1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 3:40 AM 20,258 active 1,448 known exploited

Catalog summary

20,258

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 3:40 AM 20,258 active 1,448 known exploited

Catalog summary

20,258

Active CVEs

10,136

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 13,251–13,300 of 20,258 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-56704High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2025-61078Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-65594High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2025-65882Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2025-48633High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Androidgeneric
    PublishedDec 8, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  6. CVE-2025-48572High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Androidgeneric
    PublishedDec 8, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  7. CVE-2023-53769Critical
    virt/coco/sev-guest: Double-buffer messages
    CVSS 9.3
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2023-53768High
    regmap-irq: Fix out-of-bounds access when allocating config buffers
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2023-53764High
    wifi: ath12k: Handle lock during peer_id find
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2023-53763High
    Revert "f2fs: fix to do sanity check on extent cache correctly"
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2023-53762High
    Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2023-53759High
    HID: hidraw: fix data race on device refcount
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2023-53753High
    drm/amd/display: fix mapping to non-allocated address
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2023-53752High
    net: deal with integer overflows in kmalloc_reserve()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2023-53751Critical
    cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2023-53748High
    media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2023-53747High
    vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2022-50630High
    mm: hugetlb: fix UAF in hugetlb_handle_userfault
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2022-50627Unknown severity
    wifi: ath11k: fix monitor mode bringup crash
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 15, 2026Updated Aug 15, 2026 Fix availableView HOL analysis
  20. CVE-2022-50623High
    fpga: prevent integer overflow in dfl_feature_ioctl_set_irq()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2025-40307High
    exfat: validate cluster allocation bits of the allocation bitmap
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  22. CVE-2025-65363High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  23. CVE-2025-65795High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2025-65796Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2025-65797Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2025-65798Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2025-65799Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  28. CVE-2025-40282Unknown severity
    Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2025-40280Unknown severity
    tipc: Fix use-after-free in tipc_mon_reinit_self().
    Not scoredSource severity not reported
    Linux/Linux, Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-40277Unknown severity
    drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-40276Unknown severity
    drm/panthor: Flush shmem writes before mapping buffers CPU-uncached
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-40274Unknown severity
    KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2025-40273Unknown severity
    NFSD: free copynotify stateid in nfs4_free_ol_stateid()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2025-40272Unknown severity
    mm/secretmem: fix use-after-free race in fault handler
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2025-40271Unknown severity
    fs/proc: fix uaf in proc_readdir_de()
    Not scoredSource severity not reported
    Linux/Linux, Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2025-40270Unknown severity
    mm, swap: fix potential UAF issue for VMA readahead
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-40269Unknown severity
    ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-34291High
    Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
    Not scored Known exploited
    Langflow/Langflowgeneric
    PublishedDec 5, 2025First seen at HOL May 24, 2026Updated Jul 14, 2026View HOL analysis
  39. CVE-2025-34256Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  40. CVE-2025-34265Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via rule-engines
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  41. CVE-2025-34263Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/dashboards/menus
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  42. CVE-2025-34266Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menus
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  43. CVE-2025-34264Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via dog/{agentId}
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  44. CVE-2025-34262Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  45. CVE-2025-34258Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/plan
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  46. CVE-2025-34259Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/building
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  47. CVE-2025-34261Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  48. CVE-2025-34260Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/schedule
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-34257Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/defined
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  50. CVE-2025-14104Medium
    Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
    CVSS 6.1
    util-linux/util-linuxgeneric
    PublishedDec 5, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
Page 266 of 406
Previous264265266267268Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,136

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 13,251–13,300 of 20,258 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-56704High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  2. CVE-2025-61078Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-65594High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  4. CVE-2025-65882Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedDec 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  5. CVE-2025-48633High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Androidgeneric
    PublishedDec 8, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  6. CVE-2025-48572High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Androidgeneric
    PublishedDec 8, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  7. CVE-2023-53769Critical
    virt/coco/sev-guest: Double-buffer messages
    CVSS 9.3
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2023-53768High
    regmap-irq: Fix out-of-bounds access when allocating config buffers
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2023-53764High
    wifi: ath12k: Handle lock during peer_id find
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2023-53763High
    Revert "f2fs: fix to do sanity check on extent cache correctly"
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2023-53762High
    Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2023-53759High
    HID: hidraw: fix data race on device refcount
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2023-53753High
    drm/amd/display: fix mapping to non-allocated address
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2023-53752High
    net: deal with integer overflows in kmalloc_reserve()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2023-53751Critical
    cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2023-53748High
    media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2023-53747High
    vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2022-50630High
    mm: hugetlb: fix UAF in hugetlb_handle_userfault
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2022-50627Unknown severity
    wifi: ath11k: fix monitor mode bringup crash
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 15, 2026Updated Aug 15, 2026 Fix availableView HOL analysis
  20. CVE-2022-50623High
    fpga: prevent integer overflow in dfl_feature_ioctl_set_irq()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2025-40307High
    exfat: validate cluster allocation bits of the allocation bitmap
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedDec 8, 2025First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  22. CVE-2025-65363High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  23. CVE-2025-65795High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  24. CVE-2025-65796Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  25. CVE-2025-65797Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2025-65798Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2025-65799Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedDec 8, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  28. CVE-2025-40282Unknown severity
    Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2025-40280Unknown severity
    tipc: Fix use-after-free in tipc_mon_reinit_self().
    Not scoredSource severity not reported
    Linux/Linux, Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-40277Unknown severity
    drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-40276Unknown severity
    drm/panthor: Flush shmem writes before mapping buffers CPU-uncached
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-40274Unknown severity
    KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2025-40273Unknown severity
    NFSD: free copynotify stateid in nfs4_free_ol_stateid()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2025-40272Unknown severity
    mm/secretmem: fix use-after-free race in fault handler
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2025-40271Unknown severity
    fs/proc: fix uaf in proc_readdir_de()
    Not scoredSource severity not reported
    Linux/Linux, Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2025-40270Unknown severity
    mm, swap: fix potential UAF issue for VMA readahead
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-40269Unknown severity
    ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedDec 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-34291High
    Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
    Not scored Known exploited
    Langflow/Langflowgeneric
    PublishedDec 5, 2025First seen at HOL May 24, 2026Updated Jul 14, 2026View HOL analysis
  39. CVE-2025-34256Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  40. CVE-2025-34265Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via rule-engines
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  41. CVE-2025-34263Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/dashboards/menus
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  42. CVE-2025-34266Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menus
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  43. CVE-2025-34264Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via dog/{agentId}
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  44. CVE-2025-34262Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  45. CVE-2025-34258Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/plan
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  46. CVE-2025-34259Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/building
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  47. CVE-2025-34261Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  48. CVE-2025-34260Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/schedule
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-34257Unknown severity
    Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/defined
    Not scoredSource severity not reported
    Advantech Co., Ltd./WISE-DeviceOn Servergeneric
    PublishedDec 5, 2025First seen at HOL Aug 14, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  50. CVE-2025-14104Medium
    Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
    CVSS 6.1
    util-linux/util-linuxgeneric
    PublishedDec 5, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
Page 266 of 406
Previous264265266267268Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard