HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright ยฉ 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 2:52 PM 38,894 active 1,498 known exploited

Catalog summary

38,894

Active CVEs

19,849

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,151โ€“2,200 of 38,894 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-92927Unknown severity
    SourceCodester Drug Recommendation System drug_recommendor.sql information disclosure
    Not scoredSource severity not reported
    SourceCodester/Drug Recommendation Systemgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026View HOL analysis
  2. CVE-2026-89038Unknown severity
    Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity
    Not scoredSource severity not reported
    Verizon/Verizon Cloud for Androidgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  3. CVE-2026-92926High
    code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection
    CVSS 7.3
    code-projects/Matrimonial Systemgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  4. CVE-2026-52836High
    OpenDDS: out-of-bounds `rd_ptr` dereference in `RtpsSampleHeader::init` โ€” triggered by malformed RTPS submessage, remotely exploitable denial of service
    CVSS 8.7
    OpenDDS/OpenDDSgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  5. CVE-2026-65608High
    Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
    CVSS 8.8
    getgrav/gravcomposer ยท packagist
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  6. CVE-2026-54676Medium
    Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal API tokens are enabled
    CVSS 6.5
    Erudika/scooldgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  7. CVE-2026-54677Medium
    Scoold: Authenticated user can post replies and comments to private-space questions without space membership
    CVSS 6.5
    Erudika/scooldgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  8. CVE-2026-54446High
    NetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
    CVSS 8.1
    Labs64/NetLicensing-MCP, netlicensing-mcpgeneric ยท pip
    PublishedSep 17, 2026First seen at HOL Jul 15, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  9. CVE-2026-54053Critical
    Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults
    CVSS 9.6
    brufdev/many-notesgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  10. CVE-2026-54551Medium
    WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces' traffic stats to every user (missing per-user authorization)
    CVSS 4.3
    h44z/wg-portalgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  11. CVE-2026-44235Medium
    rabbitmq-c: size_t underflow in AMQP frame length computation leads to out-of-bounds read
    CVSS 6.5
    alanxz/rabbitmq-cgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026View HOL analysis
  12. CVE-2026-44236Unknown severity
    rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max
    Not scoredSource severity not reported
    alanxz/rabbitmq-cgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026View HOL analysis
  13. CVE-2026-54546Medium
    CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) โ€” no IP-classification guard
    CVSS 5.0
    @tak-ps/cloudtak, dfpc-coe/CloudTAKgeneric ยท npm
    PublishedSep 17, 2026First seen at HOL Jul 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  14. CVE-2026-54579Low
    mport mirror-selection ping accepts insufficiently validated ICMP replies
    CVSS 2.3
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  15. CVE-2026-54576Medium
    mport package installation has symlink TOCTOU in chown and chmod handling
    CVSS 5.8
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  16. CVE-2026-54587Medium
    mport directory asset installation is vulnerable to symlink and path traversal races
    CVSS 5.8
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  17. CVE-2026-54575Medium
    mport package fetch and clean paths are vulnerable to TOCTOU filesystem races
    CVSS 5.8
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  18. CVE-2026-8674Medium
    Assertion failure in the DNS stub resolver with a long search domain
    CVSS 5.3
    The GNU C Library/glibcgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  19. CVE-2026-54578Low
    mport verify can compare stale checksum data after hashing failures
    CVSS 2.0
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  20. CVE-2026-54586Medium
    mport permits repository and package mirror fetches over insecure transport
    CVSS 6.0
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  21. CVE-2026-54585Medium
    mport sample file handling can write outside the configured root
    CVSS 6.0
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  22. CVE-2026-54580High
    mport index decompression can leave partial or corrupt index data after zstd failures
    CVSS 8.3
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  23. CVE-2026-54582Medium
    mport package installation can overwrite existing unmanaged or differently owned files
    CVSS 6.0
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  24. CVE-2026-54577Low
    mport audit can inspect the wrong package when options are present
    CVSS 2.0
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-54583High
    mport package bundle downloads allow unsafe destination filenames
    CVSS 8.3
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-54581High
    mport bootstrap index fetch can continue after hash verification failure
    CVSS 8.3
    MidnightBSD/mportgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  27. CVE-2026-28326High
    SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
    CVSS 8.8
    SolarWinds/Access Rights Managergeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026View HOL analysis
  28. CVE-2026-93296Unknown severity
    MISP Overmind: Stored Cross-Site Scripting via Unescaped Object Names in Statistics Legends
    Not scoredSource severity not reported
    misp/mispgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  29. CVE-2026-93292Unknown severity
    SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders
    Not scoredSource severity not reported
    SigNoz/signozgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  30. CVE-2026-93295Unknown severity
    MISP Background Job Argument Injection via Console Path Switches Enables Remote Code Execution
    Not scoredSource severity not reported
    misp/mispgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  31. CVE-2026-85716Low
    AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified
    CVSS 3.7
    AsyncHttpClient/async-http-client, org.asynchttpclient:async-http-clientgeneric ยท maven
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  32. CVE-2026-93204Unknown severity
    batman-adv: dat: atomically update mac addresses
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  33. CVE-2026-93203High
    batman-adv: bla: avoid CRC corruption due to parallel claim add
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  34. CVE-2026-93202Unknown severity
    i3c: master: Fix recursive locking during device registration
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  35. CVE-2026-93201High
    dm-pcache: validate seg_id fields from persistent memory
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  36. CVE-2026-93200Unknown severity
    i3c: master: Fix use-after-free of master->this
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-93199Unknown severity
    i3c: master: Do not treat master device as a duplicate target
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-93198Unknown severity
    dm-pcache: validate the persisted dirty_tail chain at load
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  39. CVE-2026-93197Unknown severity
    memcg: move LRU size accounting on reparenting instead of copying it
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-93196High
    nvdimm: virtio_pmem: refcount requests for token lifetime
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  41. CVE-2026-93195Unknown severity
    drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-93194Unknown severity
    drm/rockchip: dw_dp: Release core resources
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  43. CVE-2026-93193Unknown severity
    drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  44. CVE-2026-93192High
    drm/v3d: Clear queue->active_job when v3d_fence_create() fails
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  45. CVE-2026-93191Unknown severity
    smack: fix incorrect task context in smack_msg_queue_msgrcv
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  46. CVE-2026-93190High
    platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  47. CVE-2026-93189High
    HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  48. CVE-2026-93188Unknown severity
    HID: roccat: bound device-supplied profile index
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  49. CVE-2026-93187Unknown severity
    ASoC: SOF: ipc4-topology: Return error for invalid number of formats
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  50. CVE-2026-93186Unknown severity
    cxl/mbox: Clamp mailbox output allocation to the payload size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
Page 44 of 778
Previous4243444546Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard