1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 10:15 PM 20,349 active 1,448 known exploited

Catalog summary

20,349

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 16, 2026, 10:15 PM 20,349 active 1,448 known exploited

Catalog summary

20,349

Active CVEs

10,181

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 15,101–15,150 of 20,349 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-37741Unknown severity
    jfs: Prevent copying of nlink with value 0 from disk inode
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-37738Unknown severity
    ext4: ignore xattrs past end
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2025-23159Unknown severity
    media: venus: hfi: add a check to handle OOB in sfr region
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2025-23158Unknown severity
    media: venus: hfi: add check to handle incorrect queue size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2025-23157Unknown severity
    media: venus: hfi_parser: add check to avoid out of bound access
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2025-23156Unknown severity
    media: venus: hfi_parser: refactor hfi packet parsing logic
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-23155Unknown severity
    net: stmmac: Fix accessing freed irq affinity_hint
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-23151Unknown severity
    bus: mhi: host: Fix race between unprepare and queue_buf
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-23150Unknown severity
    ext4: fix off-by-one error in do_split
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2025-23145Unknown severity
    mptcp: fix NULL pointer in can_accept_new_subflow
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2025-23143Medium
    net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod.
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC CN 4100 +3generic
    PublishedMay 1, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  12. CVE-2025-23142Unknown severity
    sctp: detect and prevent references to a freed transport in sendmsg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-23141Unknown severity
    KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-4035Medium
    Libsoup: cookie domain validation bypass via uppercase characters in libsoup
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedApr 29, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  15. CVE-2025-3891High
    Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 29, 2025First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2024-58099Unknown severity
    vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2025-45947Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 28, 2025First seen at HOL Jul 5, 2026Updated Jul 25, 2026View HOL analysis
  18. CVE-2025-45949Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 28, 2025First seen at HOL Jul 5, 2026Updated Jul 25, 2026View HOL analysis
  19. CVE-2025-45953Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedApr 28, 2025First seen at HOL Jul 5, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2025-3935High
    ScreenConnect Exposure to ASP.NET ViewState Code Injection
    Not scored Known exploited
    ConnectWise/ScreenConnectgeneric
    PublishedApr 25, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  21. CVE-2025-3928High
    Commvault Web Server unspecified vulnerability
    Not scored Known exploited
    Commvault/Web Servergeneric
    PublishedApr 25, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  22. CVE-2025-32432High
    Craft CMS Allows Remote Code Execution
    Not scored Known exploited
    craftcms/cmsgeneric
    PublishedApr 25, 2025First seen at HOL May 24, 2026Updated Apr 3, 2026View HOL analysis
  23. CVE-2025-31324Critical
    Missing Authorization check in SAP NetWeaver (Visual Composer development server)
    CVSS 10.0 Known exploited
    SAP_SE/SAP NetWeaver (Visual Composer development server)generic
    PublishedApr 24, 2025First seen at HOL May 24, 2026Updated Aug 4, 2026View HOL analysis
  24. CVE-2025-46421Medium
    Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedApr 24, 2025First seen at HOL Jun 25, 2026Updated Jul 25, 2026View HOL analysis
  25. CVE-2025-46420Medium
    Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedApr 24, 2025First seen at HOL Jun 25, 2026Updated Jul 25, 2026View HOL analysis
  26. CVE-2025-1976High
    Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6
    Not scored Known exploited
    Brocade/Fabric OSgeneric
    PublishedApr 24, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  27. CVE-2025-46400Medium
    Xfig: fig2dev segmentation fault in read_arcobject
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  28. CVE-2025-46399Medium
    Xfig: transfig: fig2dev segmentation fault vulnerability
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  29. CVE-2025-46398Medium
    Xfig: fig2dev stack-overflow via read_objects
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  30. CVE-2025-46397High
    Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2024-47829Medium
    pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
    CVSS 6.5
    pnpm/pnpmgeneric
    PublishedApr 23, 2025First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2024-10306Medium
    Mod_proxy_cluster: mod_proxy_cluster unauthorized mcmp requests
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  33. CVE-2025-34028High
    Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
    Not scored Known exploited
    Commvault/Command Center Innovation Releasegeneric
    PublishedApr 22, 2025First seen at HOL May 24, 2026Updated Nov 29, 2025View HOL analysis
  34. CVE-2024-41446Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 21, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2025-29287Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 21, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  36. CVE-2025-37838Unknown severity
    HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-39930Unknown severity
    ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-39735Unknown severity
    jfs: fix slab-out-of-bounds read in ea_get()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-39688Unknown severity
    nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-37893Unknown severity
    LoongArch: BPF: Fix off-by-one error in build_prologue()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-37785High
    ext4: fix OOB read when checking dotdot dir
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 18, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-42599High
    CISA ADP Vulnrichment
    Not scored Known exploited
    QUALITIA CO., LTD./Active! mail 6generic
    PublishedApr 18, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  43. CVE-2025-29512Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 18, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2025-29513Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 18, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  45. CVE-2021-47670High
    can: peak_usb: fix use after free bugs
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 17, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2021-47669Unknown severity
    can: vxcan: vxcan_xmit: fix use after free bug
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 17, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2021-47668High
    can: dev: can_restart: fix use after free bug
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 17, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-32433High
    Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
    Not scored Known exploited
    erlang/otpgeneric
    PublishedApr 16, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  49. CVE-2025-31200High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedApr 16, 2025First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  50. CVE-2025-31201High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/macOS +2generic
    PublishedApr 16, 2025First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
Page 303 of 407
Previous301302303304305Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

10,181

Critical + high

1,448

Known exploited

14

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 15,101–15,150 of 20,349 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-37741Unknown severity
    jfs: Prevent copying of nlink with value 0 from disk inode
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2025-37738Unknown severity
    ext4: ignore xattrs past end
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2025-23159Unknown severity
    media: venus: hfi: add a check to handle OOB in sfr region
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2025-23158Unknown severity
    media: venus: hfi: add check to handle incorrect queue size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2025-23157Unknown severity
    media: venus: hfi_parser: add check to avoid out of bound access
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2025-23156Unknown severity
    media: venus: hfi_parser: refactor hfi packet parsing logic
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2025-23155Unknown severity
    net: stmmac: Fix accessing freed irq affinity_hint
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2025-23151Unknown severity
    bus: mhi: host: Fix race between unprepare and queue_buf
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2025-23150Unknown severity
    ext4: fix off-by-one error in do_split
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2025-23145Unknown severity
    mptcp: fix NULL pointer in can_accept_new_subflow
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2025-23143Medium
    net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod.
    CVSS 5.5
    Linux/Linux, Siemens/SIMATIC CN 4100 +3generic
    PublishedMay 1, 2025First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  12. CVE-2025-23142Unknown severity
    sctp: detect and prevent references to a freed transport in sendmsg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-23141Unknown severity
    KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedMay 1, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-4035Medium
    Libsoup: cookie domain validation bypass via uppercase characters in libsoup
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedApr 29, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  15. CVE-2025-3891High
    Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedApr 29, 2025First seen at HOL Jun 25, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2024-58099Unknown severity
    vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 29, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2025-45947Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 28, 2025First seen at HOL Jul 5, 2026Updated Jul 25, 2026View HOL analysis
  18. CVE-2025-45949Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 28, 2025First seen at HOL Jul 5, 2026Updated Jul 25, 2026View HOL analysis
  19. CVE-2025-45953Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedApr 28, 2025First seen at HOL Jul 5, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2025-3935High
    ScreenConnect Exposure to ASP.NET ViewState Code Injection
    Not scored Known exploited
    ConnectWise/ScreenConnectgeneric
    PublishedApr 25, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  21. CVE-2025-3928High
    Commvault Web Server unspecified vulnerability
    Not scored Known exploited
    Commvault/Web Servergeneric
    PublishedApr 25, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026 Fix availableView HOL analysis
  22. CVE-2025-32432High
    Craft CMS Allows Remote Code Execution
    Not scored Known exploited
    craftcms/cmsgeneric
    PublishedApr 25, 2025First seen at HOL May 24, 2026Updated Apr 3, 2026View HOL analysis
  23. CVE-2025-31324Critical
    Missing Authorization check in SAP NetWeaver (Visual Composer development server)
    CVSS 10.0 Known exploited
    SAP_SE/SAP NetWeaver (Visual Composer development server)generic
    PublishedApr 24, 2025First seen at HOL May 24, 2026Updated Aug 4, 2026View HOL analysis
  24. CVE-2025-46421Medium
    Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedApr 24, 2025First seen at HOL Jun 25, 2026Updated Jul 25, 2026View HOL analysis
  25. CVE-2025-46420Medium
    Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedApr 24, 2025First seen at HOL Jun 25, 2026Updated Jul 25, 2026View HOL analysis
  26. CVE-2025-1976High
    Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6
    Not scored Known exploited
    Brocade/Fabric OSgeneric
    PublishedApr 24, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  27. CVE-2025-46400Medium
    Xfig: fig2dev segmentation fault in read_arcobject
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  28. CVE-2025-46399Medium
    Xfig: transfig: fig2dev segmentation fault vulnerability
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  29. CVE-2025-46398Medium
    Xfig: fig2dev stack-overflow via read_objects
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  30. CVE-2025-46397High
    Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2024-47829Medium
    pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
    CVSS 6.5
    pnpm/pnpmgeneric
    PublishedApr 23, 2025First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2024-10306Medium
    Mod_proxy_cluster: mod_proxy_cluster unauthorized mcmp requests
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedApr 23, 2025First seen at HOL Jun 25, 2026Updated Jun 30, 2026View HOL analysis
  33. CVE-2025-34028High
    Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
    Not scored Known exploited
    Commvault/Command Center Innovation Releasegeneric
    PublishedApr 22, 2025First seen at HOL May 24, 2026Updated Nov 29, 2025View HOL analysis
  34. CVE-2024-41446Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedApr 21, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  35. CVE-2025-29287Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedApr 21, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  36. CVE-2025-37838Unknown severity
    HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2025-39930Unknown severity
    ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2025-39735Unknown severity
    jfs: fix slab-out-of-bounds read in ea_get()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2025-39688Unknown severity
    nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2025-37893Unknown severity
    LoongArch: BPF: Fix off-by-one error in build_prologue()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 18, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2025-37785High
    ext4: fix OOB read when checking dotdot dir
    CVSS 7.1
    Linux/Linux, Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP +2generic
    PublishedApr 18, 2025First seen at HOL Jul 14, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2025-42599High
    CISA ADP Vulnrichment
    Not scored Known exploited
    QUALITIA CO., LTD./Active! mail 6generic
    PublishedApr 18, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  43. CVE-2025-29512Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 18, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  44. CVE-2025-29513Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedApr 18, 2025First seen at HOL Jul 5, 2026Updated Jul 5, 2026View HOL analysis
  45. CVE-2021-47670High
    can: peak_usb: fix use after free bugs
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 17, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2021-47669Unknown severity
    can: vxcan: vxcan_xmit: fix use after free bug
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedApr 17, 2025First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2021-47668High
    can: dev: can_restart: fix use after free bug
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedApr 17, 2025First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2025-32433High
    Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
    Not scored Known exploited
    erlang/otpgeneric
    PublishedApr 16, 2025First seen at HOL May 24, 2026Updated Feb 26, 2026View HOL analysis
  49. CVE-2025-31200High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedApr 16, 2025First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
  50. CVE-2025-31201High
    CISA ADP Vulnrichment
    Not scored Known exploited
    Apple/iOS and iPadOS, Apple/macOS +2generic
    PublishedApr 16, 2025First seen at HOL May 24, 2026Updated Apr 2, 2026 Fix availableView HOL analysis
Page 303 of 407
Previous301302303304305Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard