HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 2:52 PM 38,894 active 1,498 known exploited

Catalog summary

38,894

Active CVEs

19,849

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,301–2,350 of 38,894 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-93083Unknown severity
    firmware: arm_scmi: Unwind TX receiver mailbox setup failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  2. CVE-2026-93082Unknown severity
    firmware: arm_scmi: Unwind P2A receiver mailbox setup failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  3. CVE-2026-93081Unknown severity
    firmware: arm_scmi: Fix SCMI device destroy lifetimes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  4. CVE-2026-93080Unknown severity
    firmware: arm_scmi: Fix transport device teardown lookup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  5. CVE-2026-93079High
    cxl/features: Reject Get Feature count larger than the output buffer
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  6. CVE-2026-93078Unknown severity
    cxl/features: Reject Set Features output buffer smaller than the header
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  7. CVE-2026-93077Unknown severity
    cxl/features: Clamp Get Feature output size to the remaining buffer
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  8. CVE-2026-93076Unknown severity
    dax/fsdev: clear vmemmap_shift when binding static pgmap
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  9. CVE-2026-93075Unknown severity
    dax/fsdev: clear pgmap ops and owner on unbind
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  10. CVE-2026-93074High
    dax/fsdev: use __va(phys) for kaddr in direct_access
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  11. CVE-2026-93073Unknown severity
    dax: read holder_ops once in dax_holder_notify_failure()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  12. CVE-2026-93072Unknown severity
    irqchip/renesas-irqc: Fix generic interrupt chip leak on remove
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  13. CVE-2026-93071Unknown severity
    media: bcm2835-unicam: Fix asc leaked in error/remove path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  14. CVE-2026-93070High
    media: ipu6: Do not free aux device pdata after init
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  15. CVE-2026-93069Unknown severity
    OPP: Fix cleanup ordering
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  16. CVE-2026-93068Unknown severity
    drm/amd/display: Fix DM I2C teardown race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  17. CVE-2026-93067Unknown severity
    drm/bridge: tc358767: clamp the reported AUX read size to the request
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  18. CVE-2026-93066Unknown severity
    x86/mm/pat: Take cpa_lock around large-page collapse
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  19. CVE-2026-93065Unknown severity
    wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  20. CVE-2026-93064Unknown severity
    wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  21. CVE-2026-93063High
    wifi: iwlwifi: mei: check SAP message length before reading it
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  22. CVE-2026-93062Unknown severity
    wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  23. CVE-2026-93061Unknown severity
    gpu: host1x: Avoid stack over-read in debug output helpers
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  24. CVE-2026-93060Unknown severity
    drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-93059Unknown severity
    drm/msm: Fix task_struct reference leak in recover_worker
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-93058Unknown severity
    drm/msm: Only fini scheduler after successful init
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  27. CVE-2026-93057Unknown severity
    scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  28. CVE-2026-93056Unknown severity
    usb: gadget: f_uac1_legacy: remove broken string configfs attributes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  29. CVE-2026-93055Unknown severity
    UDF symlink pathComponent header OOB read
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  30. CVE-2026-93054High
    uio: Fix stale info pointer in failed registration path
    CVSS 7.0
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  31. CVE-2026-93053Unknown severity
    speakup: keyhelp: guard letter_offsets possible out-of-range indexing
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-93052Unknown severity
    misc: bcm-vk: Use acquire/release for msgq_inited
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  33. CVE-2026-93051Unknown severity
    misc: ad525x_dpot: use driver core groups for sysfs files
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  34. CVE-2026-93050Unknown severity
    ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  35. CVE-2026-93049Unknown severity
    mtd: mtdswap: Avoid freeing registered blktrans device twice
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  36. CVE-2026-93048Unknown severity
    mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-93047Unknown severity
    drm/v3d: Associate BOs with every job that accesses them
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-93046High
    software node: Fix software_node_get_reference_args() with index -1
    CVSS 7.0
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  39. CVE-2026-93045High
    bpf: Reject arena frees below the arena base
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  40. CVE-2026-93044Unknown severity
    bpf: Disallow interpreter fallback for arena-related insns
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  41. CVE-2026-93043Unknown severity
    bpf: Disallow interpreter fallback for gotox insn
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-93042High
    dmaengine: dw-edma: Terminate all descriptors without callbacks
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  43. CVE-2026-93041Unknown severity
    dmaengine: dw-edma: Serialize abort state updates
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  44. CVE-2026-93040Unknown severity
    dmaengine: dw-edma: Serialize channel state checks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  45. CVE-2026-93039High
    ASoC: meson: Keep link pointers valid on realloc failure
    CVSS 7.4
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  46. CVE-2026-93038Unknown severity
    iio: dac: ad5686: missing NULL check on match data
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  47. CVE-2026-93037High
    RDMA/hfi1: Propagate sdma_txinit_ahg() errors
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  48. CVE-2026-92525High
    RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  49. CVE-2026-92524Unknown severity
    irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  50. CVE-2026-92523Unknown severity
    RDMA/nldev: validate dynamic counter attribute length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
Page 47 of 778
Previous4546474849Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard