1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 8:23 PM 20,348 active 1,448 known exploited

Catalog summary

20,348

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 8:23 PM 20,348 active 1,448 known exploited

Catalog summary

20,348

Active CVEs

10,175

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 14,951–15,000 of 20,348 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-37921Unknown severity
    vxlan: vnifilter: Fix unlocked deletion of default FDB entry
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-37920Unknown severity
    xsk: Fix race condition in AF_XDP generic RX path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2025-37918Unknown severity
    Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2025-37917Medium
    net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2025-37915Unknown severity
    net_sched: drr: Fix double list add in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2025-37914Unknown severity
    net_sched: ets: Fix double list add in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-37913Unknown severity
    net_sched: qfq: Fix double list add in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-37911Unknown severity
    bnxt_en: Fix out-of-bound memcpy() during ethtool -w
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-37909Medium
    net: lan743x: Fix memleak issue when GSO enabled
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2025-37908Unknown severity
    mm, slab: clean up slab->obj_exts always
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2025-37906Unknown severity
    ublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-37903Unknown severity
    drm/amd/display: Fix slab-use-after-free in hdcp
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-37901Unknown severity
    irqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-37899Unknown severity
    ksmbd: fix use-after-free in session logoff
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-37894Unknown severity
    net: use sock_gen_put() when sk_state is TCP_TIME_WAIT
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2025-4945Low
    Libsoup: integer overflow in cookie expiration date handling in libsoup
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedMay 19, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  17. CVE-2025-4948High
    Libsoup: integer underflow in soup_multipart_new_from_message() leading to denial of service in libsoup
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMay 19, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  18. CVE-2025-37891Unknown severity
    ALSA: ump: Fix buffer overflow at UMP SysEx message conversion
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 19, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2025-4805Medium
    WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal Configuration
    CVSS 4.8
    WatchGuard/Fireware OSgeneric
    PublishedMay 16, 2025First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  20. CVE-2025-4804Medium
    WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Hotpot Configuration
    CVSS 4.8
    WatchGuard/Fireware OSgeneric
    PublishedMay 16, 2025First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  21. CVE-2025-4476Medium
    Libsoup: null pointer dereference in libsoup may lead to denial of service
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedMay 16, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  22. CVE-2025-4478Medium
    Gnome-remote-desktop: freerdp: unauthenticated rdp packet causes segfault in freerdp leading to denial of service
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMay 16, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2025-37890Unknown severity
    net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 16, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2025-46836Unknown severity
    net-tools Stack-based Buffer Overflow vulnerability
    Not scoredSource severity not reported
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +13generic
    PublishedMay 14, 2025First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2024-57273Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 14, 2025First seen at HOL Jul 5, 2026Updated Jul 27, 2026View HOL analysis
  26. CVE-2025-25370Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    n/a/n/ageneric
    PublishedMay 14, 2025First seen at HOL Jul 5, 2026Updated Jul 27, 2026View HOL analysis
  27. CVE-2025-4574Medium
    Crossbeam-channel: crossbeam-channel vulnerable to double free on drop
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMay 13, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  28. CVE-2024-28956Medium
    CVE Program Container
    CVSS 5.6
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMay 13, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  29. CVE-2025-4428High
    Remote Code Execution
    Not scored Known exploited
    Affected software not mappedEcosystem not listed
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  30. CVE-2025-4427High
    Authentication Bypass
    Not scored Known exploited
    Affected software not mappedEcosystem not listed
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  31. CVE-2025-32756High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiCamera, Fortinet/FortiMail +3generic
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  32. CVE-2025-4632High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Samsung Electronics/MagicINFO 9 Servergeneric
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  33. CVE-2025-42999High
    Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
    CVSS 9.1 Known exploited
    SAP_SE/SAP NetWeaver (Visual Composer development server)generic
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Aug 11, 2026View HOL analysis
  34. CVE-2025-31223High
    CISA ADP Vulnrichment
    CVSS 8.0
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedMay 12, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  35. CVE-2025-4432Medium
    Ring: some aes functions may panic when overflow checking is enabled in ring
    CVSS 5.3
    github.com/briansmith/ringgo
    PublishedMay 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2025-4382Medium
    Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedMay 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2025-37887Unknown severity
    pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-37886Unknown severity
    pds_core: make wait_context part of q_info
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-37885Unknown severity
    KVM: x86: Reset IRTE to host control if *new* route isn't postable
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-37882Unknown severity
    usb: xhci: Fix isochronous Ring Underrun/Overrun event handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-37879Unknown severity
    9p/net: fix improper handling of bogus negative read/write replies
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-37876Unknown severity
    netfs: Only create /proc/fs/netfs with CONFIG_PROC_FS
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2025-37873Unknown severity
    eth: bnxt: fix missing ring index trim on error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-37871Unknown severity
    nfsd: decrease sc_count directly if fail to queue dl_recall
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2025-37869Unknown severity
    drm/xe: Use local fence in error path of xe_migrate_clear
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2025-37861Unknown severity
    scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2025-37856Unknown severity
    btrfs: harden block_group::bg_list against list_del() races
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-37854Unknown severity
    drm/amdkfd: Fix mode1 reset crash issue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2025-37849Unknown severity
    KVM: arm64: Tear down vGIC on failed vCPU creation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-37845Unknown severity
    tracing: fprobe events: Fix possible UAF on modules
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 300 of 407
Previous298299300301302Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,175

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 14,951–15,000 of 20,348 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-37921Unknown severity
    vxlan: vnifilter: Fix unlocked deletion of default FDB entry
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-37920Unknown severity
    xsk: Fix race condition in AF_XDP generic RX path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2025-37918Unknown severity
    Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2025-37917Medium
    net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2025-37915Unknown severity
    net_sched: drr: Fix double list add in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2025-37914Unknown severity
    net_sched: ets: Fix double list add in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-37913Unknown severity
    net_sched: qfq: Fix double list add in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-37911Unknown severity
    bnxt_en: Fix out-of-bound memcpy() during ethtool -w
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-37909Medium
    net: lan743x: Fix memleak issue when GSO enabled
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedMay 20, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  10. CVE-2025-37908Unknown severity
    mm, slab: clean up slab->obj_exts always
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2025-37906Unknown severity
    ublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2025-37903Unknown severity
    drm/amd/display: Fix slab-use-after-free in hdcp
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-37901Unknown severity
    irqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-37899Unknown severity
    ksmbd: fix use-after-free in session logoff
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-37894Unknown severity
    net: use sock_gen_put() when sk_state is TCP_TIME_WAIT
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 20, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2025-4945Low
    Libsoup: integer overflow in cookie expiration date handling in libsoup
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedMay 19, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  17. CVE-2025-4948High
    Libsoup: integer underflow in soup_multipart_new_from_message() leading to denial of service in libsoup
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedMay 19, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  18. CVE-2025-37891Unknown severity
    ALSA: ump: Fix buffer overflow at UMP SysEx message conversion
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 19, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2025-4805Medium
    WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal Configuration
    CVSS 4.8
    WatchGuard/Fireware OSgeneric
    PublishedMay 16, 2025First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  20. CVE-2025-4804Medium
    WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Hotpot Configuration
    CVSS 4.8
    WatchGuard/Fireware OSgeneric
    PublishedMay 16, 2025First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  21. CVE-2025-4476Medium
    Libsoup: null pointer dereference in libsoup may lead to denial of service
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedMay 16, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  22. CVE-2025-4478Medium
    Gnome-remote-desktop: freerdp: unauthenticated rdp packet causes segfault in freerdp leading to denial of service
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMay 16, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2025-37890Unknown severity
    net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 16, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2025-46836Unknown severity
    net-tools Stack-based Buffer Overflow vulnerability
    Not scoredSource severity not reported
    Siemens/RUGGEDCOM ROX MX5000, Siemens/RUGGEDCOM ROX MX5000RE +13generic
    PublishedMay 14, 2025First seen at HOL Aug 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2024-57273Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedMay 14, 2025First seen at HOL Jul 5, 2026Updated Jul 27, 2026View HOL analysis
  26. CVE-2025-25370Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    n/a/n/ageneric
    PublishedMay 14, 2025First seen at HOL Jul 5, 2026Updated Jul 27, 2026View HOL analysis
  27. CVE-2025-4574Medium
    Crossbeam-channel: crossbeam-channel vulnerable to double free on drop
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedMay 13, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  28. CVE-2024-28956Medium
    CVE Program Container
    CVSS 5.6
    Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP +2generic
    PublishedMay 13, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  29. CVE-2025-4428High
    Remote Code Execution
    Not scored Known exploited
    Affected software not mappedEcosystem not listed
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  30. CVE-2025-4427High
    Authentication Bypass
    Not scored Known exploited
    Affected software not mappedEcosystem not listed
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  31. CVE-2025-32756High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Fortinet/FortiCamera, Fortinet/FortiMail +3generic
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  32. CVE-2025-4632High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Samsung Electronics/MagicINFO 9 Servergeneric
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  33. CVE-2025-42999High
    Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
    CVSS 9.1 Known exploited
    SAP_SE/SAP NetWeaver (Visual Composer development server)generic
    PublishedMay 13, 2025First seen at HOL May 24, 2026Updated Aug 11, 2026View HOL analysis
  34. CVE-2025-31223High
    CISA ADP Vulnrichment
    CVSS 8.0
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedMay 12, 2025First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  35. CVE-2025-4432Medium
    Ring: some aes functions may panic when overflow checking is enabled in ring
    CVSS 5.3
    github.com/briansmith/ringgo
    PublishedMay 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2025-4382Medium
    Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedMay 9, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2025-37887Unknown severity
    pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-37886Unknown severity
    pds_core: make wait_context part of q_info
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-37885Unknown severity
    KVM: x86: Reset IRTE to host control if *new* route isn't postable
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-37882Unknown severity
    usb: xhci: Fix isochronous Ring Underrun/Overrun event handling
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-37879Unknown severity
    9p/net: fix improper handling of bogus negative read/write replies
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-37876Unknown severity
    netfs: Only create /proc/fs/netfs with CONFIG_PROC_FS
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2025-37873Unknown severity
    eth: bnxt: fix missing ring index trim on error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2025-37871Unknown severity
    nfsd: decrease sc_count directly if fail to queue dl_recall
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2025-37869Unknown severity
    drm/xe: Use local fence in error path of xe_migrate_clear
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2025-37861Unknown severity
    scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2025-37856Unknown severity
    btrfs: harden block_group::bg_list against list_del() races
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-37854Unknown severity
    drm/amdkfd: Fix mode1 reset crash issue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2025-37849Unknown severity
    KVM: arm64: Tear down vGIC on failed vCPU creation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2025-37845Unknown severity
    tracing: fprobe events: Fix possible UAF on modules
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 9, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 300 of 407
Previous298299300301302Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard