1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 6:35 AM 20,310 active 1,448 known exploited

Catalog summary

20,310

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 6:35 AM 20,310 active 1,448 known exploited

Catalog summary

20,310

Active CVEs

10,147

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 13,501–13,550 of 20,310 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-40182Unknown severity
    crypto: skcipher - Fix reqsize handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-59089Medium
    Python-kdcproxy: remote dos via unbounded tcp upstream buffering
    CVSS 5.9
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  3. CVE-2025-59088High
    Python-kdcproxy: unauthenticated ssrf via realm‑controlled dns srv
    CVSS 8.6
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  4. CVE-2025-40176Unknown severity
    tls: wait for pending async decryptions if tls_strp_msg_hold fails
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2025-40174Unknown severity
    x86/mm: Fix SMP ordering in switch_mm_irqs_off()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2025-40173Unknown severity
    net/ip6_tunnel: Prevent perpetual tunnel growth
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-40172Unknown severity
    accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-40171Unknown severity
    nvmet-fc: move lsop put work to nvmet_fc_ls_req_op
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-40170Unknown severity
    net: use dst_dev_rcu() in sk_setup_caps()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2025-40169Unknown severity
    bpf: Reject negative offsets for ALU ops
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2025-40168Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-40167Unknown severity
    ext4: detect invalid INLINE_DATA + EXTENTS flag combination
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-40166Unknown severity
    drm/xe/guc: Check GuC running state before deregistering exec queue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-40165Unknown severity
    media: nxp: imx8-isi: m2m: Fix streaming cleanup on release
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-40164Medium
    usbnet: Fix using smp_processor_id() in preemptible code warnings
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  16. CVE-2025-40159Unknown severity
    xsk: Harden userspace-supplied xdp_desc validation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2025-40158Unknown severity
    ipv6: use RCU in ip6_output()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2025-40155Unknown severity
    iommu/vt-d: debugfs: Fix legacy mode page table dump logic
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2025-40151Unknown severity
    LoongArch: BPF: No support of struct argument in trampoline programs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2025-40149High
    tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2025-40141Unknown severity
    Bluetooth: ISO: Fix possible UAF on iso_conn_free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2025-40140Unknown severity
    net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2025-40139Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2025-40135Unknown severity
    ipv6: use RCU in ip6_xmit()
    Not scoredSource severity not reported
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2025-40133Unknown severity
    mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2025-40129Unknown severity
    sunrpc: fix null pointer dereference on zero-length checksum
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2025-40124Unknown severity
    sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2025-40123Unknown severity
    bpf: Enforce expected_attach_type for tailcall compatibility
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2025-40118Unknown severity
    scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-40117Unknown severity
    misc: pci_endpoint_test: Fix array underflow in pci_endpoint_test_ioctl()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-40112Unknown severity
    sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-40111Unknown severity
    drm/vmwgfx: Fix Use-after-free in validation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2025-56385Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedNov 12, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2025-63396Low
    CISA ADP Vulnrichment
    CVSS 3.3
    n/a/n/ageneric
    PublishedNov 12, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2025-12748Medium
    Libvirt: denial of service in xml parsing
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedNov 11, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2025-12480High
    CISA ADP Vulnrichment
    Not scored Known exploited
    TrioFox/TrioFoxgeneric
    PublishedNov 10, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  37. CVE-2025-12613Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/cloudinarygeneric
    PublishedNov 10, 2025First seen at HOL Aug 9, 2026Updated Aug 15, 2026 Fix availableView HOL analysis
  38. CVE-2025-63397Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2025-10230Critical
    Samba: command injection in wins server hook script
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedNov 7, 2025First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2025-64328High
    FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
    Not scored Known exploited
    FreePBX/filestoregeneric
    PublishedNov 7, 2025First seen at HOL May 24, 2026Updated Feb 24, 2026View HOL analysis
  41. CVE-2022-50590Medium
    SuiteCRM < 7.12.6 Type Confusion via 'deleteAttachment' Functionality
    CVSS 5.3
    SuiteCRM/SuiteCRMgeneric
    PublishedNov 6, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2022-50589Critical
    SuiteCRM < 7.12.6 SQL Injection via 'export' Functionality
    CVSS 9.8
    SuiteCRM/SuiteCRMgeneric
    PublishedNov 6, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2025-63560High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedNov 6, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2023-43000High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/Safari, Apple/iOS and iPadOS +1generic
    PublishedNov 5, 2025First seen at HOL May 24, 2026Updated Mar 26, 2026 Fix availableView HOL analysis
  45. CVE-2025-56231Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedNov 5, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2025-57130High
    CISA ADP Vulnrichment
    CVSS 8.3
    n/a/n/ageneric
    PublishedNov 5, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  47. CVE-2025-43457Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +3generic
    PublishedNov 4, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  48. CVE-2025-43441Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +3generic
    PublishedNov 4, 2025First seen at HOL Jul 15, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-43323Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedNov 4, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-43440Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedNov 4, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 271 of 407
Previous269270271272273Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,147

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 13,501–13,550 of 20,310 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-40182Unknown severity
    crypto: skcipher - Fix reqsize handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-59089Medium
    Python-kdcproxy: remote dos via unbounded tcp upstream buffering
    CVSS 5.9
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  3. CVE-2025-59088High
    Python-kdcproxy: unauthenticated ssrf via realm‑controlled dns srv
    CVSS 8.6
    latchset/kdcproxygeneric
    PublishedNov 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  4. CVE-2025-40176Unknown severity
    tls: wait for pending async decryptions if tls_strp_msg_hold fails
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2025-40174Unknown severity
    x86/mm: Fix SMP ordering in switch_mm_irqs_off()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2025-40173Unknown severity
    net/ip6_tunnel: Prevent perpetual tunnel growth
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-40172Unknown severity
    accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-40171Unknown severity
    nvmet-fc: move lsop put work to nvmet_fc_ls_req_op
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-40170Unknown severity
    net: use dst_dev_rcu() in sk_setup_caps()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2025-40169Unknown severity
    bpf: Reject negative offsets for ALU ops
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2025-40168Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-40167Unknown severity
    ext4: detect invalid INLINE_DATA + EXTENTS flag combination
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-40166Unknown severity
    drm/xe/guc: Check GuC running state before deregistering exec queue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-40165Unknown severity
    media: nxp: imx8-isi: m2m: Fix streaming cleanup on release
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-40164Medium
    usbnet: Fix using smp_processor_id() in preemptible code warnings
    CVSS 5.5
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Jun 19, 2026Updated Jun 19, 2026 Fix availableView HOL analysis
  16. CVE-2025-40159Unknown severity
    xsk: Harden userspace-supplied xdp_desc validation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2025-40158Unknown severity
    ipv6: use RCU in ip6_output()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2025-40155Unknown severity
    iommu/vt-d: debugfs: Fix legacy mode page table dump logic
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2025-40151Unknown severity
    LoongArch: BPF: No support of struct argument in trampoline programs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2025-40149High
    tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
    CVSS 7.8
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2025-40141Unknown severity
    Bluetooth: ISO: Fix possible UAF on iso_conn_free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2025-40140Unknown severity
    net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2025-40139Unknown severity
    smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2025-40135Unknown severity
    ipv6: use RCU in ip6_xmit()
    Not scoredSource severity not reported
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedNov 12, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2025-40133Unknown severity
    mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2025-40129Unknown severity
    sunrpc: fix null pointer dereference on zero-length checksum
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2025-40124Unknown severity
    sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2025-40123Unknown severity
    bpf: Enforce expected_attach_type for tailcall compatibility
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2025-40118Unknown severity
    scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-40117Unknown severity
    misc: pci_endpoint_test: Fix array underflow in pci_endpoint_test_ioctl()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-40112Unknown severity
    sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-40111Unknown severity
    drm/vmwgfx: Fix Use-after-free in validation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedNov 12, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2025-56385Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedNov 12, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  34. CVE-2025-63396Low
    CISA ADP Vulnrichment
    CVSS 3.3
    n/a/n/ageneric
    PublishedNov 12, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2025-12748Medium
    Libvirt: denial of service in xml parsing
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedNov 11, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2025-12480High
    CISA ADP Vulnrichment
    Not scored Known exploited
    TrioFox/TrioFoxgeneric
    PublishedNov 10, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  37. CVE-2025-12613Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/cloudinarygeneric
    PublishedNov 10, 2025First seen at HOL Aug 9, 2026Updated Aug 15, 2026 Fix availableView HOL analysis
  38. CVE-2025-63397Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedNov 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  39. CVE-2025-10230Critical
    Samba: command injection in wins server hook script
    CVSS 10.0
    Affected software not mappedEcosystem not listed
    PublishedNov 7, 2025First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2025-64328High
    FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
    Not scored Known exploited
    FreePBX/filestoregeneric
    PublishedNov 7, 2025First seen at HOL May 24, 2026Updated Feb 24, 2026View HOL analysis
  41. CVE-2022-50590Medium
    SuiteCRM < 7.12.6 Type Confusion via 'deleteAttachment' Functionality
    CVSS 5.3
    SuiteCRM/SuiteCRMgeneric
    PublishedNov 6, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2022-50589Critical
    SuiteCRM < 7.12.6 SQL Injection via 'export' Functionality
    CVSS 9.8
    SuiteCRM/SuiteCRMgeneric
    PublishedNov 6, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  43. CVE-2025-63560High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedNov 6, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2023-43000High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/Safari, Apple/iOS and iPadOS +1generic
    PublishedNov 5, 2025First seen at HOL May 24, 2026Updated Mar 26, 2026 Fix availableView HOL analysis
  45. CVE-2025-56231Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedNov 5, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  46. CVE-2025-57130High
    CISA ADP Vulnrichment
    CVSS 8.3
    n/a/n/ageneric
    PublishedNov 5, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  47. CVE-2025-43457Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +3generic
    PublishedNov 4, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  48. CVE-2025-43441Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Apple/Safari, Apple/iOS and iPadOS +3generic
    PublishedNov 4, 2025First seen at HOL Jul 15, 2026Updated Aug 14, 2026 Fix availableView HOL analysis
  49. CVE-2025-43323Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedNov 4, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-43440Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedNov 4, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 271 of 407
Previous269270271272273Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard