1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 9:30 AM 16,321 active 1,443 known exploited

Catalog summary

16,321

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 9:30 AM 16,321 active 1,443 known exploited

Catalog summary

16,321

Active CVEs

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,801–2,850 of 16,321 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-44174High
    Kirby: Arbitrary Method Call via REST API search and collection query endpoints
    CVSS 8.7
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 18, 2026View HOL analysis
  2. CVE-2026-44023High
    Docling Core has unsafe remote filename resolution
    CVSS 8.6
    docling-project/docling-coregeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  3. CVE-2026-44019High
    Docling Core has insufficient validation of image reference URIs
    CVSS 8.1
    docling-project/docling-coregeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  4. CVE-2026-11889Medium
    SALTO ProAccess Space Authorization Bypass Through User-Controlled Key
    CVSS 6.5
    SALTO/ProAccess Spacegeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  5. CVE-2026-44982High
    CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests
    CVSS 7.2
    crowdsecurity/crowdsecgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  6. CVE-2026-15352High
    NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference
    CVSS 7.5
    NASA/Core Flight System (cFS) Health & Safety (HS) Applicationgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  7. CVE-2026-15422Critical
    SCTP needs to better-check INIT ACK chunk parameters
    CVSS 9.1
    OmniOS/OmniOS, Triton Data Center/SmartOS +1generic
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  8. CVE-2026-15449Medium
    TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption
    CVSS 5.8
    OmniOS/OmniOS, Triton Data Center/SmartOS +1generic
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  9. CVE-2026-46338Medium
    PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
    CVSS 4.3
    facelessuser/pymdown-extensionsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  10. CVE-2026-46515Critical
    Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution
    CVSS 9.3
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  11. CVE-2026-46512Critical
    Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping
    CVSS 9.9
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  12. CVE-2026-46513High
    Frogman: API tokens stored in plaintext
    CVSS 7.4
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  13. CVE-2026-46514Medium
    Frogman: Plaintext passwords and secrets persisted to audit log
    CVSS 6.5
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  14. CVE-2026-46353High
    BigBlueButton API checksum bypass via presentationUploadExternalUrl
    CVSS 8.1
    bigbluebutton/bigbluebuttongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2026-46404Medium
    BigBlueButton: Presentation URL Security Hardening
    CVSS 6.8
    bigbluebutton/bigbluebuttongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-46351High
    BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them
    CVSS 8.1
    bigbluebutton/bigbluebuttongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  17. CVE-2026-46377Medium
    Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
    CVSS 6.2
    TomWright/daselgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  18. CVE-2026-46378Medium
    Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
    CVSS 6.2
    TomWright/daselgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  19. CVE-2026-44969Low
    dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled
    CVSS 2.5
    dbt-labs/dbt-mcpgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  20. CVE-2026-44970Low
    dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redaction
    CVSS 3.1
    dbt-labs/dbt-mcpgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  21. CVE-2026-44968Medium
    dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
    CVSS 6.3
    dbt-labs/dbt-mcpgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  22. CVE-2026-15945Medium
    Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  23. CVE-2026-46336High
    Manyfold: Authenticated Path Traversal via File Rename
    CVSS 7.1
    manyfold3d/manyfoldgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  24. CVE-2026-15737Medium
    Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
    CVSS 5.7
    AWS/bedrock-agentcoregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  25. CVE-2026-45336Critical
    HireFlow: Use of Hard-coded Credentials
    CVSS 10.0
    StratonWebDesigners/HireFlowgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  26. CVE-2026-46687High
    Emlog Local File Inclusion (LFI)
    CVSS 7.7
    emlog/emloggeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  27. CVE-2026-46686High
    Emlog Reflected Cross-Site Scripting
    CVSS 8.5
    emlog/emloggeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2026-46341Medium
    Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
    CVSS 6.1
    apify/apify-mcp-servergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  29. CVE-2026-45367High
    HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
    CVSS 7.5
    hapifhir/org.hl7.fhir.coregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  30. CVE-2026-10590Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-10589Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-10588Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  33. CVE-2026-10587Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  34. CVE-2026-14371High
    CISA ADP Vulnrichment
    CVSS 8.8
    Lenovo/XClarity Integrator for Microsoft Windows Admin Centergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  35. CVE-2026-13104High
    CISA ADP Vulnrichment
    CVSS 7.3
    Lenovo/App Storegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-13103High
    CISA ADP Vulnrichment
    CVSS 7.3
    Lenovo/App Storegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  37. CVE-2026-45576High
    zrok copy writes attacker-controlled WebDAV paths outside the destination root
    CVSS 8.3
    openziti/zrokgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-45568Critical
    zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
    CVSS 9.9
    openziti/zrokgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  39. CVE-2026-45325High
    Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath
    CVSS 8.2
    tmlmobilidade/gogeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  40. CVE-2026-45795Medium
    Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server
    CVSS 5.3
    JanssenProject/jansgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  41. CVE-2026-45612Medium
    rz-libdemangle: Out of bound read in rust demangler
    CVSS 5.5
    rizinorg/rz-libdemanglegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  42. CVE-2026-3031Critical
    Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
    CVSS 9.8
    TOKUHIROM/Image::EPEGgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  43. CVE-2026-13401Unknown severity
    XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes
    Not scoredSource severity not reported
    CODECHILD/XML::Baregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  44. CVE-2026-13397Unknown severity
    HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes
    Not scoredSource severity not reported
    CODECHILD/HTML::Baregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  45. CVE-2026-47729Medium
    Squid: Memory disclosure in FTP gateway
    CVSS 6.5
    squid-cache/squidgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  46. CVE-2026-46621Critical
    Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
    CVSS 9.1
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  47. CVE-2026-46562Critical
    Yamcs: Remote Code Execution via Mission Database algorithm override
    CVSS 9.8
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  48. CVE-2026-44632Critical
    Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
    CVSS 9.1
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  49. CVE-2026-44596Medium
    Yamcs: No Rate Limiting on Authentication Endpoint
    CVSS 6.5
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  50. CVE-2026-44595Medium
    Yamcs: Unauthorized user enumeration via IAM API endpoints
    CVSS 4.3
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
Page 57 of 327
Previous5556575859Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,801–2,850 of 16,321 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-44174High
    Kirby: Arbitrary Method Call via REST API search and collection query endpoints
    CVSS 8.7
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 18, 2026View HOL analysis
  2. CVE-2026-44023High
    Docling Core has unsafe remote filename resolution
    CVSS 8.6
    docling-project/docling-coregeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  3. CVE-2026-44019High
    Docling Core has insufficient validation of image reference URIs
    CVSS 8.1
    docling-project/docling-coregeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  4. CVE-2026-11889Medium
    SALTO ProAccess Space Authorization Bypass Through User-Controlled Key
    CVSS 6.5
    SALTO/ProAccess Spacegeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  5. CVE-2026-44982High
    CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests
    CVSS 7.2
    crowdsecurity/crowdsecgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  6. CVE-2026-15352High
    NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference
    CVSS 7.5
    NASA/Core Flight System (cFS) Health & Safety (HS) Applicationgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  7. CVE-2026-15422Critical
    SCTP needs to better-check INIT ACK chunk parameters
    CVSS 9.1
    OmniOS/OmniOS, Triton Data Center/SmartOS +1generic
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  8. CVE-2026-15449Medium
    TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption
    CVSS 5.8
    OmniOS/OmniOS, Triton Data Center/SmartOS +1generic
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  9. CVE-2026-46338Medium
    PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
    CVSS 4.3
    facelessuser/pymdown-extensionsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  10. CVE-2026-46515Critical
    Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution
    CVSS 9.3
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  11. CVE-2026-46512Critical
    Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping
    CVSS 9.9
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  12. CVE-2026-46513High
    Frogman: API tokens stored in plaintext
    CVSS 7.4
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  13. CVE-2026-46514Medium
    Frogman: Plaintext passwords and secrets persisted to audit log
    CVSS 6.5
    mwtcmi/frogmangeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  14. CVE-2026-46353High
    BigBlueButton API checksum bypass via presentationUploadExternalUrl
    CVSS 8.1
    bigbluebutton/bigbluebuttongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2026-46404Medium
    BigBlueButton: Presentation URL Security Hardening
    CVSS 6.8
    bigbluebutton/bigbluebuttongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-46351High
    BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them
    CVSS 8.1
    bigbluebutton/bigbluebuttongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  17. CVE-2026-46377Medium
    Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
    CVSS 6.2
    TomWright/daselgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  18. CVE-2026-46378Medium
    Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
    CVSS 6.2
    TomWright/daselgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  19. CVE-2026-44969Low
    dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled
    CVSS 2.5
    dbt-labs/dbt-mcpgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  20. CVE-2026-44970Low
    dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redaction
    CVSS 3.1
    dbt-labs/dbt-mcpgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  21. CVE-2026-44968Medium
    dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
    CVSS 6.3
    dbt-labs/dbt-mcpgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  22. CVE-2026-15945Medium
    Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  23. CVE-2026-46336High
    Manyfold: Authenticated Path Traversal via File Rename
    CVSS 7.1
    manyfold3d/manyfoldgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  24. CVE-2026-15737Medium
    Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
    CVSS 5.7
    AWS/bedrock-agentcoregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  25. CVE-2026-45336Critical
    HireFlow: Use of Hard-coded Credentials
    CVSS 10.0
    StratonWebDesigners/HireFlowgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  26. CVE-2026-46687High
    Emlog Local File Inclusion (LFI)
    CVSS 7.7
    emlog/emloggeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  27. CVE-2026-46686High
    Emlog Reflected Cross-Site Scripting
    CVSS 8.5
    emlog/emloggeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2026-46341Medium
    Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
    CVSS 6.1
    apify/apify-mcp-servergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  29. CVE-2026-45367High
    HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
    CVSS 7.5
    hapifhir/org.hl7.fhir.coregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  30. CVE-2026-10590Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-10589Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-10588Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  33. CVE-2026-10587Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Lenovo/IdeaPad 5 15ABA7 BIOS, Lenovo/IdeaPad Pro 5 16AGP11 BIOS +55generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  34. CVE-2026-14371High
    CISA ADP Vulnrichment
    CVSS 8.8
    Lenovo/XClarity Integrator for Microsoft Windows Admin Centergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  35. CVE-2026-13104High
    CISA ADP Vulnrichment
    CVSS 7.3
    Lenovo/App Storegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  36. CVE-2026-13103High
    CISA ADP Vulnrichment
    CVSS 7.3
    Lenovo/App Storegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  37. CVE-2026-45576High
    zrok copy writes attacker-controlled WebDAV paths outside the destination root
    CVSS 8.3
    openziti/zrokgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-45568Critical
    zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
    CVSS 9.9
    openziti/zrokgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  39. CVE-2026-45325High
    Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath
    CVSS 8.2
    tmlmobilidade/gogeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  40. CVE-2026-45795Medium
    Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server
    CVSS 5.3
    JanssenProject/jansgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  41. CVE-2026-45612Medium
    rz-libdemangle: Out of bound read in rust demangler
    CVSS 5.5
    rizinorg/rz-libdemanglegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  42. CVE-2026-3031Critical
    Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
    CVSS 9.8
    TOKUHIROM/Image::EPEGgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  43. CVE-2026-13401Unknown severity
    XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes
    Not scoredSource severity not reported
    CODECHILD/XML::Baregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  44. CVE-2026-13397Unknown severity
    HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes
    Not scoredSource severity not reported
    CODECHILD/HTML::Baregeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  45. CVE-2026-47729Medium
    Squid: Memory disclosure in FTP gateway
    CVSS 6.5
    squid-cache/squidgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  46. CVE-2026-46621Critical
    Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
    CVSS 9.1
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  47. CVE-2026-46562Critical
    Yamcs: Remote Code Execution via Mission Database algorithm override
    CVSS 9.8
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  48. CVE-2026-44632Critical
    Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
    CVSS 9.1
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  49. CVE-2026-44596Medium
    Yamcs: No Rate Limiting on Authentication Endpoint
    CVSS 6.5
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  50. CVE-2026-44595Medium
    Yamcs: Unauthorized user enumeration via IAM API endpoints
    CVSS 4.3
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
Page 57 of 327
Previous5556575859Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard