HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 2:52 PM 38,894 active 1,498 known exploited

Catalog summary

38,894

Active CVEs

19,849

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,001–2,050 of 38,894 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-68493Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Nextcloud/Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  2. CVE-2026-77164Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Nextcloud/Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  3. CVE-2026-82985Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Nextcloud/Servergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  4. CVE-2026-77170Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Nextcloud/Deckgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  5. CVE-2026-82982Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Nextcloud/Approvalgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  6. CVE-2026-77169Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Nextcloud/Team Foldersgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  7. CVE-2026-82980Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Nextcloud/Files Lockgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  8. CVE-2026-93456High
    django-page-cms through 2.0.13 CSRF via admin mutation views
    CVSS 8.4
    batiste/django-page-cmsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 24, 2026View HOL analysis
  9. CVE-2026-93455High
    django-page-cms through 2.0.13 Unauthorized Content Access via Staff Account
    CVSS 7.1
    batiste/django-page-cmsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 24, 2026View HOL analysis
  10. CVE-2026-93313Medium
    Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow
    CVSS 6.3
    Freedesktop/Popplergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  11. CVE-2026-93312Medium
    Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference
    CVSS 5.3
    Freedesktop/Popplergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  12. CVE-2026-93311Medium
    Freedesktop Poppler SampledFunction Function.cc integer overflow
    CVSS 5.3
    Freedesktop/Popplergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  13. CVE-2026-79954High
    NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
    CVSS 8.7
    NASA/CryptoLibgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  14. CVE-2026-93310Medium
    O-RAN-SC SMO OAM VES Collector allocation of resources
    CVSS 5.3
    O-RAN-SC/SMO OAMgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  15. CVE-2026-79294Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  16. CVE-2026-88622Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  17. CVE-2026-88623High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  18. CVE-2026-93309Unknown severity
    O-RAN-SC SMO OAM VES Collector allocation of resources
    Not scoredSource severity not reported
    O-RAN-SC/SMO OAMgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026View HOL analysis
  19. CVE-2026-18441Unknown severity
    LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter
    Not scoredSource severity not reported
    latepoint/Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026View HOL analysis
  20. CVE-2026-2585Unknown severity
    Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter
    Not scoredSource severity not reported
    themefusecom/Brizy – Page Buildergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026View HOL analysis
  21. CVE-2026-93454Unknown severity
    Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
    Not scoredSource severity not reported
    Webkul/Aureus ERPgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026View HOL analysis
  22. CVE-2026-93453Unknown severity
    SOGo before 5.12.11 Password Reset Token Interception via Origin Header
    Not scoredSource severity not reported
    Alinto/SOGogeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  23. CVE-2026-93452Unknown severity
    snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress
    Not scoredSource severity not reported
    xerial/snappy-javageneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  24. CVE-2026-93451Unknown severity
    snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods
    Not scoredSource severity not reported
    xerial/snappy-javageneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026View HOL analysis
  25. CVE-2026-93450Unknown severity
    go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal
    Not scoredSource severity not reported
    go-openapi/swaggeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  26. CVE-2026-93308Medium
    O-RAN-SC SMO OAM VES Collector allocation of resources
    CVSS 4.3
    O-RAN-SC/SMO OAMgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  27. CVE-2026-93436High
    vLLM through 0.29.0 Memory Exhaustion via Rejected Requests
    CVSS 8.7
    vllm-project/vllmgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 24, 2026View HOL analysis
  28. CVE-2026-93435High
    redis-parser through 3.0.0 Denial of Service via Unbounded Recursion
    CVSS 8.7
    NodeRedis/redis-parsergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 24, 2026View HOL analysis
  29. CVE-2026-54645Medium
    CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass
    CVSS 4.8
    cubecart/v6generic
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  30. CVE-2026-54643Medium
    CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.php
    CVSS 5.4
    cubecart/v6generic
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  31. CVE-2026-54642Medium
    CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.php
    CVSS 5.3
    cubecart/v6generic
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-54644Medium
    CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System
    CVSS 6.1
    cubecart/v6generic
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  33. CVE-2026-54647High
    CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php
    CVSS 7.2
    cubecart/v6generic
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  34. CVE-2026-54646High
    CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php
    CVSS 7.2
    cubecart/v6generic
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  35. CVE-2026-54648Medium
    CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Customer Data Deletion
    CVSS 6.5
    cubecart/v6generic
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  36. CVE-2026-54734Critical
    Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction
    CVSS 10.0
    prebid/prebid-server-javageneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  37. CVE-2026-54519High
    AI Agent Automation: Missing ownership checks in memory APIs allow cross-user memory read and deletion
    CVSS 8.8
    vmDeshpande/ai-agent-automationgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  38. CVE-2026-86688High
    Session id is not renewed on authentication in ash_authentication, allowing session fixation
    CVSS 7.4
    team-alembic/ash_authenticationgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  39. CVE-2026-76949Critical
    Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement
    CVSS 9.1
    team-alembic/ash_authenticationgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  40. CVE-2026-54520High
    AI Agent Automation: Workflow file step path traversal allows read and write outside the expected directory
    CVSS 8.1
    vmDeshpande/ai-agent-automationgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  41. CVE-2026-54767Critical
    WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php
    CVSS 9.1
    LabRedesCefetRJ/WeGIAgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  42. CVE-2026-54671High
    WeGIA: Authorization Bypass via Empty Resource Array in InternoControle
    CVSS 8.8
    LabRedesCefetRJ/WeGIAgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  43. CVE-2026-54670Critical
    WeGIA: Unauthenticated Auth Bypass + Local File Inclusion
    CVSS 9.1
    LabRedesCefetRJ/WeGIAgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  44. CVE-2026-54634High
    Hamlib: rigctld `send_raw` Stack Out-of-Bounds Write and Uninitialized Memory Disclosure
    CVSS 7.3
    Hamlib/Hamlibgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  45. CVE-2026-54608High
    MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpoint allows arbitrary free credit top-up
    CVSS 7.1
    MythicalLTD/MythicalDashgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  46. CVE-2026-54506High
    Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field
    CVSS 7.6
    givanz/Vvvebgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  47. CVE-2026-54612High
    Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global
    CVSS 8.8
    givanz/Vvvebgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  48. CVE-2026-54613Medium
    Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter
    CVSS 5.4
    givanz/Vvvebgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  49. CVE-2026-93307Medium
    O-RAN-SC SMO OAM VES Collector memory allocation
    CVSS 5.3
    O-RAN-SC/SMO OAMgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 23, 2026View HOL analysis
  50. CVE-2026-54507High
    Vvveb oEmbedProxy vulnerable to server-side request forgery
    CVSS 8.4
    givanz/Vvvebgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
Page 41 of 778
Previous3940414243Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard