HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 2:52 PM 38,894 active 1,498 known exploited

Catalog summary

38,894

Active CVEs

19,849

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,051–2,100 of 38,894 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-50158High
    yutu: Arbitrary File Write via MCP `caption-download` Tool
    CVSS 7.7
    eat-pray-ai/yutu, github.com/eat-pray-ai/yutugeneric · go
    PublishedSep 17, 2026First seen at HOL Jul 15, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  2. CVE-2026-53534High
    JabRef CAYW Sublime Text integration permits operating-system command injection
    CVSS 7.5
    JabRef/jabrefgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  3. CVE-2026-53557High
    SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution
    CVSS 7.7
    dataease/SQLBotgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  4. CVE-2026-53555Medium
    Stored XSS via SVG Upload
    CVSS 5.1
    dataease/SQLBotgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  5. CVE-2026-53556Medium
    SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read
    CVSS 6.0
    dataease/SQLBotgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  6. CVE-2026-53554High
    SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing
    CVSS 7.3
    dataease/SQLBotgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  7. CVE-2026-54633Medium
    PoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchScanLine)
    CVSS 6.9
    podofo/podofogeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  8. CVE-2026-54343High
    Frappe LMS: Path Traversal in SCORM File Serving
    CVSS 8.7
    frappe/lmsgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  9. CVE-2026-50291Medium
    OpenImageIO: Segmentation Fault in BmpInput::read_native_scanline (bmpinput.cpp:399)
    CVSS 5.5
    AcademySoftwareFoundation/OpenImageIOgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026View HOL analysis
  10. CVE-2026-14311Medium
    Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover
    CVSS 5.4
    melograno/Booking for Appointments and Events Calendar – Ameliageneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  11. CVE-2026-16582Medium
    Booking for Appointments and Events Calendar - Amelia <= 2.4.5 - Missing Authorization to Unauthenticated Payment Bypass
    CVSS 5.3
    melograno/Booking for Appointments and Events Calendar – Ameliageneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  12. CVE-2026-16750Medium
    Motors – Car Dealership & Classified Listings <= 1.4.120 - Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure
    CVSS 5.3
    stylemix/Motors – Car Dealership & Classified Listings Plugingeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  13. CVE-2026-93426Unknown severity
    SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names
    Not scoredSource severity not reported
    SigNoz/signozgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  14. CVE-2026-73639Critical
    Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026View HOL analysis
  15. CVE-2026-73638Medium
    Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd
    CVSS 6.2
    Affected software not mappedEcosystem not listed
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026View HOL analysis
  16. CVE-2026-93386Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  17. CVE-2026-93385Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  18. CVE-2026-93378Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  19. CVE-2026-93376Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  20. CVE-2026-93383Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  21. CVE-2026-93384Low
    CISA ADP Vulnrichment
    CVSS 3.7
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  22. CVE-2026-93380Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  23. CVE-2026-93377Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  24. CVE-2026-93379Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  25. CVE-2026-93381Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  26. CVE-2026-93373Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  27. CVE-2026-93387Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  28. CVE-2026-93382High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026View HOL analysis
  29. CVE-2026-93375Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  30. CVE-2026-93372Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  31. CVE-2026-93374Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    Google/Chromegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  32. CVE-2026-77615High
    Paella Player: Stored XSS via caption cue text
    CVSS 8.7
    opencast/opencast, org.opencastproject:opencast-engage-paella-player-7 +2generic · maven · npm
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  33. CVE-2026-15815High
    CVE-2026-15815 CVE Record
    CVSS 8.8
    Grafana/Grafana Enterprise, Grafana/Grafana OSSgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 19, 2026View HOL analysis
  34. CVE-2026-93395Medium
    Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()
    CVSS 5.3
    MongoDB Inc./C Drivergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  35. CVE-2026-54597High
    ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter
    CVSS 8.3
    itflow-org/itflowgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  36. CVE-2026-54596High
    ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration
    CVSS 8.1
    itflow-org/itflowgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-54907Medium
    Caddy Proxy Manager: Registrations enabled by default allows creating users with "user" permission
    CVSS 5.3
    fuomag9/caddy-proxy-managergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  38. CVE-2026-93394Low
    libmongoc SCRAM client nonce-validation bypass
    CVSS 3.7
    MongoDB Inc./C Drivergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  39. CVE-2026-54604Medium
    OpenSlide: openslide_read_region() returns uninitialized memory with libtiff 4.7.1
    CVSS 5.3
    openslide/openslidegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  40. CVE-2026-86049High
    Jupyter Server: 5xx request logging leaks token-bearing Referer header values
    CVSS 7.1
    jupyter-server, jupyter-server/jupyter_server +1generic · pip · pypi
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  41. CVE-2026-93393High
    Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream
    CVSS 8.1
    MongoDB Inc./C Drivergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  42. CVE-2026-48977Unknown severity
    OpenSlide: Arbitrary memory write with crafted Ventana BIF file
    Not scoredSource severity not reported
    openslide/openslidegeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  43. CVE-2026-54355Medium
    MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST`
    CVSS 5.3
    MapServer/MapServergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  44. CVE-2026-68523High
    Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
    CVSS 7.5
    fulgur, fulgur-rs/fulgurcrates.io · generic · rust
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  45. CVE-2026-54354High
    MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query Translation
    CVSS 8.2
    MapServer/MapServergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  46. CVE-2026-76154High
    CVE-2026-76154 CVE Record
    CVSS 7.3
    Grafana/Grafana Enterprise, Grafana/Grafana OSSgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  47. CVE-2026-54339High
    Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via Malicious RSS Feed in /api/feeds/discover
    CVSS 7.7
    LeslieLeung/gleangeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  48. CVE-2026-67071Medium
    HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or Transfer
    CVSS 6.5
    HCLSoftware/HCL DevOps Deploy / HCL Launchgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  49. CVE-2026-54510High
    Speakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hook
    CVSS 7.1
    murtaza-nasir/speakrgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  50. CVE-2026-54565Medium
    rhwp browser extension performs SSRF / private-network requests and leaks HWP preview data to untrusted pages
    CVSS 4.7
    edwardkim/rhwpgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
Page 42 of 778
Previous4041424344Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard