1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 5:45 AM 16,295 active 1,443 known exploited

Catalog summary

16,295

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 5:45 AM 16,295 active 1,443 known exploited

Catalog summary

16,295

Active CVEs

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,351–2,400 of 16,295 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64268Unknown severity
    RDMA/siw: bound Read Response placement to the RREAD length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-64266Unknown severity
    fuse: re-lock request before returning from fuse_ref_folio()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-64265Unknown severity
    fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-64261Unknown severity
    fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-64260Unknown severity
    fuse-uring: Avoid queue->stopped races and set/read that value under lock
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-64259Unknown severity
    fuse-uring: make a fuse_req on SQE commit only findable after memcpy
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-64257Unknown severity
    smb: client: reject overlapping data areas in SMB2 responses
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-66373High
    CISA ADP Vulnrichment
    CVSS 7.5
    Redis/Redisgeneric
    PublishedJul 25, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-17107High
    Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJul 24, 2026First seen at HOL Aug 4, 2026Updated Aug 9, 2026View HOL analysis
  10. CVE-2026-64255Unknown severity
    wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-64251Unknown severity
    pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-64247Unknown severity
    KVM: x86: hyper-v: Bound the bank index when querying sparse banks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-64243Unknown severity
    ASoC: codecs: simple-mux: Fix enum control bounds check
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-64235Unknown severity
    x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-64232Unknown severity
    block: recompute nr_integrity_segments in blk_insert_cloned_request
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-64226Unknown severity
    sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-64223Unknown severity
    wifi: mac80211: consume only present negotiated TTLM maps
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-64222Unknown severity
    octeontx2-pf: avoid double free of pool->stack on AQ init failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-64221Unknown severity
    spi: ti-qspi: fix use-after-free after DMA setup failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-64219Unknown severity
    drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-64218Unknown severity
    batman-adv: bla: fix report_work leak on backbone_gw purge
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-64217Unknown severity
    netfs: Fix overrun check in netfs_extract_user_iter()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-64216Unknown severity
    netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-64210Unknown severity
    net/mlx5e: xsk: Fix unlocked writing to ICOSQ
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-64208Unknown severity
    crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-16730Unknown severity
    Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  27. CVE-2026-21655High
    C-CURE 9000 and Victor application server - Deserialization of Untrusted Data
    CVSS 8.7
    Johnson Control/victor, Johnson Controls/CCure 9000 +1generic
    PublishedJul 23, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  28. CVE-2026-65512Medium
    WordPress WP Activity Log and WP Activity Log Premium plugins <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 5.4
    Melapress/WP Activity Log, Melapress/WP Activity Log Premiumgeneric
    PublishedJul 23, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-65458Medium
    WordPress Polylang and Polylang Pro plugins <= 3.8.5 - Sensitive Data Exposure vulnerability
    CVSS 4.3
    Chouby/Polylang, Chouby/Polylang Progeneric
    PublishedJul 23, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-24552High
    WordPress Create plugin <= 2.5.3 - SQL Injection vulnerability
    CVSS 8.5
    John-Michael L'Allier/Creategeneric
    PublishedJul 23, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-64600High
    xfs: resample the data fork mapping after cycling ILOCK
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJul 23, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-64829High
    Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
    CVSS 7.4
    q2a/question2answergeneric
    PublishedJul 22, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  33. CVE-2026-64828Medium
    Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field
    CVSS 6.1
    Froiden/TableTrackgeneric
    PublishedJul 22, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  34. CVE-2026-16232Critical
    Authentication Bypass in the SmartConsole Login Process Using an Application Token
    CVSS 9.1 Known exploited
    checkpoint/Multi-Domain Security Management, checkpoint/Quantum Security Managementgeneric
    PublishedJul 22, 2026First seen at HOL Aug 2, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-2406Medium
    IDOR in Universe Software's Online Registration and Workflow Management System
    CVSS 6.5
    Universe Software Computer Marketing Trade and Industry Inc./Online Registration and Workflow Management Systemgeneric
    PublishedJul 22, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-15927Medium
    Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 21, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-64206Unknown severity
    Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-64191Unknown severity
    i2c: stub: Reject I2C block transfers with invalid length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-64189Unknown severity
    netfilter: ipset: fix race between dump and ip_set_list resize
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-64188Unknown severity
    net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-16242Critical
    Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
    CVSS 9.4
    Affected software not mappedEcosystem not listed
    PublishedJul 20, 2026First seen at HOL Aug 4, 2026Updated Aug 9, 2026View HOL analysis
  42. CVE-2026-64181Unknown severity
    mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-64178Unknown severity
    Bluetooth: bnep: Fix UAF read of dev->name
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-64176Unknown severity
    wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-64175Unknown severity
    wifi: iwlwifi: mld: stop TX during firmware restart
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64172Unknown severity
    KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-64162Unknown severity
    idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-64160Unknown severity
    netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-64158Unknown severity
    netfs: Fix write streaming disablement if fd open O_RDWR
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-64153Unknown severity
    drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 48 of 326
Previous4647484950Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,351–2,400 of 16,295 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64268Unknown severity
    RDMA/siw: bound Read Response placement to the RREAD length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-64266Unknown severity
    fuse: re-lock request before returning from fuse_ref_folio()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-64265Unknown severity
    fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-64261Unknown severity
    fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-64260Unknown severity
    fuse-uring: Avoid queue->stopped races and set/read that value under lock
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-64259Unknown severity
    fuse-uring: make a fuse_req on SQE commit only findable after memcpy
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-64257Unknown severity
    smb: client: reject overlapping data areas in SMB2 responses
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-66373High
    CISA ADP Vulnrichment
    CVSS 7.5
    Redis/Redisgeneric
    PublishedJul 25, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-17107High
    Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJul 24, 2026First seen at HOL Aug 4, 2026Updated Aug 9, 2026View HOL analysis
  10. CVE-2026-64255Unknown severity
    wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-64251Unknown severity
    pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-64247Unknown severity
    KVM: x86: hyper-v: Bound the bank index when querying sparse banks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-64243Unknown severity
    ASoC: codecs: simple-mux: Fix enum control bounds check
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-64235Unknown severity
    x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-64232Unknown severity
    block: recompute nr_integrity_segments in blk_insert_cloned_request
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-64226Unknown severity
    sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-64223Unknown severity
    wifi: mac80211: consume only present negotiated TTLM maps
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-64222Unknown severity
    octeontx2-pf: avoid double free of pool->stack on AQ init failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-64221Unknown severity
    spi: ti-qspi: fix use-after-free after DMA setup failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-64219Unknown severity
    drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-64218Unknown severity
    batman-adv: bla: fix report_work leak on backbone_gw purge
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-64217Unknown severity
    netfs: Fix overrun check in netfs_extract_user_iter()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-64216Unknown severity
    netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-64210Unknown severity
    net/mlx5e: xsk: Fix unlocked writing to ICOSQ
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-64208Unknown severity
    crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-16730Unknown severity
    Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedJul 24, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  27. CVE-2026-21655High
    C-CURE 9000 and Victor application server - Deserialization of Untrusted Data
    CVSS 8.7
    Johnson Control/victor, Johnson Controls/CCure 9000 +1generic
    PublishedJul 23, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  28. CVE-2026-65512Medium
    WordPress WP Activity Log and WP Activity Log Premium plugins <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 5.4
    Melapress/WP Activity Log, Melapress/WP Activity Log Premiumgeneric
    PublishedJul 23, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-65458Medium
    WordPress Polylang and Polylang Pro plugins <= 3.8.5 - Sensitive Data Exposure vulnerability
    CVSS 4.3
    Chouby/Polylang, Chouby/Polylang Progeneric
    PublishedJul 23, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-24552High
    WordPress Create plugin <= 2.5.3 - SQL Injection vulnerability
    CVSS 8.5
    John-Michael L'Allier/Creategeneric
    PublishedJul 23, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-64600High
    xfs: resample the data fork mapping after cycling ILOCK
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJul 23, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-64829High
    Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
    CVSS 7.4
    q2a/question2answergeneric
    PublishedJul 22, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  33. CVE-2026-64828Medium
    Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field
    CVSS 6.1
    Froiden/TableTrackgeneric
    PublishedJul 22, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  34. CVE-2026-16232Critical
    Authentication Bypass in the SmartConsole Login Process Using an Application Token
    CVSS 9.1 Known exploited
    checkpoint/Multi-Domain Security Management, checkpoint/Quantum Security Managementgeneric
    PublishedJul 22, 2026First seen at HOL Aug 2, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-2406Medium
    IDOR in Universe Software's Online Registration and Workflow Management System
    CVSS 6.5
    Universe Software Computer Marketing Trade and Industry Inc./Online Registration and Workflow Management Systemgeneric
    PublishedJul 22, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-15927Medium
    Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 21, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-64206Unknown severity
    Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-64191Unknown severity
    i2c: stub: Reject I2C block transfers with invalid length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-64189Unknown severity
    netfilter: ipset: fix race between dump and ip_set_list resize
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-64188Unknown severity
    net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 20, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-16242Critical
    Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
    CVSS 9.4
    Affected software not mappedEcosystem not listed
    PublishedJul 20, 2026First seen at HOL Aug 4, 2026Updated Aug 9, 2026View HOL analysis
  42. CVE-2026-64181Unknown severity
    mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-64178Unknown severity
    Bluetooth: bnep: Fix UAF read of dev->name
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-64176Unknown severity
    wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-64175Unknown severity
    wifi: iwlwifi: mld: stop TX during firmware restart
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64172Unknown severity
    KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-64162Unknown severity
    idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-64160Unknown severity
    netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-64158Unknown severity
    netfs: Fix write streaming disablement if fd open O_RDWR
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-64153Unknown severity
    drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 48 of 326
Previous4647484950Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard