1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:25 AM 16,320 active 1,443 known exploited

Catalog summary

16,320

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:25 AM 16,320 active 1,443 known exploited

Catalog summary

16,320

Active CVEs

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,701–2,750 of 16,320 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15415Medium
    Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server
    CVSS 5.5
    AWS/aws-healthomics-mcp-servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  2. CVE-2026-15322High
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 7.5
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  3. CVE-2026-15995Medium
    IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use
    CVSS 5.4
    IBM/Cognos Analyticsgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  4. CVE-2026-12283Medium
    SQL injection in Amazon Athena Synapse connector
    CVSS 6.8
    AWS/aws-athena-query-federationgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  5. CVE-2026-45309High
    AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
    CVSS 8.2
    ronf/asyncsshgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  6. CVE-2026-47184Medium
    Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast flood
    CVSS 6.5
    python-zeroconf/python-zeroconfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  7. CVE-2026-47183Medium
    Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
    CVSS 6.5
    python-zeroconf/python-zeroconfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  8. CVE-2026-47180Medium
    Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of service
    CVSS 6.5
    python-zeroconf/python-zeroconfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  9. CVE-2026-16073Low
    AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting
    CVSS 3.5
    AstrBotDevs/AstrBotgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 22, 2026View HOL analysis
  10. CVE-2026-9198Critical
    Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
    CVSS 9.8 Known exploited
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 7, 2026View HOL analysis
  11. CVE-2025-59866Low
    CISA ADP Vulnrichment
    CVSS 3.3
    HCLSoftware/DFMPro for CATIA, HCLSoftware/DFXAnalytics +1generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  12. CVE-2026-21764Low
    Insufficient Input Validation in DevOps Loop
    CVSS 3.1
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  13. CVE-2026-21762Low
    Missing HTTP Security Headers in DevOps Loop
    CVSS 3.7
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  14. CVE-2026-21761Medium
    CORS Misconfiguration in DevOps Loop
    CVSS 4.2
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2026-21760Medium
    Unauthorized Access to Admin Functionality via Forced Browsing
    CVSS 4.6
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-12694Critical
    Missing Authorization in Vimesoft's Enterprise Video Platform
    CVSS 9.1
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  17. CVE-2026-12693Critical
    IDOR in Vimesoft's Enterprise Video Platform
    CVSS 9.4
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  18. CVE-2026-16104Medium
    Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-16103Medium
    Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-16106Medium
    Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-16108Medium
    Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-16093Medium
    Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  23. CVE-2026-44722Medium
    pyzipper: Encryption bypass for small files encrypted with pyzipper
    CVSS 6.2
    danifus/pyzippergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  24. CVE-2026-12692Critical
    Improper Authentication in Vimesoft's Enterprise Video Platform
    CVSS 9.8
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-12691High
    Authentication Bypass in Vimesoft's Enterprise Video Platform
    CVSS 7.5
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-11763Medium
    IDOR in GIS Informatics' GisLab Laboratory Management System
    CVSS 6.5
    Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc./GisLab Laboratory Management Systemgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  27. CVE-2026-15783Medium
    Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
    CVSS 5.3
    GitHub/Enterprise Servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2026-14741Unknown severity
    HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
    Not scoredSource severity not reported
    OALDERS/HTTP::Dategeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  29. CVE-2026-15343High
    Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
    CVSS 8.6
    GitHub/Enterprise Servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  30. CVE-2026-15007Medium
    Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
    CVSS 5.7
    GitHub/Enterprise Servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  31. CVE-2026-12715High
    Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft
    CVSS 8.5
    Google Cloud/Firebase Studiogeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-14871High
    osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
    CVSS 7.1
    osTicket/osTicketgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  33. CVE-2026-12705Medium
    Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool
    CVSS 6.4
    ABB/KNX Update Tool (ABB), ABB/KNX Update Tool (BJE)generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  34. CVE-2026-16089Medium
    Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 22, 2026View HOL analysis
  35. CVE-2026-16017Medium
    mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  36. CVE-2024-23572Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  37. CVE-2024-23570Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  38. CVE-2024-23578Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  39. CVE-2024-23569Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  40. CVE-2024-23577Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  41. CVE-2024-23574Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  42. CVE-2024-42214Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  43. CVE-2024-23575Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  44. CVE-2024-23571Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  45. CVE-2024-23573Low
    CISA ADP Vulnrichment
    CVSS 3.7
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  46. CVE-2026-16072Medium
    Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  47. CVE-2024-23568Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  48. CVE-2024-23565Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  49. CVE-2024-23566Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  50. CVE-2024-23567Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 55 of 327
Previous5354555657Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,701–2,750 of 16,320 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15415Medium
    Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server
    CVSS 5.5
    AWS/aws-healthomics-mcp-servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  2. CVE-2026-15322High
    Multiple Vulnerabilities in IBM Engineering AI hub.
    CVSS 7.5
    IBM/Engineering AI Hubgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  3. CVE-2026-15995Medium
    IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use
    CVSS 5.4
    IBM/Cognos Analyticsgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  4. CVE-2026-12283Medium
    SQL injection in Amazon Athena Synapse connector
    CVSS 6.8
    AWS/aws-athena-query-federationgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  5. CVE-2026-45309High
    AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
    CVSS 8.2
    ronf/asyncsshgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  6. CVE-2026-47184Medium
    Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast flood
    CVSS 6.5
    python-zeroconf/python-zeroconfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  7. CVE-2026-47183Medium
    Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
    CVSS 6.5
    python-zeroconf/python-zeroconfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  8. CVE-2026-47180Medium
    Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of service
    CVSS 6.5
    python-zeroconf/python-zeroconfgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  9. CVE-2026-16073Low
    AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting
    CVSS 3.5
    AstrBotDevs/AstrBotgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 22, 2026View HOL analysis
  10. CVE-2026-9198Critical
    Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
    CVSS 9.8 Known exploited
    IBM/Langflow OSSgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 7, 2026View HOL analysis
  11. CVE-2025-59866Low
    CISA ADP Vulnrichment
    CVSS 3.3
    HCLSoftware/DFMPro for CATIA, HCLSoftware/DFXAnalytics +1generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  12. CVE-2026-21764Low
    Insufficient Input Validation in DevOps Loop
    CVSS 3.1
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  13. CVE-2026-21762Low
    Missing HTTP Security Headers in DevOps Loop
    CVSS 3.7
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  14. CVE-2026-21761Medium
    CORS Misconfiguration in DevOps Loop
    CVSS 4.2
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2026-21760Medium
    Unauthorized Access to Admin Functionality via Forced Browsing
    CVSS 4.6
    HCLSoftware/DevOps Loopgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-12694Critical
    Missing Authorization in Vimesoft's Enterprise Video Platform
    CVSS 9.1
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  17. CVE-2026-12693Critical
    IDOR in Vimesoft's Enterprise Video Platform
    CVSS 9.4
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  18. CVE-2026-16104Medium
    Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-16103Medium
    Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-16106Medium
    Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-16108Medium
    Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-16093Medium
    Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  23. CVE-2026-44722Medium
    pyzipper: Encryption bypass for small files encrypted with pyzipper
    CVSS 6.2
    danifus/pyzippergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  24. CVE-2026-12692Critical
    Improper Authentication in Vimesoft's Enterprise Video Platform
    CVSS 9.8
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-12691High
    Authentication Bypass in Vimesoft's Enterprise Video Platform
    CVSS 7.5
    Vimesoft Inc./Enterprise Video Platformgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-11763Medium
    IDOR in GIS Informatics' GisLab Laboratory Management System
    CVSS 6.5
    Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc./GisLab Laboratory Management Systemgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  27. CVE-2026-15783Medium
    Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
    CVSS 5.3
    GitHub/Enterprise Servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2026-14741Unknown severity
    HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
    Not scoredSource severity not reported
    OALDERS/HTTP::Dategeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  29. CVE-2026-15343High
    Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
    CVSS 8.6
    GitHub/Enterprise Servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  30. CVE-2026-15007Medium
    Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
    CVSS 5.7
    GitHub/Enterprise Servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  31. CVE-2026-12715High
    Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft
    CVSS 8.5
    Google Cloud/Firebase Studiogeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-14871High
    osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
    CVSS 7.1
    osTicket/osTicketgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  33. CVE-2026-12705Medium
    Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool
    CVSS 6.4
    ABB/KNX Update Tool (ABB), ABB/KNX Update Tool (BJE)generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  34. CVE-2026-16089Medium
    Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 22, 2026View HOL analysis
  35. CVE-2026-16017Medium
    mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  36. CVE-2024-23572Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  37. CVE-2024-23570Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  38. CVE-2024-23578Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  39. CVE-2024-23569Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  40. CVE-2024-23577Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  41. CVE-2024-23574Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  42. CVE-2024-42214Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  43. CVE-2024-23575Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  44. CVE-2024-23571Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  45. CVE-2024-23573Low
    CISA ADP Vulnrichment
    CVSS 3.7
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  46. CVE-2026-16072Medium
    Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  47. CVE-2024-23568Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  48. CVE-2024-23565Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  49. CVE-2024-23566Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  50. CVE-2024-23567Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 55 of 327
Previous5354555657Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard