1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 12:50 AM 16,281 active 1,443 known exploited

Catalog summary

16,281

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 12:50 AM 16,281 active 1,443 known exploited

Catalog summary

16,281

Active CVEs

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,751–1,800 of 16,281 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-58048Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-58047Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-17566Critical
    pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
    CVSS 9.9
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-17351Critical
    pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-17350Medium
    pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
    CVSS 5.4
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-17349Critical
    pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
    CVSS 9.6
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-17348Medium
    pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)
    CVSS 6.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-17347High
    pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
    CVSS 7.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-17346High
    pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
    CVSS 8.8
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-10686Medium
    Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers
    CVSS 5.8
    zephyrproject/zephyrgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-18141High
    Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  12. CVE-2026-16504Critical
    VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities
    CVSS 9.8
    VPS.org/Zulip templategeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  13. CVE-2026-16503Critical
    VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities
    CVSS 9.1
    VPS.org/Supabase templategeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  14. CVE-2026-10685High
    Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler
    CVSS 7.6
    zephyrproject/zephyrgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-18358High
    Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  16. CVE-2026-44615Medium
    Path traversal in NotebookRepo note and folder path composition
    CVSS 6.5
    Apache Software Foundation/Apache Zeppelingeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  17. CVE-2026-16843High
    CISA ADP Vulnrichment
    CVSS 7.2
    Hikvision/DS-3WAP521-SI, Hikvision/DS-3WAP522-SI +8generic
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  18. CVE-2026-11770High
    389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-15722High
    389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  20. CVE-2026-10079High
    Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  21. CVE-2026-18209Low
    Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check
    CVSS 3.4
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-18206Low
    Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-18214Medium
    Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-18203Medium
    Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-18211Medium
    Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-18208Medium
    Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  27. CVE-2026-16105Medium
    Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-18215Medium
    Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-18217Low
    Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution
    CVSS 3.4
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  30. CVE-2026-18218Medium
    Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-43833Medium
    tbc
    CVSS 5.3
    tbc/tbcgeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-18157High
    Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection
    CVSS 7.8
    RedHatInsights/yggdrasil-worker-package-managergeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  33. CVE-2025-69946Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2025-69948Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-38708Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  36. CVE-2026-38710High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-38711Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-38713Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  39. CVE-2026-12946Critical
    Remote Code Execution in CUGA Component CodeAgent
    CVSS 9.9
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  40. CVE-2026-13444High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  41. CVE-2026-66066Critical
    Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
    CVSS 9.5
    activestorage, rails/railsgeneric · rubygems
    PublishedJul 30, 2026First seen at HOL Aug 2, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-15969Critical
    CVE-2026-15969
    CVSS 9.8
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  43. CVE-2026-15978High
    CVE-2026-15978
    CVSS 7.5
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  44. CVE-2026-15977High
    CVE-2026-15977
    CVSS 7.5
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  45. CVE-2026-15976Critical
    CVE-2026-15976
    CVSS 9.8
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  46. CVE-2026-15974Medium
    CVE-2026-15974
    CVSS 6.5
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  47. CVE-2026-15971Critical
    CVE-2026-15971
    CVSS 9.8
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  48. CVE-2026-10700Medium
    Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  49. CVE-2026-13435Critical
    Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure
    CVSS 9.9
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  50. CVE-2026-12942High
    Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 7.5
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
Page 36 of 326
Previous3435363738Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,751–1,800 of 16,281 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-58048Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-58047Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-17566Critical
    pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
    CVSS 9.9
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-17351Critical
    pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-17350Medium
    pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
    CVSS 5.4
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-17349Critical
    pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
    CVSS 9.6
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-17348Medium
    pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)
    CVSS 6.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-17347High
    pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
    CVSS 7.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-17346High
    pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
    CVSS 8.8
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-10686Medium
    Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers
    CVSS 5.8
    zephyrproject/zephyrgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-18141High
    Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  12. CVE-2026-16504Critical
    VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities
    CVSS 9.8
    VPS.org/Zulip templategeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  13. CVE-2026-16503Critical
    VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities
    CVSS 9.1
    VPS.org/Supabase templategeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  14. CVE-2026-10685High
    Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler
    CVSS 7.6
    zephyrproject/zephyrgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-18358High
    Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  16. CVE-2026-44615Medium
    Path traversal in NotebookRepo note and folder path composition
    CVSS 6.5
    Apache Software Foundation/Apache Zeppelingeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  17. CVE-2026-16843High
    CISA ADP Vulnrichment
    CVSS 7.2
    Hikvision/DS-3WAP521-SI, Hikvision/DS-3WAP522-SI +8generic
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  18. CVE-2026-11770High
    389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-15722High
    389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  20. CVE-2026-10079High
    Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  21. CVE-2026-18209Low
    Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check
    CVSS 3.4
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-18206Low
    Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-18214Medium
    Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-18203Medium
    Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-18211Medium
    Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-18208Medium
    Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  27. CVE-2026-16105Medium
    Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-18215Medium
    Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-18217Low
    Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution
    CVSS 3.4
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  30. CVE-2026-18218Medium
    Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-43833Medium
    tbc
    CVSS 5.3
    tbc/tbcgeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-18157High
    Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection
    CVSS 7.8
    RedHatInsights/yggdrasil-worker-package-managergeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  33. CVE-2025-69946Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2025-69948Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-38708Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  36. CVE-2026-38710High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-38711Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-38713Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  39. CVE-2026-12946Critical
    Remote Code Execution in CUGA Component CodeAgent
    CVSS 9.9
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  40. CVE-2026-13444High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  41. CVE-2026-66066Critical
    Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
    CVSS 9.5
    activestorage, rails/railsgeneric · rubygems
    PublishedJul 30, 2026First seen at HOL Aug 2, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-15969Critical
    CVE-2026-15969
    CVSS 9.8
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  43. CVE-2026-15978High
    CVE-2026-15978
    CVSS 7.5
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  44. CVE-2026-15977High
    CVE-2026-15977
    CVSS 7.5
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  45. CVE-2026-15976Critical
    CVE-2026-15976
    CVSS 9.8
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  46. CVE-2026-15974Medium
    CVE-2026-15974
    CVSS 6.5
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  47. CVE-2026-15971Critical
    CVE-2026-15971
    CVSS 9.8
    SGLang/SGLanggeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  48. CVE-2026-10700Medium
    Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files
    CVSS 6.5
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  49. CVE-2026-13435Critical
    Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure
    CVSS 9.9
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  50. CVE-2026-12942High
    Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 7.5
    IBM/Langflow OSSgeneric
    PublishedJul 30, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
Page 36 of 326
Previous3435363738Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard