1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 1:23 PM 16,329 active 1,443 known exploited

Catalog summary

16,329

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 1:23 PM 16,329 active 1,443 known exploited

Catalog summary

16,329

Active CVEs

8,450

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,151–3,200 of 16,329 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-45072Medium
    Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
    CVSS 5.4
    symfony/symfony, symfony/twig-bridge +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  2. CVE-2026-15642Low
    CISA ADP Vulnrichment
    CVSS 3.3
    Devolutions/Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  3. CVE-2026-15641High
    CISA ADP Vulnrichment
    CVSS 7.1
    Devolutions/Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-15637High
    CISA ADP Vulnrichment
    CVSS 7.5
    Devolutions/Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  5. CVE-2026-45756High
    Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
    CVSS 7.5
    symfony/json-path, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  6. CVE-2026-45066Medium
    Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
    CVSS 6.1
    symfony/html-sanitizer, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  7. CVE-2026-45074High
    Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
    CVSS 8.1
    symfony/security-http, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-47967High
    Audition | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Auditiongeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-47969Medium
    Audition | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/Auditiongeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-47968High
    Audition | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Auditiongeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-45077High
    Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
    CVSS 8.6
    symfony/monolog-bridge, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-15757Medium
    Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router
    CVSS 6.3
    NETGEAR/DGND3700v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2026-45065Medium
    Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
    CVSS 6.1
    symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-4018Medium
    TOCTOU race condition in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
    CVSS 6.4
    BlackBerry Ltd./QNX OS for Medical, BlackBerry Ltd/QNX OS for Safety +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-4017High
    Buffer overflow in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
    CVSS 7.4
    BlackBerry Ltd./QNX OS for Medical, BlackBerry Ltd/QNX OS for Safety +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-0515Medium
    Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
    CVSS 6.2
    BlackBerry Ltd./QNX OS for Medical, BlackBerry Ltd/QNX OS for Safety +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-15747Critical
    Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
    CVSS 9.1
    SRI/Mojoliciousgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  18. CVE-2026-15429Medium
    Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v
    CVSS 5.1
    TP-Link Systems Inc./Archer VX1800v v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-15428High
    OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
    CVSS 8.5
    TP-Link Systems Inc./Archer VX1800v v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-15427High
    OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
    CVSS 8.6
    TP-Link Systems Inc./Archer VX1800v v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-15703High
    SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-14646Medium
    Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect
    CVSS 4.9
    Sonatype/Nexus Repository 3generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-15702Medium
    tamagui config.ts updateConfig prototype pollution
    CVSS 6.3
    n/a/tamaguigeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-14645Medium
    Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability
    CVSS 5.1
    Sonatype/Nexus Repository 3generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-15701Critical
    Totolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow
    CVSS 9.8
    Totolink/NR1800Xgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-15700Medium
    DedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal
    CVSS 4.7
    n/a/DedeCMSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-14504High
    Nexus Repository 3 - Authorization Bypass in Component Upload API
    CVSS 8.2
    Sonatype/Nexus Repository 3generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-12523High
    Resource exhaustion in quiche HTTP/3 and QPACK layers
    CVSS 7.5
    Cloudflare/quichegeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  29. CVE-2026-15392High
    DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
    CVSS 7.7
    HMBRAND/DBD::Filegeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-11403High
    Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
    CVSS 8.7
    Sonatype/Nexus Repository Managergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2025-43892Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Fortinet/FortiOSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-15697Medium
    svgdotjs svg.js npm Package API EventTarget.on prototype pollution
    CVSS 6.3
    svgdotjs/svg.jsgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2025-53379High
    CISA ADP Vulnrichment
    CVSS 7.5
    Fortinet/FortiAuthenticatorgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 22, 2026View HOL analysis
  34. CVE-2026-10670Medium
    User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier
    CVSS 5.5
    zephyrproject/zephyrgeneric
    PublishedJul 14, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-15695High
    Tenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-14903High
    CISA ADP Vulnrichment
    CVSS 7.7
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-14902Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-15736High
    Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemy
    CVSS 8.3
    Snowflake/Snowflake SQLAlchemygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  39. CVE-2026-15693High
    Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  40. CVE-2026-10577Critical
    Rockwell Automation 1715 Redundant IO – Access Control Vulnerability
    CVSS 10.0
    Rockwell Auotmation/1715 EtherNet/IP Communications Modulegeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  41. CVE-2026-15305Medium
    TYPO3 CMS - Unrestricted File Upload in Form Framework
    CVSS 6.3
    TYPO3/TYPO3 CMSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-12588Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Trellix/Trellix HX Consolegeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  43. CVE-2026-15692High
    Tenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  44. CVE-2026-15719Medium
    Site isolation issue in the DOM: Navigation component
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 22, 2026View HOL analysis
  45. CVE-2026-15718Medium
    Invalid pointer in the JavaScript: WebAssembly component
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 22, 2026View HOL analysis
  46. CVE-2026-15691High
    Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-15690Low
    open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference
    CVSS 3.1
    n/a/open62541generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  48. CVE-2026-9341Medium
    Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter
    CVSS 4.3
    kodezen/Academy LMSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  49. CVE-2026-15389High
    Inadequate access control in Sesame Time session management
    CVSS 8.7
    Sesame Time/Sesame Timegeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-3014Critical
    Remote Code Execution by administrative user on the Management Server
    CVSS 9.1
    Milestone Systems/XProtect Management Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 16, 2026View HOL analysis
Page 64 of 327
Previous6263646566Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,450

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,151–3,200 of 16,329 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-45072Medium
    Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
    CVSS 5.4
    symfony/symfony, symfony/twig-bridge +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  2. CVE-2026-15642Low
    CISA ADP Vulnrichment
    CVSS 3.3
    Devolutions/Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  3. CVE-2026-15641High
    CISA ADP Vulnrichment
    CVSS 7.1
    Devolutions/Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-15637High
    CISA ADP Vulnrichment
    CVSS 7.5
    Devolutions/Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  5. CVE-2026-45756High
    Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
    CVSS 7.5
    symfony/json-path, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  6. CVE-2026-45066Medium
    Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
    CVSS 6.1
    symfony/html-sanitizer, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  7. CVE-2026-45074High
    Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
    CVSS 8.1
    symfony/security-http, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  8. CVE-2026-47967High
    Audition | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Auditiongeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  9. CVE-2026-47969Medium
    Audition | Out-of-bounds Read (CWE-125)
    CVSS 5.5
    Adobe/Auditiongeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  10. CVE-2026-47968High
    Audition | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Auditiongeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  11. CVE-2026-45077High
    Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
    CVSS 8.6
    symfony/monolog-bridge, symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  12. CVE-2026-15757Medium
    Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router
    CVSS 6.3
    NETGEAR/DGND3700v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2026-45065Medium
    Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
    CVSS 6.1
    symfony/symfonygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2026-4018Medium
    TOCTOU race condition in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
    CVSS 6.4
    BlackBerry Ltd./QNX OS for Medical, BlackBerry Ltd/QNX OS for Safety +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  15. CVE-2026-4017High
    Buffer overflow in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
    CVSS 7.4
    BlackBerry Ltd./QNX OS for Medical, BlackBerry Ltd/QNX OS for Safety +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  16. CVE-2026-0515Medium
    Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
    CVSS 6.2
    BlackBerry Ltd./QNX OS for Medical, BlackBerry Ltd/QNX OS for Safety +1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2026-15747Critical
    Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
    CVSS 9.1
    SRI/Mojoliciousgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  18. CVE-2026-15429Medium
    Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v
    CVSS 5.1
    TP-Link Systems Inc./Archer VX1800v v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-15428High
    OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
    CVSS 8.5
    TP-Link Systems Inc./Archer VX1800v v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-15427High
    OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
    CVSS 8.6
    TP-Link Systems Inc./Archer VX1800v v1generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-15703High
    SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-14646Medium
    Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect
    CVSS 4.9
    Sonatype/Nexus Repository 3generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  23. CVE-2026-15702Medium
    tamagui config.ts updateConfig prototype pollution
    CVSS 6.3
    n/a/tamaguigeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-14645Medium
    Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability
    CVSS 5.1
    Sonatype/Nexus Repository 3generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  25. CVE-2026-15701Critical
    Totolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow
    CVSS 9.8
    Totolink/NR1800Xgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  26. CVE-2026-15700Medium
    DedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal
    CVSS 4.7
    n/a/DedeCMSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  27. CVE-2026-14504High
    Nexus Repository 3 - Authorization Bypass in Component Upload API
    CVSS 8.2
    Sonatype/Nexus Repository 3generic
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-12523High
    Resource exhaustion in quiche HTTP/3 and QPACK layers
    CVSS 7.5
    Cloudflare/quichegeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  29. CVE-2026-15392High
    DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
    CVSS 7.7
    HMBRAND/DBD::Filegeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  30. CVE-2026-11403High
    Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
    CVSS 8.7
    Sonatype/Nexus Repository Managergeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  31. CVE-2025-43892Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Fortinet/FortiOSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-15697Medium
    svgdotjs svg.js npm Package API EventTarget.on prototype pollution
    CVSS 6.3
    svgdotjs/svg.jsgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2025-53379High
    CISA ADP Vulnrichment
    CVSS 7.5
    Fortinet/FortiAuthenticatorgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 22, 2026View HOL analysis
  34. CVE-2026-10670Medium
    User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier
    CVSS 5.5
    zephyrproject/zephyrgeneric
    PublishedJul 14, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-15695High
    Tenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-14903High
    CISA ADP Vulnrichment
    CVSS 7.7
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-14902Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-15736High
    Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemy
    CVSS 8.3
    Snowflake/Snowflake SQLAlchemygeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  39. CVE-2026-15693High
    Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  40. CVE-2026-10577Critical
    Rockwell Automation 1715 Redundant IO – Access Control Vulnerability
    CVSS 10.0
    Rockwell Auotmation/1715 EtherNet/IP Communications Modulegeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  41. CVE-2026-15305Medium
    TYPO3 CMS - Unrestricted File Upload in Form Framework
    CVSS 6.3
    TYPO3/TYPO3 CMSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  42. CVE-2026-12588Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Trellix/Trellix HX Consolegeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  43. CVE-2026-15692High
    Tenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  44. CVE-2026-15719Medium
    Site isolation issue in the DOM: Navigation component
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 22, 2026View HOL analysis
  45. CVE-2026-15718Medium
    Invalid pointer in the JavaScript: WebAssembly component
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 22, 2026View HOL analysis
  46. CVE-2026-15691High
    Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow
    CVSS 8.8
    Tenda/BE12 Progeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-15690Low
    open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference
    CVSS 3.1
    n/a/open62541generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  48. CVE-2026-9341Medium
    Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter
    CVSS 4.3
    kodezen/Academy LMSgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  49. CVE-2026-15389High
    Inadequate access control in Sesame Time session management
    CVSS 8.7
    Sesame Time/Sesame Timegeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  50. CVE-2026-3014Critical
    Remote Code Execution by administrative user on the Management Server
    CVSS 9.1
    Milestone Systems/XProtect Management Servergeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 16, 2026View HOL analysis
Page 64 of 327
Previous6263646566Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard