HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 10:49 AM 38,773 active 1,498 known exploited

Catalog summary

38,773

Active CVEs

19,706

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,551–1,600 of 38,773 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-17619Unknown severity
    The IBM Platform RTM is affected by an SQL injection vulnerability
    Not scoredSource severity not reported
    IBM/spectrum-lsf : IBM Platform RTMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  2. CVE-2026-91203Medium
    Cockpit-files: cockpit-files: arbitrary file ownership and permission modification via symlink race condition
    CVSS 6.0
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  3. CVE-2026-17262Medium
    IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]
    CVSS 5.4
    IBM/igeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 23, 2026View HOL analysis
  4. CVE-2026-11727Unknown severity
    IBM MQ for HPE NonStop is vulnerable to a denial of service issue
    Not scoredSource severity not reported
    IBM/MQ for HPE NonStopgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  5. CVE-2026-11726Unknown severity
    IBM MQ for HPE NonStop is vulnerable to a denial of service issue
    Not scoredSource severity not reported
    IBM/MQ for HPE NonStopgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  6. CVE-2026-11725Unknown severity
    IBM MQ queue manager is vulnerable to privilege escalation
    Not scoredSource severity not reported
    IBM/MQgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  7. CVE-2026-91205Medium
    Cockpit-files: cockpit-files: local attacker can hijack file ownership via symlink race
    CVSS 6.0
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  8. CVE-2026-11722Unknown severity
    Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
    Not scoredSource severity not reported
    IBM/CICS TX Advancedgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  9. CVE-2026-11716Unknown severity
    IBM MQ for HPE NonStop is vulnerable to a denial of service attack
    Not scoredSource severity not reported
    IBM/MQ for HPE NonStopgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  10. CVE-2026-11711Unknown severity
    IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
    Not scoredSource severity not reported
    IBM/WebSphere Application Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  11. CVE-2026-11710Unknown severity
    IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability
    Not scoredSource severity not reported
    IBM/WebSphere Application Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  12. CVE-2026-11549Unknown severity
    Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
    Not scoredSource severity not reported
    IBM/CICS TX Advancedgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  13. CVE-2026-93841Unknown severity
    vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs
    Not scoredSource severity not reported
    vllm-project/vllmgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  14. CVE-2026-93840Unknown severity
    vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids
    Not scoredSource severity not reported
    vllm-project/vllmgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  15. CVE-2026-93839Critical
    LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint
    CVSS 9.3
    ModelTC/LightLLMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  16. CVE-2026-93838Unknown severity
    SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx
    Not scoredSource severity not reported
    sgl-project/sglanggeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  17. CVE-2026-11548Unknown severity
    Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
    Not scoredSource severity not reported
    IBM/CICS TX Advancedgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  18. CVE-2026-11545Unknown severity
    IBM WebSphere Application Server is affected by a privilege escalation
    Not scoredSource severity not reported
    IBM/WebSphere Application Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  19. CVE-2026-11540Unknown severity
    IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
    Not scoredSource severity not reported
    IBM/WebSphere Application Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  20. CVE-2026-11539Unknown severity
    IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
    Not scoredSource severity not reported
    IBM/WebSphere Application Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  21. CVE-2026-75895Unknown severity
    Out of bounds read at smpp34_unpack()
    Not scoredSource severity not reported
    Osmocom/libsmpp34generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  22. CVE-2017-20284Unknown severity
    Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet
    Not scoredSource severity not reported
    Caucho Technology, Inc./Resingeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  23. CVE-2026-11538Low
    IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
    CVSS 3.7
    IBM/WebSphere Application Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  24. CVE-2021-48008Unknown severity
    Chanjet CRM SQL Injection via get_usedspace.php
    Not scoredSource severity not reported
    Chanjet Information Technology Co., Ltd./CRMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  25. CVE-2019-25776High
    Weaver E-cology SQL Injection via SyncUserInfo.jsp
    CVSS 8.7
    Weaver Network Co., Ltd./E-cologygeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  26. CVE-2023-54399Unknown severity
    Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree
    Not scoredSource severity not reported
    Hongjing/e-HRgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  27. CVE-2026-93854High
    CISA ADP Vulnrichment
    CVSS 7.2
    OpenStack/Blazargeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  28. CVE-2026-75894Unknown severity
    Reachable assertion at ranap_handle_co_dt()
    Not scoredSource severity not reported
    Osmocom/osmo-bsc, Osmocom/osmo-iuhgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  29. CVE-2026-93852Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    OpenStack/Blazargeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  30. CVE-2026-75893Unknown severity
    Heap based buffer overflow at ipaccess_proxy_read_msg()
    Not scoredSource severity not reported
    Osmocom/osmo-bscgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  31. CVE-2026-75892Unknown severity
    Out of bounds write in PDP ctx GSN-Address decode
    Not scoredSource severity not reported
    Osmocom/osmo-ggsngeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  32. CVE-2026-93650Low
    Saleor throttling.py get_client_ip excessive authentication
    CVSS 3.7
    n/a/Saleorgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  33. CVE-2026-59163Critical
    Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
    CVSS 9.1
    AxDSan/mnemosyne, mnemosyne-memorygeneric · pip · pypi
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  34. CVE-2026-92768Medium
    Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  35. CVE-2026-92747Medium
    Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  36. CVE-2026-92745Medium
    Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  37. CVE-2026-93432Medium
    Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection via qute {#eval} section in quarkus
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  38. CVE-2026-93753Unknown severity
    deepmerge through 4.3.1 Prototype Poisoning via mergeObject
    Not scoredSource severity not reported
    TehShrike/deepmergegeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  39. CVE-2026-93752Unknown severity
    CSSOM through 0.5.0 Denial of Service via length Property
    Not scoredSource severity not reported
    NV/CSSOMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  40. CVE-2026-93751Unknown severity
    uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars
    Not scoredSource severity not reported
    garycourt/uri-jsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  41. CVE-2026-93750Unknown severity
    http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard
    Not scoredSource severity not reported
    kornelski/http-cache-semanticsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  42. CVE-2026-93749High
    source-map-js through 1.2.1 Event Loop Denial of Service
    CVSS 8.7
    7rulnik/source-map-jsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  43. CVE-2026-93748Unknown severity
    http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale
    Not scoredSource severity not reported
    kornelski/http-cache-semanticsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  44. CVE-2026-81181Unknown severity
    SysReptor: Session Fixation in Password-Protected Shared Notes
    Not scoredSource severity not reported
    Syslifters/sysreptorgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026View HOL analysis
  45. CVE-2026-81182Medium
    SysReptor: Unauthorized file disclosure by broken access control in writable shared notes
    CVSS 4.2
    Syslifters/sysreptorgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  46. CVE-2026-81180High
    SysReptor: Authenticated RCE by insecure image processing
    CVSS 8.8
    Syslifters/sysreptorgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  47. CVE-2026-81179High
    SysReptor: Host header injection might allow account takeover
    CVSS 8.1
    Syslifters/sysreptorgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  48. CVE-2026-81178Low
    SysReptor: Anonymous note-share link discloses project member identities and non-shared note activity
    CVSS 3.5
    Syslifters/sysreptorgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  49. CVE-2026-71537Medium
    Paymenter: Credit-refund double-spend race condition in service downgrade (doUpgrade)
    CVSS 6.5
    Paymenter/Paymenter, paymenter/paymentercomposer · generic · packagist
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  50. CVE-2026-85058High
    Moquette: Missing Authorization in io.moquette:moquette-broker
    CVSS 7.5
    io.moquette:moquette-broker, moquette-io/moquettegeneric · maven
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
Page 32 of 776
Previous3031323334Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard