagergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-75036Medium
    Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
    CVSS 5.3
    SUSE/Fleetgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-85137High
    SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection
    CVSS 7.3
    n/a/SeaCMSgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 5, 2026View HOL analysis
  19. CVE-2026-85236High
    MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request
    CVSS 8.8
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 11, 2026View HOL analysis
  20. CVE-2026-75035High
    Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass
    CVSS 7.7
    SUSE/Ranchergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  21. CVE-2026-84962Medium
    Authenticated KMS request forgery via CRLF injection in GCP key identifier strings
    CVSS 4.2
    MongoDB/libmongocryptgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  22. CVE-2026-84963Medium
    Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
    CVSS 5.3
    MongoDB/C Drivergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  23. CVE-2026-84964Medium
    Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
    CVSS 5.9
    MongoDB/C Drivergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  24. CVE-2026-84965Medium
    Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds
    CVSS 5.1
    MongoDB/C Drivergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  25. CVE-2026-75034High
    Rancher: SAML Assertion Replay
    CVSS 7.4
    SUSE/Ranchergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  26. CVE-2026-84966Medium
    BSON element injection via NUL-embedded document keys in builder append
    CVSS 5.1
    MongoDB/C++ Drivergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  27. CVE-2026-84969Low
    Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output
    CVSS 3.7
    MongoDB/C Drivergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  28. CVE-2026-84971Medium
    Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path
    CVSS 6.5
    MongoDB/libmongocryptgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  29. CVE-2026-75033High
    Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing
    CVSS 7.7
    SUSE/Ranchergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  30. CVE-2026-84970Medium
    Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser
    CVSS 6.2
    MongoDB/C++ Drivergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 10, 2026 Fix availableView HOL analysis
  31. CVE-2026-71404High
    Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole
    CVSS 8.7
    SUSE/Ranchergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  32. CVE-2026-85230Medium
    MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection
    CVSS 5.3
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 10, 2026View HOL analysis
  33. CVE-2026-84989High
    ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags
    CVSS 7.1
    ntop/ntopnggeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026View HOL analysis
  34. CVE-2026-71403Medium
    Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind
    CVSS 6.1
    SUSE/Ranchergeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  35. CVE-2026-85227Medium
    Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAttachedAttributes Parameters
    CVSS 6.1
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 10, 2026View HOL analysis
  36. CVE-2026-85226Medium
    MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Correlations
    CVSS 5.3
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 10, 2026View HOL analysis
  37. CVE-2026-56128Medium
    pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php
    CVSS 5.4
    Netgate/pfSense CE, Netgate/pfSense Plusgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  38. CVE-2026-63694Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    Dell/SmartFabric OS10generic
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 4, 2026 Fix availableView HOL analysis
  39. CVE-2026-56127Medium
    pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php
    CVSS 5.4
    Netgate/pfSense CE, Netgate/pfSense Plusgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  40. CVE-2026-56126Medium
    pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php
    CVSS 5.4
    Netgate/pfSense CE, Netgate/pfSense Plusgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 9, 2026 Fix availableView HOL analysis
  41. CVE-2026-85221High
    MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attacks
    CVSS 7.6
    misp/mispgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 10, 2026View HOL analysis
  42. CVE-2026-35160Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    Dell/SmartFabric OS10 Softwaregeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 4, 2026 Fix availableView HOL analysis
  43. CVE-2026-85214High
    vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite
    CVSS 7.2
    lenve/vhrgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
  44. CVE-2026-85213High
    Kill Bill through 0.24.21 Missing Authorization on AdminResource Endpoints
    CVSS 7.2
    killbill/killbillgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
  45. CVE-2026-85212High
    CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check
    CVSS 8.7
    crmeb/CRMEBgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
  46. CVE-2026-85211High
    Label Studio through 1.23.0 Cross-Organization Storage URI Resolution
    CVSS 8.3
    HumanSignal/label-studiogeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
  47. CVE-2026-85210Medium
    Oppia through 3.5.2 Missing Authorization on AdminRoleHandler GET
    CVSS 5.3
    oppia/oppiageneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
  48. CVE-2026-85183Critical
    Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS
    CVSS 9.3
    Avaiga/taipygeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
  49. CVE-2026-85182High
    vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change
    CVSS 7.7
    lenve/vhrgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
  50. CVE-2026-85181Critical
    CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
    CVSS 9.3
    dianping/catgeneric
    PublishedSep 3, 2026First seen at HOL Sep 3, 2026Updated Sep 24, 2026View HOL analysis
Page 252 of 848
Previous250251252253254Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard