1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 4:05 AM 16,288 active 1,443 known exploited

Catalog summary

16,288

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 4:05 AM 16,288 active 1,443 known exploited

Catalog summary

16,288

Active CVEs

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,151–2,200 of 16,288 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-69931Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 30, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  2. CVE-2026-46678Medium
    Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
    CVSS 6.8
    pydantic/pydantic-ai, pydantic/pydantic-ai-slimgeneric
    PublishedJul 29, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  3. CVE-2025-14562Low
    Incorrect Authorization in GitLab
    CVSS 3.1
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  4. CVE-2026-3093Medium
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 4.7
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  5. CVE-2026-4672Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  6. CVE-2026-12436High
    Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
    CVSS 8.4
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  7. CVE-2026-13113Medium
    Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
    CVSS 6.5
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  8. CVE-2026-14341Medium
    Missing Authorization in GitLab
    CVSS 4.9
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  9. CVE-2026-14351Medium
    Exposure of Sensitive Information Through Metadata in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  10. CVE-2026-15077Medium
    Improper Neutralization of Input Used for LLM Prompting in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  11. CVE-2026-15831Medium
    Generation of Incorrect Security Tokens in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  12. CVE-2026-15975High
    Allocation of Resources Without Limits or Throttling in GitLab
    CVSS 7.5
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  13. CVE-2026-16553Medium
    Insufficiently Protected Credentials in GitLab
    CVSS 5.4
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  14. CVE-2026-2482Low
    IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
    CVSS 3.1
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJul 29, 2026First seen at HOL Aug 4, 2026Updated Jul 30, 2026View HOL analysis
  15. CVE-2026-64560Unknown severity
    posix-cpu-timers: Prevent UAF caused by non-leader exec() race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-64559Unknown severity
    s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-64558Unknown severity
    s390/pkey: Check length in pkey_pckmo handler implementation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-20316High
    Cisco Secure Firewall Management Center Software Static Credential Vulnerability
    Not scored Known exploited
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedJul 29, 2026First seen at HOL Aug 2, 2026Updated Aug 1, 2026View HOL analysis
  19. CVE-2026-17550Medium
    DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
    CVSS 5.5
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +1generic
    PublishedJul 29, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-16465Medium
    DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
    CVSS 6.1
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +1generic
    PublishedJul 29, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-16463High
    DXF File Parsing Heap-Based Overflow in Autodesk AutoCAD
    CVSS 7.8
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +1generic
    PublishedJul 29, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-64557Unknown severity
    Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-64556Unknown severity
    perf/core: Detach event groups during remove_on_exec
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-33930Medium
    Apache Traffic Server: Buffer overflow via Host field that has a long string value
    CVSS 5.9
    Apache Software Foundation/Apache Traffic Servergeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  25. CVE-2026-41920Critical
    Apache Traffic Server: SNI to Host header matching policy is not properly enforced
    CVSS 9.3
    Apache Software Foundation/Apache Traffic Servergeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  26. CVE-2025-69944High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedJul 29, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  27. CVE-2026-54658Critical
    @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
    CVSS 9.8
    @hypequery/clickhouse, hypequery/hypequerygeneric · npm
    PublishedJul 28, 2026First seen at HOL Aug 2, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  28. CVE-2026-13442High
    Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 7.1
    IBM/Langflow OSSgeneric
    PublishedJul 28, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  29. CVE-2026-15325High
    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
    CVSS 8.7
    IBM/WebSphere Application Server, IBM/WebSphere Application Server - Libertygeneric
    PublishedJul 28, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-16184High
    IBM WebSphere Application Server is affected by an authentication bypass
    CVSS 7.0
    IBM/WebSphere Application Servergeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  31. CVE-2026-16192High
    IBM WebSphere Application Server Liberty is affected by a denial of service
    CVSS 7.1
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-1918Medium
    IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file
    CVSS 4.9
    IBM/Sterling B2B Integrator, IBM/Sterling File Gatewaygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  33. CVE-2026-3157Medium
    Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI
    CVSS 4.3
    IBM/Sterling B2B Integrator, IBM/Sterling File Gatewaygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2026-3158Medium
    Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
    CVSS 4.3
    IBM/Sterling B2B Integrator, IBM/Sterling File Gatewaygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-16313High
    Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export
    CVSS 7.6
    Affected software not mappedEcosystem not listed
    PublishedJul 28, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  36. CVE-2026-6879Low
    Quadratic Behavior in xml.etree.ElementPath Index Predicates
    CVSS 2.0
    Python Software Foundation/CPythongeneric
    PublishedJul 28, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-7187High
    Improper Authentication in Universal Sotware's UKBS
    CVSS 8.8
    Universal Software Inc./UKBSgeneric
    PublishedJul 28, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  38. CVE-2026-65880Unknown severity
    Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
    Not scoredSource severity not reported
    balbooa.com/Balbooa Forms component for Joomlageneric
    PublishedJul 28, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-39875High
    CISA ADP Vulnrichment
    CVSS 7.8
    Apple/macOSgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-64555Unknown severity
    KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-64554Unknown severity
    netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-64552Unknown severity
    virtio-net: fix len check in receive_big()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-64551Unknown severity
    sctp: validate STALE_COOKIE cause length before reading staleness
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-64550Unknown severity
    net: qualcomm: rmnet: validate MAP frame length before ingress parsing
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-64548Unknown severity
    bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64547Unknown severity
    net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-64546Unknown severity
    drm/edid: fix OOB read in drm_parse_tiled_block()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-64545Unknown severity
    net, bpf: check master for NULL in xdp_master_redirect()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-64543Unknown severity
    tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-64541Unknown severity
    net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 44 of 326
Previous4243444546Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,151–2,200 of 16,288 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-69931Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 30, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  2. CVE-2026-46678Medium
    Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
    CVSS 6.8
    pydantic/pydantic-ai, pydantic/pydantic-ai-slimgeneric
    PublishedJul 29, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  3. CVE-2025-14562Low
    Incorrect Authorization in GitLab
    CVSS 3.1
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  4. CVE-2026-3093Medium
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 4.7
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  5. CVE-2026-4672Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  6. CVE-2026-12436High
    Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
    CVSS 8.4
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  7. CVE-2026-13113Medium
    Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
    CVSS 6.5
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  8. CVE-2026-14341Medium
    Missing Authorization in GitLab
    CVSS 4.9
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  9. CVE-2026-14351Medium
    Exposure of Sensitive Information Through Metadata in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  10. CVE-2026-15077Medium
    Improper Neutralization of Input Used for LLM Prompting in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  11. CVE-2026-15831Medium
    Generation of Incorrect Security Tokens in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  12. CVE-2026-15975High
    Allocation of Resources Without Limits or Throttling in GitLab
    CVSS 7.5
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  13. CVE-2026-16553Medium
    Insufficiently Protected Credentials in GitLab
    CVSS 5.4
    GitLab/GitLabgeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  14. CVE-2026-2482Low
    IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
    CVSS 3.1
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJul 29, 2026First seen at HOL Aug 4, 2026Updated Jul 30, 2026View HOL analysis
  15. CVE-2026-64560Unknown severity
    posix-cpu-timers: Prevent UAF caused by non-leader exec() race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-64559Unknown severity
    s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-64558Unknown severity
    s390/pkey: Check length in pkey_pckmo handler implementation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-20316High
    Cisco Secure Firewall Management Center Software Static Credential Vulnerability
    Not scored Known exploited
    Cisco/Cisco Secure Firewall Management Center (FMC)generic
    PublishedJul 29, 2026First seen at HOL Aug 2, 2026Updated Aug 1, 2026View HOL analysis
  19. CVE-2026-17550Medium
    DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
    CVSS 5.5
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +1generic
    PublishedJul 29, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-16465Medium
    DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
    CVSS 6.1
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +1generic
    PublishedJul 29, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-16463High
    DXF File Parsing Heap-Based Overflow in Autodesk AutoCAD
    CVSS 7.8
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +1generic
    PublishedJul 29, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-64557Unknown severity
    Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-64556Unknown severity
    perf/core: Detach event groups during remove_on_exec
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 29, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-33930Medium
    Apache Traffic Server: Buffer overflow via Host field that has a long string value
    CVSS 5.9
    Apache Software Foundation/Apache Traffic Servergeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  25. CVE-2026-41920Critical
    Apache Traffic Server: SNI to Host header matching policy is not properly enforced
    CVSS 9.3
    Apache Software Foundation/Apache Traffic Servergeneric
    PublishedJul 29, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  26. CVE-2025-69944High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedJul 29, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  27. CVE-2026-54658Critical
    @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
    CVSS 9.8
    @hypequery/clickhouse, hypequery/hypequerygeneric · npm
    PublishedJul 28, 2026First seen at HOL Aug 2, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  28. CVE-2026-13442High
    Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 7.1
    IBM/Langflow OSSgeneric
    PublishedJul 28, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  29. CVE-2026-15325High
    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
    CVSS 8.7
    IBM/WebSphere Application Server, IBM/WebSphere Application Server - Libertygeneric
    PublishedJul 28, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-16184High
    IBM WebSphere Application Server is affected by an authentication bypass
    CVSS 7.0
    IBM/WebSphere Application Servergeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  31. CVE-2026-16192High
    IBM WebSphere Application Server Liberty is affected by a denial of service
    CVSS 7.1
    IBM/WebSphere Application Server - Libertygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-1918Medium
    IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file
    CVSS 4.9
    IBM/Sterling B2B Integrator, IBM/Sterling File Gatewaygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  33. CVE-2026-3157Medium
    Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI
    CVSS 4.3
    IBM/Sterling B2B Integrator, IBM/Sterling File Gatewaygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2026-3158Medium
    Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
    CVSS 4.3
    IBM/Sterling B2B Integrator, IBM/Sterling File Gatewaygeneric
    PublishedJul 28, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-16313High
    Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export
    CVSS 7.6
    Affected software not mappedEcosystem not listed
    PublishedJul 28, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  36. CVE-2026-6879Low
    Quadratic Behavior in xml.etree.ElementPath Index Predicates
    CVSS 2.0
    Python Software Foundation/CPythongeneric
    PublishedJul 28, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-7187High
    Improper Authentication in Universal Sotware's UKBS
    CVSS 8.8
    Universal Software Inc./UKBSgeneric
    PublishedJul 28, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  38. CVE-2026-65880Unknown severity
    Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
    Not scoredSource severity not reported
    balbooa.com/Balbooa Forms component for Joomlageneric
    PublishedJul 28, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-39875High
    CISA ADP Vulnrichment
    CVSS 7.8
    Apple/macOSgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-64555Unknown severity
    KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-64554Unknown severity
    netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-64552Unknown severity
    virtio-net: fix len check in receive_big()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-64551Unknown severity
    sctp: validate STALE_COOKIE cause length before reading staleness
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-64550Unknown severity
    net: qualcomm: rmnet: validate MAP frame length before ingress parsing
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-64548Unknown severity
    bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64547Unknown severity
    net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-64546Unknown severity
    drm/edid: fix OOB read in drm_parse_tiled_block()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-64545Unknown severity
    net, bpf: check master for NULL in xdp_master_redirect()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-64543Unknown severity
    tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-64541Unknown severity
    net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 27, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 44 of 326
Previous4243444546Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard