HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 24, 2026, 2:52 PM 38,894 active 1,498 known exploited

Catalog summary

38,894

Active CVEs

19,849

Critical + high

1,498

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,701–2,750 of 38,894 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-90130Unknown severity
    vdpa_sim: fix cleanup after worker creation failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  2. CVE-2026-90129Unknown severity
    virtio_balloon: quiesce balloon work before device shutdown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  3. CVE-2026-90128Unknown severity
    vdpa/mlx5: fix wrong list iterated in add_direct_chain error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  4. CVE-2026-90127Unknown severity
    virtio: rtc: time out alarm requests
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  5. CVE-2026-90126Unknown severity
    rtc: pcf8563: fix clock provider leak on unbind
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  6. CVE-2026-90125Unknown severity
    smb: client: fix request buffer leak in smb2_new_read_req()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  7. CVE-2026-90124Unknown severity
    irqchip/renesas-rzg2l: Fix loss of interrupt
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  8. CVE-2026-90123Unknown severity
    irqchip/ast2700-intc: Avoid allocating in the irq_domain activate() callback
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  9. CVE-2026-90122Unknown severity
    clk: visconti: Make sure clk_init_data is fully initialized
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  10. CVE-2026-90121Unknown severity
    irqchip/gic-v5: Clear per-CPU IRS data on teardown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  11. CVE-2026-90120High
    irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing
    CVSS 8.4
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  12. CVE-2026-90119Unknown severity
    ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  13. CVE-2026-90118High
    ntfs: fix off-by-one page overflow in ntfs_decompress()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  14. CVE-2026-90117Unknown severity
    ntfs: validate usa_ofs before preserving the update sequence number
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  15. CVE-2026-90116Unknown severity
    ALSA: mtpav: shut down output timer before card teardown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  16. CVE-2026-90115Unknown severity
    xsk: fix NULL pointer dereference in __xsk_rcv()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  17. CVE-2026-90114Unknown severity
    net: bridge: Reject descending VLAN tunnel ranges
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  18. CVE-2026-90113Unknown severity
    netdevsim: update queue NAPI association on queue reset
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  19. CVE-2026-90112Unknown severity
    net: qlcnic: validate unified ROM sections before loading
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  20. CVE-2026-90111High
    ip6mr: do not clone dst in ip6mr_cache_report()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  21. CVE-2026-90110Critical
    inetpeer: randomize RB-tree node comparison using SipHash
    CVSS 9.4
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  22. CVE-2026-90109Unknown severity
    net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  23. CVE-2026-90108Unknown severity
    net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  24. CVE-2026-90107Unknown severity
    net/smc: free pending qentry in smc_llc_flow_stop() before memset
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-90106Unknown severity
    net: bridge: arp/nd proxy: fix reading neigh ha
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-90105Unknown severity
    vxlan: fix reading neigh ha
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  27. CVE-2026-90104Critical
    NFSv4.1: zero referring call lists before decoding
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  28. CVE-2026-90103High
    NFSv4.2: fix LAYOUTSTATS send buffer exhaustion
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  29. CVE-2026-90102High
    NFSv4/pnfs: key the data server cache on the NFS version
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  30. CVE-2026-90101Unknown severity
    bnxt_en: Fix call to hardware monitoring event handler
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  31. CVE-2026-90100Unknown severity
    ptp: netc: fix period truncation and potential divide-by-zero in PEROUT
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-90099Unknown severity
    net/sched: account classifier filter allocations to memcg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  33. CVE-2026-90098Unknown severity
    net: sparx5: fix sleep in atomic context in MAC table access
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  34. CVE-2026-90097Unknown severity
    Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  35. CVE-2026-90096Unknown severity
    fuse: invalidate the correct range after O_APPEND direct write
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  36. CVE-2026-90095Unknown severity
    fuse: Fix the condition to enable over-io-uring
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-90094Unknown severity
    arm64: process: Fix context switching MTE store-only tag check
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-90093High
    Bluetooth: L2CAP: access chan->conn safely in get/setsockopt
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  39. CVE-2026-90092High
    Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN
    CVSS 8.0
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  40. CVE-2026-90091High
    Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan
    CVSS 8.0
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  41. CVE-2026-90090Unknown severity
    Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-90089High
    Bluetooth: btnxpuart: Validate the FW dump header length
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  43. CVE-2026-90088Unknown severity
    Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  44. CVE-2026-90087Unknown severity
    Bluetooth: do not leak an hci_conn when a second LE connect is rejected
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  45. CVE-2026-90086Unknown severity
    xsk: honor XDP_TX_METADATA in zero-copy path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  46. CVE-2026-90085Unknown severity
    octeontx2-af: fix NULL deref in NIX TM tree debugfs read path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  47. CVE-2026-90084Unknown severity
    octeontx2-vf: fix workqueue and netdev race in probe/remove
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  48. CVE-2026-90083Unknown severity
    net/sched: act_ife: Only operate on Ethernet frames
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  49. CVE-2026-90082Unknown severity
    net: mana: Cap MSI-X vectors to the device MSI-X table size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  50. CVE-2026-90081Unknown severity
    net/rds: use wq_has_sleeper() in rds_cong_map_updated()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedSep 17, 2026First seen at HOL Sep 17, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
Page 55 of 778
Previous5354555657Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard