1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:25 AM 16,326 active 1,443 known exploited

Catalog summary

16,326

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:25 AM 16,326 active 1,443 known exploited

Catalog summary

16,326

Active CVEs

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,001–3,050 of 16,326 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-47158High
    Vaultwarden: CSRF in SSO Authorization Flow
    CVSS 8.3
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-46709High
    Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)
    CVSS 7.8
    Eugeny/tabbygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  3. CVE-2026-41580Medium
    Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)
    CVSS 6.1
    Stirling-Tools/Stirling-PDFgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-33213Medium
    Redash: Open redirect vulnerability in post-login redirect handling
    CVSS 6.1
    getredash/redashgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-42533High
    NGINX Map directive and Regex matching vulnerability
    CVSS 8.1
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  6. CVE-2026-43637Critical
    Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
    CVSS 9.1
    PreferredAI/cornacgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  7. CVE-2026-46459Medium
    Missing Authorization in ICU Scandinavia Boomerang
    CVSS 5.3
    ICU Scandinavia/Boomeranggeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2026-46458High
    Credential exposure in ICU Scandinavia Boomerang
    CVSS 7.1
    ICU Scandinavia/Boomeranggeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  9. CVE-2026-15779Medium
    Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-15809High
    Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  11. CVE-2026-40633High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/PowerScale OneFSgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-35152High
    Apache Fineract: SQL injection in runreports endpoint
    CVSS 8.8
    Apache Software Foundation/Apache Fineractgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-15804High
    MetaGuru|HCM - SQL Injection
    CVSS 8.8
    MetaGuru/HCMgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2026-15583High
    SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
    CVSS 8.6
    Grafana/Grafana MCP Servergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026View HOL analysis
  15. CVE-2026-14251High
    Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clusterrole/role cases enables potential privilege escalation and dos
    CVSS 7.7
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  16. CVE-2026-12512High
    Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
    CVSS 8.6
    Unknown/Quotes llamageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2026-12281High
    Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
    CVSS 8.1
    Unknown/Shibbolethgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  18. CVE-2026-11580Medium
    Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
    CVSS 5.5
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-11579Medium
    Kali Forms < 2.4.17 - Unauthenticated Media Upload
    CVSS 5.3
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-42936High
    CISA ADP Vulnrichment
    CVSS 8.4
    SBI SECURITIES Co.,Ltd./HYPER SBI 2generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  21. CVE-2026-13385Critical
    CISA ADP Vulnrichment
    CVSS 9.5
    ASUS/Routergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026View HOL analysis
  22. CVE-2026-15029High
    CISA ADP Vulnrichment
    CVSS 8.4
    ASUS/Business Manager, ASUS/System Control Interface +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-15030Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    ASUS/Business Manager, ASUS/System Control Interface +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-13585High
    CISA ADP Vulnrichment
    CVSS 8.2
    ASUS/Business Manager, ASUS/System Control Interface +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  25. CVE-2026-11851Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    ASUS/Routergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-13230Medium
    Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71
    CVSS 5.3
    TP-Link Systems Inc./Kasa EC70 v4, TP-Link Systems Inc./Kasa EC71 v4generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2025-65720Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  28. CVE-2026-26718Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  29. CVE-2026-26719Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  30. CVE-2026-30618Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  31. CVE-2026-30623Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-36590High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  33. CVE-2026-38752High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  34. CVE-2026-38753High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  35. CVE-2026-38754High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 22, 2026View HOL analysis
  36. CVE-2026-38755High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  37. CVE-2026-38974Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-15753Medium
    zhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side
    CVSS 5.4
    zhinianboke/xianyu-auto-replygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-15752High
    zhinianboke xianyu-auto-reply Backend User Endpoint users authorization
    CVSS 7.3
    zhinianboke/xianyu-auto-replygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-15751Medium
    mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workflow.md execute path traversal
    CVSS 5.3
    mastergo-design/mastergo-magic-mcpgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-42049High
    jadx: RCE Via Groovy Code Injection in Gradle Export
    CVSS 8.4
    skylot/jadxgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-21840Low
    HCL BigFix Platform is affected by a user enumeration vulnerability
    CVSS 3.1
    HCLSoftware/HCL BigFix Platformgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-45363Critical
    `jwt` (Ruby gem) - empty-key HMAC bypass
    CVSS 9.1
    jwt, jwt/ruby-jwtgeneric · rubygems
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-15750Medium
    mastergo-design mastergo-magic-mcp mcp__getComponentLink get-component-link.ts z.string server-side request forgery
    CVSS 6.3
    mastergo-design/mastergo-magic-mcpgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-46637Medium
    Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
    CVSS 5.4
    twig/cssinliner-extra, twig/markdown-extra +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  46. CVE-2026-46638High
    Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
    CVSS 8.1
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  47. CVE-2026-46629Medium
    Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
    CVSS 6.5
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  48. CVE-2026-46628Medium
    Twig: The `spaceless` filter implicitly marks its output as safe
    CVSS 5.4
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  49. CVE-2026-46634Critical
    Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
    CVSS 9.8
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026View HOL analysis
  50. CVE-2026-46627Medium
    Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
    CVSS 6.5
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
Page 61 of 327
Previous5960616263Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,001–3,050 of 16,326 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-47158High
    Vaultwarden: CSRF in SSO Authorization Flow
    CVSS 8.3
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  2. CVE-2026-46709High
    Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)
    CVSS 7.8
    Eugeny/tabbygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  3. CVE-2026-41580Medium
    Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)
    CVSS 6.1
    Stirling-Tools/Stirling-PDFgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  4. CVE-2026-33213Medium
    Redash: Open redirect vulnerability in post-login redirect handling
    CVSS 6.1
    getredash/redashgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  5. CVE-2026-42533High
    NGINX Map directive and Regex matching vulnerability
    CVSS 8.1
    F5/NGINX Open Source, F5/NGINX Plusgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  6. CVE-2026-43637Critical
    Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
    CVSS 9.1
    PreferredAI/cornacgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  7. CVE-2026-46459Medium
    Missing Authorization in ICU Scandinavia Boomerang
    CVSS 5.3
    ICU Scandinavia/Boomeranggeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  8. CVE-2026-46458High
    Credential exposure in ICU Scandinavia Boomerang
    CVSS 7.1
    ICU Scandinavia/Boomeranggeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  9. CVE-2026-15779Medium
    Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation
    CVSS 6.1
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-15809High
    Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  11. CVE-2026-40633High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/PowerScale OneFSgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  12. CVE-2026-35152High
    Apache Fineract: SQL injection in runreports endpoint
    CVSS 8.8
    Apache Software Foundation/Apache Fineractgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-15804High
    MetaGuru|HCM - SQL Injection
    CVSS 8.8
    MetaGuru/HCMgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  14. CVE-2026-15583High
    SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
    CVSS 8.6
    Grafana/Grafana MCP Servergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026View HOL analysis
  15. CVE-2026-14251High
    Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clusterrole/role cases enables potential privilege escalation and dos
    CVSS 7.7
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  16. CVE-2026-12512High
    Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
    CVSS 8.6
    Unknown/Quotes llamageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  17. CVE-2026-12281High
    Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
    CVSS 8.1
    Unknown/Shibbolethgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  18. CVE-2026-11580Medium
    Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
    CVSS 5.5
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  19. CVE-2026-11579Medium
    Kali Forms < 2.4.17 - Unauthenticated Media Upload
    CVSS 5.3
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  20. CVE-2026-42936High
    CISA ADP Vulnrichment
    CVSS 8.4
    SBI SECURITIES Co.,Ltd./HYPER SBI 2generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  21. CVE-2026-13385Critical
    CISA ADP Vulnrichment
    CVSS 9.5
    ASUS/Routergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026View HOL analysis
  22. CVE-2026-15029High
    CISA ADP Vulnrichment
    CVSS 8.4
    ASUS/Business Manager, ASUS/System Control Interface +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-15030Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    ASUS/Business Manager, ASUS/System Control Interface +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-13585High
    CISA ADP Vulnrichment
    CVSS 8.2
    ASUS/Business Manager, ASUS/System Control Interface +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  25. CVE-2026-11851Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    ASUS/Routergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-13230Medium
    Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71
    CVSS 5.3
    TP-Link Systems Inc./Kasa EC70 v4, TP-Link Systems Inc./Kasa EC71 v4generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2025-65720Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  28. CVE-2026-26718Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  29. CVE-2026-26719Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  30. CVE-2026-30618Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  31. CVE-2026-30623Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-36590High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  33. CVE-2026-38752High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  34. CVE-2026-38753High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  35. CVE-2026-38754High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 22, 2026View HOL analysis
  36. CVE-2026-38755High
    CISA ADP Vulnrichment
    CVSS 7.5
    BusyBox/BusyBoxgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  37. CVE-2026-38974Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    n/a/n/ageneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  38. CVE-2026-15753Medium
    zhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side
    CVSS 5.4
    zhinianboke/xianyu-auto-replygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-15752High
    zhinianboke xianyu-auto-reply Backend User Endpoint users authorization
    CVSS 7.3
    zhinianboke/xianyu-auto-replygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-15751Medium
    mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workflow.md execute path traversal
    CVSS 5.3
    mastergo-design/mastergo-magic-mcpgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-42049High
    jadx: RCE Via Groovy Code Injection in Gradle Export
    CVSS 8.4
    skylot/jadxgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-21840Low
    HCL BigFix Platform is affected by a user enumeration vulnerability
    CVSS 3.1
    HCLSoftware/HCL BigFix Platformgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-45363Critical
    `jwt` (Ruby gem) - empty-key HMAC bypass
    CVSS 9.1
    jwt, jwt/ruby-jwtgeneric · rubygems
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  44. CVE-2026-15750Medium
    mastergo-design mastergo-magic-mcp mcp__getComponentLink get-component-link.ts z.string server-side request forgery
    CVSS 6.3
    mastergo-design/mastergo-magic-mcpgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-46637Medium
    Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
    CVSS 5.4
    twig/cssinliner-extra, twig/markdown-extra +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  46. CVE-2026-46638High
    Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
    CVSS 8.1
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  47. CVE-2026-46629Medium
    Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
    CVSS 6.5
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  48. CVE-2026-46628Medium
    Twig: The `spaceless` filter implicitly marks its output as safe
    CVSS 5.4
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  49. CVE-2026-46634Critical
    Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
    CVSS 9.8
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 29, 2026View HOL analysis
  50. CVE-2026-46627Medium
    Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
    CVSS 6.5
    twigphp/Twiggeneric
    PublishedJul 14, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
Page 61 of 327
Previous5960616263Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard