HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 10:09 AM 38,771 active 1,498 known exploited

Catalog summary

38,771

Active CVEs

19,706

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,451–1,500 of 38,771 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-61670Medium
    microsandbox: Secret values exposed in world-readable process arguments
    CVSS 6.5
    microsandbox, superradcompany/microsandboxcrates.io · generic · rust
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  2. CVE-2026-68928Unknown severity
    Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode
    Not scoredSource severity not reported
    Acode-Foundation/Acodegeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  3. CVE-2026-85271Medium
    Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thread Title (incomplete patch of CVE-2026-42857)
    CVSS 6.1
    openedx/openedx-platformgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  4. CVE-2026-93894Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Varnish-Software/Varnish Cache, Vinyl-Cache/Vinyl Cachegeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  5. CVE-2026-85272Unknown severity
    Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validation
    Not scoredSource severity not reported
    openedx/openedx-platformgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  6. CVE-2026-71855Unknown severity
    Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state
    Not scoredSource severity not reported
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  7. CVE-2026-71418Unknown severity
    Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption
    Not scoredSource severity not reported
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  8. CVE-2026-57223High
    Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation
    CVSS 7.0
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  9. CVE-2026-63446Unknown severity
    Suricata app-layer: passed flows can retain transactions, causing resource exhaustion
    Not scoredSource severity not reported
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  10. CVE-2026-63447Unknown severity
    Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption
    Not scoredSource severity not reported
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  11. CVE-2026-63448Medium
    Suricata smb: some SMB flows can cause resource exhaustion
    CVSS 5.9
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  12. CVE-2026-57229Medium
    Suricata smtp/mime: incomplete state reset allows detection bypass
    CVSS 5.3
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  13. CVE-2026-57225Low
    Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading
    CVSS 3.3
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  14. CVE-2026-63452Unknown severity
    Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption
    Not scoredSource severity not reported
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  15. CVE-2026-63451Unknown severity
    Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule load
    Not scoredSource severity not reported
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  16. CVE-2026-57227High
    Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages
    CVSS 7.5
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  17. CVE-2026-63450Low
    Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection
    CVSS 3.7
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  18. CVE-2026-93562Medium
    Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  19. CVE-2026-93574Medium
    Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in chunk-size parsing
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  20. CVE-2026-63449Unknown severity
    Suricata sip: large SIP message bodies can evade detection with frame keyword
    Not scoredSource severity not reported
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  21. CVE-2026-57228High
    Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder
    CVSS 8.2
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  22. CVE-2026-57224Medium
    Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustion
    CVSS 6.5
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  23. CVE-2026-57226Low
    Suricata swf: heap buffer overflow in SWF decompression depth handling
    CVSS 3.7
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  24. CVE-2026-57222Medium
    Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6
    CVSS 5.3
    OISF/suricatageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  25. CVE-2026-61720Medium
    FluidSynth: SF2 DMOD Chunk Unsigned Underflow
    CVSS 6.2
    FluidSynth/fluidsynthgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  26. CVE-2026-61723Medium
    FluidSynth: DLS ptbl Chunk Integer Overflow
    CVSS 6.8
    FluidSynth/fluidsynthgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  27. CVE-2026-61722Medium
    FluidSynth: DLS Articulation Chunk Integer Overflow
    CVSS 6.8
    FluidSynth/fluidsynthgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  28. CVE-2026-61714High
    FluidSynth: Heap Buffer Overflow in MIDI Player
    CVSS 7.8
    FluidSynth/fluidsynthgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  29. CVE-2026-61721High
    FluidSynth: Heap-based buffer overrun for DLS samples
    CVSS 8.0
    FluidSynth/fluidsynthgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  30. CVE-2026-58264Critical
    FluidSynth: Heap-based buffer overrun
    CVSS 9.8
    FluidSynth/fluidsynthgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  31. CVE-2026-76899Unknown severity
    CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`
    Not scoredSource severity not reported
    1Panel-dev/CordysCRMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  32. CVE-2026-76902Unknown severity
    CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`
    Not scoredSource severity not reported
    1Panel-dev/CordysCRMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  33. CVE-2026-76900Medium
    CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime
    CVSS 6.8
    1Panel-dev/CordysCRMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  34. CVE-2026-93873Unknown severity
    Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin
    Not scoredSource severity not reported
    Cotonti/Cotontigeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  35. CVE-2026-93872Unknown severity
    Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter
    Not scoredSource severity not reported
    Cotonti/Cotontigeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  36. CVE-2026-93871Unknown severity
    Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix
    Not scoredSource severity not reported
    Cotonti/Cotontigeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  37. CVE-2026-93870Medium
    Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler
    CVSS 5.3
    Cotonti/Cotontigeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  38. CVE-2026-93869Unknown severity
    Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex
    Not scoredSource severity not reported
    Cotonti/Cotontigeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  39. CVE-2026-93868Unknown severity
    Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG
    Not scoredSource severity not reported
    Cotonti/Cotontigeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  40. CVE-2026-76901Unknown severity
    CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts
    Not scoredSource severity not reported
    1Panel-dev/CordysCRMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  41. CVE-2026-84239Unknown severity
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Not scoredSource severity not reported
    IBM/Guardium Data Protectiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  42. CVE-2026-92708High
    devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Buffers
    CVSS 7.5
    sveltejs/devaluegeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  43. CVE-2026-63647Unknown severity
    CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`
    Not scoredSource severity not reported
    1Panel-dev/CordysCRMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  44. CVE-2026-84241High
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    CVSS 8.1
    IBM/Guardium Data Protectiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 23, 2026View HOL analysis
  45. CVE-2026-84108Unknown severity
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Not scoredSource severity not reported
    IBM/Guardium Data Protectiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  46. CVE-2026-84106Unknown severity
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Not scoredSource severity not reported
    IBM/Guardium Data Protectiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  47. CVE-2026-84105Unknown severity
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    Not scoredSource severity not reported
    IBM/Guardium Data Protectiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  48. CVE-2026-63646Unknown severity
    CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users
    Not scoredSource severity not reported
    1Panel-dev/CordysCRMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  49. CVE-2026-84089High
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    CVSS 7.8
    IBM/Guardium Data Protectiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 23, 2026View HOL analysis
  50. CVE-2026-84086High
    IBM Guardium Data Protection is affected by multiple vulnerabilities.
    CVSS 7.2
    IBM/Guardium Data Protectiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 23, 2026View HOL analysis
Page 30 of 776
Previous2829303132Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard