1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:43 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:43 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

8,421

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,451–1,500 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59912High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/Display and Peripheral Manager (DDPM Mac)generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-15631Medium
    Weak Credential Storage in TP-Link Omada Devices
    CVSS 5.7
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2025-15630Medium
    Device Provisioning Race Condition in TP-Link Omada Adoption Workflow
    CVSS 5.8
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2025-15629Medium
    Weak Session Key Generation in TP-Link Omada Adoption Protocol
    CVSS 6.9
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2025-15628High
    Hardcoded Certificates in TP-Link Omada Device Communications
    CVSS 8.2
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +3generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2025-15627Medium
    Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication
    CVSS 6.9
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2025-15544Medium
    Weak Credential Protection During TP-Link Omada Device Adoption
    CVSS 6.9
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada App +4generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2025-9291High
    Improper Certificate Validation in TP-Link Omada Cloud Communications
    CVSS 7.7
    TP-Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  9. CVE-2026-18613Critical
    GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
    CVSS 9.8
    GL-iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  10. CVE-2026-40717Medium
    CISA ADP Vulnrichment
    CVSS 6.6
    Dell/Monitor drivergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-18612Critical
    GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection
    CVSS 9.8
    GL-iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  12. CVE-2026-18610Medium
    NewType WebEIP EIP_Com_FileList.aspx improper authentication
    CVSS 5.3
    NewType/WebEIPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  13. CVE-2026-18718High
    Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
    CVSS 7.0
    National Security Agency/Ghidrageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  14. CVE-2026-18607High
    Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow
    CVSS 8.8
    Wavlink/NU516, Wavlink/WN529 +10generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  15. CVE-2026-18606High
    Razer RzUpdateService Named Pipe RzUpdateService.exe privileges management
    CVSS 7.8
    Razer/RzUpdateServicegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  16. CVE-2026-18605High
    CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path
    CVSS 7.0
    CheckMAL/AppCheck Progeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  17. CVE-2026-39932Critical
    OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
    CVSS 9.1
    openemr/openemrgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  18. CVE-2026-18243Medium
    HP DesignJet T3500 - Potential Cross-Site Scripting (XSS)
    CVSS 6.9
    HP Inc/HP DesignJet T3500generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  19. CVE-2026-39931High
    OpenEMR Authenticated SQL Injection via backup.php Import Feature
    CVSS 7.2
    openemr/openemrgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  20. CVE-2026-41453High
    Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter
    CVSS 8.8
    krayin/laravel-crmgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-18604Medium
    textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
    CVSS 5.3
    textPlus/Text Message and Call Appgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  22. CVE-2026-41452Critical
    Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup
    CVSS 9.8
    krayin/laravel-crmgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  23. CVE-2026-18477Medium
    Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-18602Critical
    GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection
    CVSS 9.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  25. CVE-2026-18248Critical
    @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header
    CVSS 9.1
    @fastify/aws-lambda/@fastify/aws-lambdageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  26. CVE-2026-18651Medium
    389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2026-18508Medium
    Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-15430Medium
    CVE-2026-15430
    CVSS 6.2
    Wellbia/XIGNCODE3generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-18568High
    XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check
    CVSS 7.5
    TIMLEGGE/XML::Siggeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-18642High
    Remote Code Execution via Insecure Deserialization in TÜBİTAK BİLGEM's eta-otp-lock
    CVSS 7.8
    TUBITAK BILGEM Software Technologies Research Institute/eta-otp-lockgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  31. CVE-2026-64827Critical
    Telenia TVox 26.5.3 Authentication Bypass via set_env.php
    CVSS 9.8
    Telenia Software/TVoxgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  32. CVE-2026-18092High
    Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree
    CVSS 8.1
    TIMLEGGE/Net::SAML2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-69097High
    GitPython before 3.1.53 Config Injection via Submodule Names
    CVSS 7.0
    gitpython-developers/GitPythongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-69096High
    OpenWrt luci-app-dockerman Read ACL Remote Code Execution
    CVSS 8.8
    openwrt/lucigeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-18601Critical
    GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection
    CVSS 9.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  36. CVE-2026-18108Critical
    Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature
    CVSS 9.8
    TIMLEGGE/Net::SAML2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-18600High
    GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection
    CVSS 8.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-18089High
    Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured
    CVSS 7.5
    TIMLEGGE/Net::SAML2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  39. CVE-2026-18574Critical
    Authentication Bypass in Check Point Security Management Server
    CVSS 9.3
    checkpoint/Multi-Domain Security Management Server, checkpoint/Security Management Servergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18599High
    GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
    CVSS 8.0
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-2346Critical
    IDOR in Menulux Software's Mobile App
    CVSS 9.8
    Menulux Software Inc./Mobile Appgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  42. CVE-2026-18598High
    GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection
    CVSS 8.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  43. CVE-2026-0392High
    eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update
    CVSS 7.3
    Latvijas Valsts radio un televīzijas centrs (LVRTC)/eParakstītājs 3.0generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-33591Critical
    Authentication bypass on WaptServer
    CVSS 10.0
    Tranquil IT Systems/WAPT Servergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  45. CVE-2026-18593Medium
    vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox
    CVSS 5.6
    vxcontrol/PentAGIgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  46. CVE-2026-18592Medium
    osCommerce Email Template Configuration EmailController.php EmailController sql injection
    CVSS 4.7
    n/a/osCommercegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  47. CVE-2026-21555High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./UDX710generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  48. CVE-2026-21554High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./UDX710generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  49. CVE-2026-21553High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  50. CVE-2026-21552High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
Page 30 of 326
Previous2829303132Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,421

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,451–1,500 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59912High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/Display and Peripheral Manager (DDPM Mac)generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-15631Medium
    Weak Credential Storage in TP-Link Omada Devices
    CVSS 5.7
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2025-15630Medium
    Device Provisioning Race Condition in TP-Link Omada Adoption Workflow
    CVSS 5.8
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2025-15629Medium
    Weak Session Key Generation in TP-Link Omada Adoption Protocol
    CVSS 6.9
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2025-15628High
    Hardcoded Certificates in TP-Link Omada Device Communications
    CVSS 8.2
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +3generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2025-15627Medium
    Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication
    CVSS 6.9
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2025-15544Medium
    Weak Credential Protection During TP-Link Omada Device Adoption
    CVSS 6.9
    TP Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada App +4generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2025-9291High
    Improper Certificate Validation in TP-Link Omada Cloud Communications
    CVSS 7.7
    TP-Link Systems Inc./Omada Access Points, TP-Link Systems Inc./Omada Gateways +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  9. CVE-2026-18613Critical
    GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
    CVSS 9.8
    GL-iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  10. CVE-2026-40717Medium
    CISA ADP Vulnrichment
    CVSS 6.6
    Dell/Monitor drivergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-18612Critical
    GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection
    CVSS 9.8
    GL-iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  12. CVE-2026-18610Medium
    NewType WebEIP EIP_Com_FileList.aspx improper authentication
    CVSS 5.3
    NewType/WebEIPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  13. CVE-2026-18718High
    Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
    CVSS 7.0
    National Security Agency/Ghidrageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  14. CVE-2026-18607High
    Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow
    CVSS 8.8
    Wavlink/NU516, Wavlink/WN529 +10generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  15. CVE-2026-18606High
    Razer RzUpdateService Named Pipe RzUpdateService.exe privileges management
    CVSS 7.8
    Razer/RzUpdateServicegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  16. CVE-2026-18605High
    CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path
    CVSS 7.0
    CheckMAL/AppCheck Progeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  17. CVE-2026-39932Critical
    OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
    CVSS 9.1
    openemr/openemrgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  18. CVE-2026-18243Medium
    HP DesignJet T3500 - Potential Cross-Site Scripting (XSS)
    CVSS 6.9
    HP Inc/HP DesignJet T3500generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  19. CVE-2026-39931High
    OpenEMR Authenticated SQL Injection via backup.php Import Feature
    CVSS 7.2
    openemr/openemrgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  20. CVE-2026-41453High
    Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter
    CVSS 8.8
    krayin/laravel-crmgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-18604Medium
    textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
    CVSS 5.3
    textPlus/Text Message and Call Appgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  22. CVE-2026-41452Critical
    Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup
    CVSS 9.8
    krayin/laravel-crmgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  23. CVE-2026-18477Medium
    Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-18602Critical
    GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection
    CVSS 9.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  25. CVE-2026-18248Critical
    @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header
    CVSS 9.1
    @fastify/aws-lambda/@fastify/aws-lambdageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  26. CVE-2026-18651Medium
    389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2026-18508Medium
    Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-15430Medium
    CVE-2026-15430
    CVSS 6.2
    Wellbia/XIGNCODE3generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-18568High
    XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check
    CVSS 7.5
    TIMLEGGE/XML::Siggeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-18642High
    Remote Code Execution via Insecure Deserialization in TÜBİTAK BİLGEM's eta-otp-lock
    CVSS 7.8
    TUBITAK BILGEM Software Technologies Research Institute/eta-otp-lockgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  31. CVE-2026-64827Critical
    Telenia TVox 26.5.3 Authentication Bypass via set_env.php
    CVSS 9.8
    Telenia Software/TVoxgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  32. CVE-2026-18092High
    Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree
    CVSS 8.1
    TIMLEGGE/Net::SAML2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-69097High
    GitPython before 3.1.53 Config Injection via Submodule Names
    CVSS 7.0
    gitpython-developers/GitPythongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-69096High
    OpenWrt luci-app-dockerman Read ACL Remote Code Execution
    CVSS 8.8
    openwrt/lucigeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-18601Critical
    GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection
    CVSS 9.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  36. CVE-2026-18108Critical
    Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature
    CVSS 9.8
    TIMLEGGE/Net::SAML2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-18600High
    GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection
    CVSS 8.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-18089High
    Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured
    CVSS 7.5
    TIMLEGGE/Net::SAML2generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  39. CVE-2026-18574Critical
    Authentication Bypass in Check Point Security Management Server
    CVSS 9.3
    checkpoint/Multi-Domain Security Management Server, checkpoint/Security Management Servergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18599High
    GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
    CVSS 8.0
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-2346Critical
    IDOR in Menulux Software's Mobile App
    CVSS 9.8
    Menulux Software Inc./Mobile Appgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  42. CVE-2026-18598High
    GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection
    CVSS 8.8
    GL.iNet/GL-MT3000generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  43. CVE-2026-0392High
    eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update
    CVSS 7.3
    Latvijas Valsts radio un televīzijas centrs (LVRTC)/eParakstītājs 3.0generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-33591Critical
    Authentication bypass on WaptServer
    CVSS 10.0
    Tranquil IT Systems/WAPT Servergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  45. CVE-2026-18593Medium
    vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox
    CVSS 5.6
    vxcontrol/PentAGIgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  46. CVE-2026-18592Medium
    osCommerce Email Template Configuration EmailController.php EmailController sql injection
    CVSS 4.7
    n/a/osCommercegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  47. CVE-2026-21555High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./UDX710generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  48. CVE-2026-21554High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./UDX710generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  49. CVE-2026-21553High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  50. CVE-2026-21552High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
Page 30 of 326
Previous2829303132Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard