1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:25 AM 16,320 active 1,443 known exploited

Catalog summary

16,320

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:25 AM 16,320 active 1,443 known exploited

Catalog summary

16,320

Active CVEs

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,651–2,700 of 16,320 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-63795Unknown severity
    9p: avoid putting oldfid in p9_client_walk() error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-63793Unknown severity
    ntfs: serialize volume label accesses
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-53402Unknown severity
    fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-53401Unknown severity
    fbdev: omap2: fix use-after-free in omapfb_mmap
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-53400Unknown severity
    i2c: core: fix adapter registration race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-53399Unknown severity
    nfsd: release layout stid on setlease failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-53398Unknown severity
    NFSD: Fix SECINFO_NO_NAME decode error cleanup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-53397Unknown severity
    nfsd: fix posix_acl leak on SETACL decode failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-53396Unknown severity
    nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-53395Unknown severity
    nfsd: fix dead ACL conflict guard in nfsd4_create
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-53394Unknown severity
    nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-53392Unknown severity
    NFSv4/flexfiles: reject zero filehandle version count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-53391Unknown severity
    NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-53390Unknown severity
    ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-53389Unknown severity
    net/tcp-ao: fix use-after-free of key in del_async path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-53388Unknown severity
    fuse: re-lock request before replacing page cache folio
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-53387Unknown severity
    iio: light: veml6075: add bounds check to veml6075_it_ms index
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-53386Unknown severity
    iio: adc: ti-ads1298: add bounds check to pga_settings index
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-53384Critical
    serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-53383Unknown severity
    ksmbd: reject non-VALID session in compound request branch
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-53381Unknown severity
    virtiofs: fix UAF on submount umount
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-53380Unknown severity
    media: rzv2h-ivc: Fix concurrent buffer list access
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-53375Unknown severity
    drm/amdgpu/vce: Prevent partial address patches
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-53374Unknown severity
    drm/amdgpu: zero-initialize GART table on allocation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-53373Unknown severity
    mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-53369Unknown severity
    udf: reject descriptors with oversized CRC length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-53368Unknown severity
    f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-9147Unknown severity
    uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
    Not scoredSource severity not reported
    scikit-hep/uprootgeneric
    PublishedJul 18, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-16077Medium
    AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
    CVSS 5.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 18, 2026First seen at HOL Jul 18, 2026Updated Jul 20, 2026View HOL analysis
  30. CVE-2026-16076Medium
    AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
    CVSS 6.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 18, 2026First seen at HOL Jul 18, 2026Updated Jul 20, 2026View HOL analysis
  31. CVE-2026-16075Medium
    AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
    CVSS 4.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 18, 2026First seen at HOL Jul 18, 2026Updated Jul 21, 2026View HOL analysis
  32. CVE-2026-13445High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  33. CVE-2026-13446Critical
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 9.8
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  34. CVE-2026-45785Medium
    OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
    CVSS 6.2
    openmcdf/openmcdfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  35. CVE-2026-48062Critical
    CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule
    CVSS 9.8
    codeigniter4/CodeIgniter4generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  36. CVE-2026-45784Medium
    rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
    CVSS 5.1
    rust-openssl/rust-opensslgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  37. CVE-2026-16074Medium
    AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery
    CVSS 6.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  38. CVE-2026-44974High
    Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters
    CVSS 7.7
    hapijs/contentgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  39. CVE-2026-13448High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  40. CVE-2026-13473High
    IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow
    CVSS 8.1
    IBM/Storage Protect Clientgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  41. CVE-2026-14499High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  42. CVE-2026-14501Medium
    Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
    CVSS 4.3
    IBM/Agentics, IBM/Db2 Genius Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  43. CVE-2026-46420Medium
    setup-php: Command Injection in Repository-Derived PHP Version Resolution
    CVSS 5.6
    shivammathur/setup-phpgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  44. CVE-2026-14971Low
    This PowerVM Novalink update is being released to address
    CVSS 3.9
    IBM/PowerVM Novalinkgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  45. CVE-2026-45799High
    Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
    CVSS 7.5
    com.squareup.wire:wire-runtime, com.squareup.wire:wire-runtime-jvm +1generic · maven
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-14979Medium
    IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
    CVSS 5.3
    IBM/Engineering Lifecycle Managementgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 28, 2026View HOL analysis
  47. CVE-2026-16118High
    Xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 29, 2026View HOL analysis
  48. CVE-2026-15069Medium
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 5.4
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  49. CVE-2026-15091Critical
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 9.3
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  50. CVE-2026-15093Medium
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 4.3
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 54 of 327
Previous5253545556Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,651–2,700 of 16,320 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-63795Unknown severity
    9p: avoid putting oldfid in p9_client_walk() error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-63793Unknown severity
    ntfs: serialize volume label accesses
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-53402Unknown severity
    fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-53401Unknown severity
    fbdev: omap2: fix use-after-free in omapfb_mmap
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-53400Unknown severity
    i2c: core: fix adapter registration race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-53399Unknown severity
    nfsd: release layout stid on setlease failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-53398Unknown severity
    NFSD: Fix SECINFO_NO_NAME decode error cleanup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-53397Unknown severity
    nfsd: fix posix_acl leak on SETACL decode failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-53396Unknown severity
    nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-53395Unknown severity
    nfsd: fix dead ACL conflict guard in nfsd4_create
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-53394Unknown severity
    nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-53392Unknown severity
    NFSv4/flexfiles: reject zero filehandle version count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-53391Unknown severity
    NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-53390Unknown severity
    ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-53389Unknown severity
    net/tcp-ao: fix use-after-free of key in del_async path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-53388Unknown severity
    fuse: re-lock request before replacing page cache folio
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-53387Unknown severity
    iio: light: veml6075: add bounds check to veml6075_it_ms index
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-53386Unknown severity
    iio: adc: ti-ads1298: add bounds check to pga_settings index
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-53384Critical
    serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-53383Unknown severity
    ksmbd: reject non-VALID session in compound request branch
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-53381Unknown severity
    virtiofs: fix UAF on submount umount
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-53380Unknown severity
    media: rzv2h-ivc: Fix concurrent buffer list access
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-53375Unknown severity
    drm/amdgpu/vce: Prevent partial address patches
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-53374Unknown severity
    drm/amdgpu: zero-initialize GART table on allocation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-53373Unknown severity
    mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-53369Unknown severity
    udf: reject descriptors with oversized CRC length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-53368Unknown severity
    f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 19, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-9147Unknown severity
    uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
    Not scoredSource severity not reported
    scikit-hep/uprootgeneric
    PublishedJul 18, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-16077Medium
    AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
    CVSS 5.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 18, 2026First seen at HOL Jul 18, 2026Updated Jul 20, 2026View HOL analysis
  30. CVE-2026-16076Medium
    AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
    CVSS 6.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 18, 2026First seen at HOL Jul 18, 2026Updated Jul 20, 2026View HOL analysis
  31. CVE-2026-16075Medium
    AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
    CVSS 4.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 18, 2026First seen at HOL Jul 18, 2026Updated Jul 21, 2026View HOL analysis
  32. CVE-2026-13445High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  33. CVE-2026-13446Critical
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 9.8
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  34. CVE-2026-45785Medium
    OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
    CVSS 6.2
    openmcdf/openmcdfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  35. CVE-2026-48062Critical
    CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule
    CVSS 9.8
    codeigniter4/CodeIgniter4generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  36. CVE-2026-45784Medium
    rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
    CVSS 5.1
    rust-openssl/rust-opensslgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  37. CVE-2026-16074Medium
    AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery
    CVSS 6.3
    AstrBotDevs/AstrBotgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  38. CVE-2026-44974High
    Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters
    CVSS 7.7
    hapijs/contentgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  39. CVE-2026-13448High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.1
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  40. CVE-2026-13473High
    IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow
    CVSS 8.1
    IBM/Storage Protect Clientgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  41. CVE-2026-14499High
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    CVSS 8.8
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 23, 2026View HOL analysis
  42. CVE-2026-14501Medium
    Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
    CVSS 4.3
    IBM/Agentics, IBM/Db2 Genius Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  43. CVE-2026-46420Medium
    setup-php: Command Injection in Repository-Derived PHP Version Resolution
    CVSS 5.6
    shivammathur/setup-phpgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  44. CVE-2026-14971Low
    This PowerVM Novalink update is being released to address
    CVSS 3.9
    IBM/PowerVM Novalinkgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  45. CVE-2026-45799High
    Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
    CVSS 7.5
    com.squareup.wire:wire-runtime, com.squareup.wire:wire-runtime-jvm +1generic · maven
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-14979Medium
    IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
    CVSS 5.3
    IBM/Engineering Lifecycle Managementgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 28, 2026View HOL analysis
  47. CVE-2026-16118High
    Xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 29, 2026View HOL analysis
  48. CVE-2026-15069Medium
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 5.4
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  49. CVE-2026-15091Critical
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 9.3
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  50. CVE-2026-15093Medium
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 4.3
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 54 of 327
Previous5253545556Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard