1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 7:20 PM 20,347 active 1,448 known exploited

Catalog summary

20,347

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 7:20 PM 20,347 active 1,448 known exploited

Catalog summary

20,347

Active CVEs

10,168

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 14,851–14,900 of 20,347 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-38005Unknown severity
    dmaengine: ti: k3-udma: Add missing locking
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-46157Critical
    CISA ADP Vulnrichment
    CVSS 9.9
    n/a/n/ageneric
    PublishedJun 18, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-49180High
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extension
    CVSS 7.8
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  4. CVE-2025-49179High
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension
    CVSS 7.3
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  5. CVE-2025-49178Medium
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignore
    CVSS 5.5
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  6. CVE-2025-49177Medium
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode
    CVSS 6.1
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  7. CVE-2025-49176High
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension
    CVSS 7.3
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  8. CVE-2025-49175Medium
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors
    CVSS 6.1
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  9. CVE-2025-6199Low
    Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder
    CVSS 3.3
    Affected software not mappedEcosystem not listed
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  10. CVE-2025-4404Critical
    Freeipa: idm: privilege escalation from host to domain admin in freeipa
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  11. CVE-2025-6020High
    Linux-pam: linux-pam directory traversal
    CVSS 7.8
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +9generic
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  12. CVE-2025-5777High
    NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
    CVSS 7.5 Known exploited
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 17, 2025First seen at HOL May 24, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  13. CVE-2025-43200High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/iPadOS +3generic
    PublishedJun 16, 2025First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  14. CVE-2025-49794Critical
    Libxml: heap use after free (uaf) leads to denial of service (dos)
    CVSS 9.1
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +10generic
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  15. CVE-2025-6170Low
    Libxml2: stack buffer overflow in xmllint interactive shell command handling
    CVSS 2.5
    Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  16. CVE-2025-49795High
    Libxml: null pointer dereference leads to denial of service (dos)
    CVSS 7.5
    GNOME/libxml2, Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  17. CVE-2025-49796Critical
    Libxml: type confusion leads to denial of service (dos)
    CVSS 9.1
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +10generic
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  18. CVE-2025-6035Medium
    Gimp: gimp integer overflow
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedJun 13, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  19. CVE-2025-46060Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  20. CVE-2025-6021High
    Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
    CVSS 7.5
    Siemens/SIMATIC CN 4100generic
    PublishedJun 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  21. CVE-2025-46035High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 12, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  22. CVE-2025-2884Medium
    Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation
    CVSS 6.6
    Siemens/SIMATIC CN 4100, Siemens/SIMATIC Field PG M5 +23generic
    PublishedJun 10, 2025First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2025-25250Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Fortinet/FortiOS, Fortinet/FortiSASE +1generic
    PublishedJun 10, 2025First seen at HOL Jun 23, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  24. CVE-2025-24471Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Fortinet/FortiOS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2025First seen at HOL Aug 6, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  25. CVE-2024-50562Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Fortinet/FortiOS, Fortinet/FortiPAM +2generic
    PublishedJun 10, 2025First seen at HOL Aug 6, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  26. CVE-2024-41502Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2024-41503Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  28. CVE-2024-41504Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  29. CVE-2024-41505Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2025-5914High
    Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
    CVSS 7.8
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  31. CVE-2025-5918Low
    Libarchive: reading past eof may be triggered for piped file streams
    CVSS 3.9
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2025-5917Low
    Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c
    CVSS 2.8
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  33. CVE-2025-5916Low
    Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c
    CVSS 3.9
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  34. CVE-2025-5915Medium
    Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  35. CVE-2025-47711Medium
    Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2025-47712Medium
    Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2025-46041Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedJun 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  38. CVE-2025-38004Unknown severity
    can: bcm: add locking for bcm_op runtime updates
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 8, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-38003Unknown severity
    can: bcm: add missing rcu read protection for procfs content
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 8, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-38002Unknown severity
    io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-38001Unknown severity
    net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-0620Medium
    Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJun 6, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  43. CVE-2025-38000Unknown severity
    sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-47827High
    CISA ADP Vulnrichment
    Not scored Known exploited
    n/a/n/ageneric
    PublishedJun 5, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  45. CVE-2025-5521Medium
    WuKongOpenSource WukongCRM updataPassword cross-site request forgery
    CVSS 4.3
    WuKongOpenSource/WukongCRMgeneric
    PublishedJun 3, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  46. CVE-2025-21479High
    Incorrect Authorization in Graphics
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedJun 3, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  47. CVE-2025-27038High
    Use After Free in Graphics
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedJun 3, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  48. CVE-2025-21480High
    Incorrect Authorization in Graphics Windows
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedJun 3, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  49. CVE-2025-44148Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 3, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  50. CVE-2025-5419High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Chromegeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
Page 298 of 407
Previous296297298299300Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,168

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 14,851–14,900 of 20,347 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-38005Unknown severity
    dmaengine: ti: k3-udma: Add missing locking
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-46157Critical
    CISA ADP Vulnrichment
    CVSS 9.9
    n/a/n/ageneric
    PublishedJun 18, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  3. CVE-2025-49180High
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extension
    CVSS 7.8
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  4. CVE-2025-49179High
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension
    CVSS 7.3
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  5. CVE-2025-49178Medium
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignore
    CVSS 5.5
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  6. CVE-2025-49177Medium
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode
    CVSS 6.1
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  7. CVE-2025-49176High
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension
    CVSS 7.3
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  8. CVE-2025-49175Medium
    Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors
    CVSS 6.1
    X.Org/xwaylandgeneric
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  9. CVE-2025-6199Low
    Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder
    CVSS 3.3
    Affected software not mappedEcosystem not listed
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  10. CVE-2025-4404Critical
    Freeipa: idm: privilege escalation from host to domain admin in freeipa
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  11. CVE-2025-6020High
    Linux-pam: linux-pam directory traversal
    CVSS 7.8
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +9generic
    PublishedJun 17, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  12. CVE-2025-5777High
    NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
    CVSS 7.5 Known exploited
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 17, 2025First seen at HOL May 24, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  13. CVE-2025-43200High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/iPadOS +3generic
    PublishedJun 16, 2025First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  14. CVE-2025-49794Critical
    Libxml: heap use after free (uaf) leads to denial of service (dos)
    CVSS 9.1
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +10generic
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  15. CVE-2025-6170Low
    Libxml2: stack buffer overflow in xmllint interactive shell command handling
    CVSS 2.5
    Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  16. CVE-2025-49795High
    Libxml: null pointer dereference leads to denial of service (dos)
    CVSS 7.5
    GNOME/libxml2, Siemens/RUGGEDCOM RST2428Pgeneric
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  17. CVE-2025-49796Critical
    Libxml: type confusion leads to denial of service (dos)
    CVSS 9.1
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +10generic
    PublishedJun 16, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  18. CVE-2025-6035Medium
    Gimp: gimp integer overflow
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedJun 13, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  19. CVE-2025-46060Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 13, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  20. CVE-2025-6021High
    Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
    CVSS 7.5
    Siemens/SIMATIC CN 4100generic
    PublishedJun 12, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  21. CVE-2025-46035High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 12, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  22. CVE-2025-2884Medium
    Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation
    CVSS 6.6
    Siemens/SIMATIC CN 4100, Siemens/SIMATIC Field PG M5 +23generic
    PublishedJun 10, 2025First seen at HOL Aug 11, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  23. CVE-2025-25250Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Fortinet/FortiOS, Fortinet/FortiSASE +1generic
    PublishedJun 10, 2025First seen at HOL Jun 23, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  24. CVE-2025-24471Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Fortinet/FortiOS, Siemens/RUGGEDCOM APE1808generic
    PublishedJun 10, 2025First seen at HOL Aug 6, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  25. CVE-2024-50562Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Fortinet/FortiOS, Fortinet/FortiPAM +2generic
    PublishedJun 10, 2025First seen at HOL Aug 6, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  26. CVE-2024-41502Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  27. CVE-2024-41503Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  28. CVE-2024-41504Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  29. CVE-2024-41505Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJun 10, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  30. CVE-2025-5914High
    Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
    CVSS 7.8
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Aug 16, 2026 Fix availableView HOL analysis
  31. CVE-2025-5918Low
    Libarchive: reading past eof may be triggered for piped file streams
    CVSS 3.9
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2025-5917Low
    Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c
    CVSS 2.8
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  33. CVE-2025-5916Low
    Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c
    CVSS 3.9
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  34. CVE-2025-5915Medium
    Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  35. CVE-2025-47711Medium
    Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2025-47712Medium
    Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2025-46041Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedJun 9, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  38. CVE-2025-38004Unknown severity
    can: bcm: add locking for bcm_op runtime updates
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 8, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-38003Unknown severity
    can: bcm: add missing rcu read protection for procfs content
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 8, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-38002Unknown severity
    io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-38001Unknown severity
    net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-0620Medium
    Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJun 6, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  43. CVE-2025-38000Unknown severity
    sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJun 6, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-47827High
    CISA ADP Vulnrichment
    Not scored Known exploited
    n/a/n/ageneric
    PublishedJun 5, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  45. CVE-2025-5521Medium
    WuKongOpenSource WukongCRM updataPassword cross-site request forgery
    CVSS 4.3
    WuKongOpenSource/WukongCRMgeneric
    PublishedJun 3, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  46. CVE-2025-21479High
    Incorrect Authorization in Graphics
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedJun 3, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  47. CVE-2025-27038High
    Use After Free in Graphics
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedJun 3, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  48. CVE-2025-21480High
    Incorrect Authorization in Graphics Windows
    Not scored Known exploited
    Qualcomm, Inc./Snapdragongeneric
    PublishedJun 3, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  49. CVE-2025-44148Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 3, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  50. CVE-2025-5419High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Chromegeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
Page 298 of 407
Previous296297298299300Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard