1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 8:15 PM 20,348 active 1,448 known exploited

Catalog summary

20,348

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 8:15 PM 20,348 active 1,448 known exploited

Catalog summary

20,348

Active CVEs

10,175

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 14,901–14,950 of 20,348 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-5419High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Chromegeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  2. CVE-2025-5086High
    Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
    Not scored Known exploited
    Dassault Systèmes/DELMIA Aprisogeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  3. CVE-2025-49113High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Roundcube/Webmailgeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Mar 13, 2026 Fix availableView HOL analysis
  4. CVE-2025-4598Medium
    Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
    CVSS 4.7
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +1generic
    PublishedMay 30, 2025First seen at HOL Jun 25, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2025-44619Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMay 30, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  6. CVE-2025-37998Unknown severity
    openvswitch: Fix unsafe attribute parsing in output_userspace()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-37997Unknown severity
    netfilter: ipset: fix region locking in hash types
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-37996Unknown severity
    KVM: arm64: Fix uninitialized memcache pointer in user_mem_abort()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-5276High
    CISA ADP Vulnrichment
    CVSS 7.4
    n/a/mcp-markdownify-servergeneric
    PublishedMay 29, 2025First seen at HOL Jul 2, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2025-5273Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/mcp-markdownify-servergeneric
    PublishedMay 29, 2025First seen at HOL Jul 16, 2026Updated Jul 26, 2026 Fix availableView HOL analysis
  11. CVE-2025-45343Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMay 28, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  12. CVE-2025-48927High
    CISA ADP Vulnrichment
    Not scored Known exploited
    TeleMessage/servicegeneric
    PublishedMay 28, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  13. CVE-2025-48928High
    CISA ADP Vulnrichment
    Not scored Known exploited
    TeleMessage/servicegeneric
    PublishedMay 28, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  14. CVE-2025-5278Medium
    Coreutils: heap buffer under-read in gnu coreutils sort via key specification
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 24, 2026Updated Aug 16, 2026View HOL analysis
  15. CVE-2025-5222High
    Icu: stack buffer overflow in the srbroot::addtag function
    CVSS 7.0
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2025-5245Unknown severity
    GNU Binutils objdump debug.c debug_type_samep memory corruption
    Not scoredSource severity not reported
    GNU/Binutils, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedMay 27, 2025First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2025-48798High
    Gimp: multiple use after free in xcf parser
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 27, 2026View HOL analysis
  18. CVE-2025-48797High
    Gimp: multiple heap buffer overflows in tga parser
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 27, 2026View HOL analysis
  19. CVE-2025-48796High
    Gimp: stack-based buffer overflows in file-ico
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 27, 2026View HOL analysis
  20. CVE-2025-5244Unknown severity
    GNU Binutils ld elflink.c elf_gc_sweep memory corruption
    Not scoredSource severity not reported
    GNU/Binutils, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedMay 27, 2025First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2025-5024High
    Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMay 22, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  22. CVE-2025-34026High
    Versa Concerto Actuator Authentication Bypass Information Leak
    Not scored Known exploited
    Versa/Concertogeneric
    PublishedMay 21, 2025First seen at HOL May 24, 2026Updated Feb 12, 2026View HOL analysis
  23. CVE-2025-4008High
    Arbitrary Command Injection in Smartbedded MeteoBridge
    Not scored Known exploited
    Smartbedded/MeteoBridgegeneric
    PublishedMay 21, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  24. CVE-2025-4969Medium
    Libsoup: off-by-one out-of-bounds read in find_boundary() in soup-multipart.c
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMay 21, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  25. CVE-2024-57529Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMay 21, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2025-37988Unknown severity
    fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2025-37984Unknown severity
    crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2025-37980Medium
    block: fix resource leak in blk_register_queue() error path
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  29. CVE-2025-37979Unknown severity
    ASoC: qcom: Fix sc7280 lpass potential buffer overflow
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-37977Unknown severity
    scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-37973Unknown severity
    wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-37972Medium
    Input: mtk-pmic-keys - fix possible null pointer dereference
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  33. CVE-2025-37964Medium
    x86/mm: Eliminate window where TLB flushes may be inadvertently skipped
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2025-37959Medium
    bpf: Scrub packet on bpf_redirect_peer
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2025-37957Unknown severity
    KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2025-37956Unknown severity
    ksmbd: prevent rename with empty string
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-37954Unknown severity
    smb: client: Avoid race in open_cached_dir with lease breaks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-37952Unknown severity
    ksmbd: Fix UAF in __close_file_table_ids
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-37949Unknown severity
    xenbus: Use kref to track req lifetime
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-37947Unknown severity
    ksmbd: prevent out-of-bounds stream writes by validating *pos
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-37945Medium
    net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2025-37944Unknown severity
    wifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2025-37943Unknown severity
    wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-37938Unknown severity
    tracing: Verify event formats that have "%*p.."
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2025-37936Unknown severity
    perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value.
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2025-37935Unknown severity
    net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2025-37931Unknown severity
    btrfs: adjust subpage bit start based on sectorsize
    Not scoredSource severity not reported
    Linux/Linux, Siemens/SIMATIC CN 4100generic
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-37926Unknown severity
    ksmbd: fix use-after-free in ksmbd_session_rpc_open
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2025-37924Unknown severity
    ksmbd: fix use-after-free in kerberos authentication
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-37923Unknown severity
    tracing: Fix oob write in trace_seq_to_buffer()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 299 of 407
Previous297298299300301Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,175

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 14,901–14,950 of 20,348 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-5419High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Google/Chromegeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  2. CVE-2025-5086High
    Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
    Not scored Known exploited
    Dassault Systèmes/DELMIA Aprisogeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  3. CVE-2025-49113High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Roundcube/Webmailgeneric
    PublishedJun 2, 2025First seen at HOL May 24, 2026Updated Mar 13, 2026 Fix availableView HOL analysis
  4. CVE-2025-4598Medium
    Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
    CVSS 4.7
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +1generic
    PublishedMay 30, 2025First seen at HOL Jun 25, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2025-44619Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedMay 30, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  6. CVE-2025-37998Unknown severity
    openvswitch: Fix unsafe attribute parsing in output_userspace()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-37997Unknown severity
    netfilter: ipset: fix region locking in hash types
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-37996Unknown severity
    KVM: arm64: Fix uninitialized memcache pointer in user_mem_abort()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-5276High
    CISA ADP Vulnrichment
    CVSS 7.4
    n/a/mcp-markdownify-servergeneric
    PublishedMay 29, 2025First seen at HOL Jul 2, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2025-5273Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/mcp-markdownify-servergeneric
    PublishedMay 29, 2025First seen at HOL Jul 16, 2026Updated Jul 26, 2026 Fix availableView HOL analysis
  11. CVE-2025-45343Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedMay 28, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  12. CVE-2025-48927High
    CISA ADP Vulnrichment
    Not scored Known exploited
    TeleMessage/servicegeneric
    PublishedMay 28, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  13. CVE-2025-48928High
    CISA ADP Vulnrichment
    Not scored Known exploited
    TeleMessage/servicegeneric
    PublishedMay 28, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  14. CVE-2025-5278Medium
    Coreutils: heap buffer under-read in gnu coreutils sort via key specification
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 24, 2026Updated Aug 16, 2026View HOL analysis
  15. CVE-2025-5222High
    Icu: stack buffer overflow in the srbroot::addtag function
    CVSS 7.0
    Siemens/SIDIS Secured SmartPluggeneric
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  16. CVE-2025-5245Unknown severity
    GNU Binutils objdump debug.c debug_type_samep memory corruption
    Not scoredSource severity not reported
    GNU/Binutils, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedMay 27, 2025First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2025-48798High
    Gimp: multiple use after free in xcf parser
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 27, 2026View HOL analysis
  18. CVE-2025-48797High
    Gimp: multiple heap buffer overflows in tga parser
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 27, 2026View HOL analysis
  19. CVE-2025-48796High
    Gimp: stack-based buffer overflows in file-ico
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedMay 27, 2025First seen at HOL Jun 25, 2026Updated Jul 27, 2026View HOL analysis
  20. CVE-2025-5244Unknown severity
    GNU Binutils ld elflink.c elf_gc_sweep memory corruption
    Not scoredSource severity not reported
    GNU/Binutils, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +3generic
    PublishedMay 27, 2025First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  21. CVE-2025-5024High
    Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedMay 22, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  22. CVE-2025-34026High
    Versa Concerto Actuator Authentication Bypass Information Leak
    Not scored Known exploited
    Versa/Concertogeneric
    PublishedMay 21, 2025First seen at HOL May 24, 2026Updated Feb 12, 2026View HOL analysis
  23. CVE-2025-4008High
    Arbitrary Command Injection in Smartbedded MeteoBridge
    Not scored Known exploited
    Smartbedded/MeteoBridgegeneric
    PublishedMay 21, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  24. CVE-2025-4969Medium
    Libsoup: off-by-one out-of-bounds read in find_boundary() in soup-multipart.c
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMay 21, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  25. CVE-2024-57529Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedMay 21, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  26. CVE-2025-37988Unknown severity
    fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2025-37984Unknown severity
    crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2025-37980Medium
    block: fix resource leak in blk_register_queue() error path
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  29. CVE-2025-37979Unknown severity
    ASoC: qcom: Fix sc7280 lpass potential buffer overflow
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-37977Unknown severity
    scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2025-37973Unknown severity
    wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2025-37972Medium
    Input: mtk-pmic-keys - fix possible null pointer dereference
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  33. CVE-2025-37964Medium
    x86/mm: Eliminate window where TLB flushes may be inadvertently skipped
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2025-37959Medium
    bpf: Scrub packet on bpf_redirect_peer
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2025-37957Unknown severity
    KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2025-37956Unknown severity
    ksmbd: prevent rename with empty string
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-37954Unknown severity
    smb: client: Avoid race in open_cached_dir with lease breaks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-37952Unknown severity
    ksmbd: Fix UAF in __close_file_table_ids
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-37949Unknown severity
    xenbus: Use kref to track req lifetime
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-37947Unknown severity
    ksmbd: prevent out-of-bounds stream writes by validating *pos
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-37945Medium
    net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2025-37944Unknown severity
    wifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2025-37943Unknown severity
    wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-37938Unknown severity
    tracing: Verify event formats that have "%*p.."
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2025-37936Unknown severity
    perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value.
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2025-37935Unknown severity
    net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2025-37931Unknown severity
    btrfs: adjust subpage bit start based on sectorsize
    Not scoredSource severity not reported
    Linux/Linux, Siemens/SIMATIC CN 4100generic
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-37926Unknown severity
    ksmbd: fix use-after-free in ksmbd_session_rpc_open
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2025-37924Unknown severity
    ksmbd: fix use-after-free in kerberos authentication
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-37923Unknown severity
    tracing: Fix oob write in trace_seq_to_buffer()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 299 of 407
Previous297298299300301Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard