HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 27, 2026, 6:04 AM 40,408 active 1,502 known exploited

Catalog summary

40,408

Active CVEs

20,493

Critical + high

1,502

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,251–3,300 of 40,408 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-93568High
    Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connect requests are downgraded as regular connect requests
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  2. CVE-2025-13882Medium
    Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.
    CVSS 5.3
    IBM/Sterling Partner Engagement Manager Essentials Edition, IBM/Sterling Partner Engagement Manager Standard Editiongeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  3. CVE-2026-93576High
    Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)
    CVSS 7.5
    Red Hat/jboss-eap-7/eap74-els-openjdk11-openshift-rhel8, Red Hat/jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 +2generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 25, 2026View HOL analysis
  4. CVE-2025-1350Medium
    Multiple vulnerabilities in IBM Controller
    CVSS 5.3
    IBM/Controllergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  5. CVE-2026-16515Medium
    ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack
    CVSS 4.7
    zephyrproject/zephyrgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  6. CVE-2026-16514Medium
    Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved
    CVSS 4.3
    zephyrproject/zephyrgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  7. CVE-2026-16512Low
    Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames
    CVSS 3.1
    zephyrproject/zephyrgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  8. CVE-2024-56344Medium
    IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities
    CVSS 5.9
    IBM/Cognos Analyticsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026View HOL analysis
  9. CVE-2026-85511Medium
    Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2
    CVSS 4.2
    Red Hat/redhat-datagrid-server.zip, Red Hat/wildfly-elytron-realm-tokengeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 25, 2026View HOL analysis
  10. CVE-2026-93569High
    Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  11. CVE-2026-77929High
    ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint
    CVSS 8.7
    MacWarrior/clipbucket-v5generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 26, 2026 Fix availableView HOL analysis
  12. CVE-2026-93567High
    Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authority
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  13. CVE-2026-93660High
    SQLBot through 1.10.1 Improper Access Control via Dashboard Update
    CVSS 7.1
    dataease/SQLBotgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  14. CVE-2026-93659Unknown severity
    Concrete CMS Community Store before 2.7.8 Stored XSS
    Not scoredSource severity not reported
    concretecms-community-store/community_storegeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  15. CVE-2026-93658Unknown severity
    uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid
    Not scoredSource severity not reported
    uutils/coreutilsgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  16. CVE-2026-93657Unknown severity
    hickory-resolver before 0.26.2 DNSSEC Validation Bypass
    Not scoredSource severity not reported
    hickory-dns/hickory-resolvergeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  17. CVE-2026-77928High
    ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint
    CVSS 7.1
    MacWarrior/clipbucket-v5generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 26, 2026 Fix availableView HOL analysis
  18. CVE-2026-93676Low
    Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks
    CVSS 3.2
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  19. CVE-2026-10832Medium
    Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload
    CVSS 5.9
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  20. CVE-2026-93566Medium
    Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line
    CVSS 6.5
    Red Hat/netty-codec-httpgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 24, 2026View HOL analysis
  21. CVE-2026-93565High
    Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  22. CVE-2026-77927High
    ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint
    CVSS 7.1
    MacWarrior/clipbucket-v5generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 26, 2026 Fix availableView HOL analysis
  23. CVE-2026-93505Low
    SveltyCMS SVG Media Upload media-service.server.ts cross site scripting
    CVSS 3.5
    n/a/SveltyCMSgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  24. CVE-2026-93653Medium
    Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service)
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  25. CVE-2026-93564High
    Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881)
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  26. CVE-2026-93558High
    Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  27. CVE-2026-25684Medium
    File Type Control rule bypass
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  28. CVE-2026-93019Critical
    Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026View HOL analysis
  29. CVE-2026-93018Medium
    Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  30. CVE-2026-62282Medium
    OpenCVE: Server-Side Request Forgery (SSRF) in notifications
    CVSS 6.5
    opencve, opencve/opencvegeneric · pip · pypi
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  31. CVE-2026-93560Unknown severity
    Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos
    Not scoredSource severity not reported
    Affected software not mappedEcosystem not listed
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026View HOL analysis
  32. CVE-2026-93606Critical
    vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species
    CVSS 10.0
    patriksimek/vm2generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  33. CVE-2026-93605Unknown severity
    vm2 NodeVM before 3.12.1 Remote Code Execution via child_process
    Not scoredSource severity not reported
    patriksimek/vm2generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  34. CVE-2026-93604High
    vm2 3.11.8 Sandbox Escape via crypto.setFips
    CVSS 7.2
    patriksimek/vm2generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  35. CVE-2026-93603Unknown severity
    vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function
    Not scoredSource severity not reported
    patriksimek/vm2generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  36. CVE-2026-93602Medium
    rustls-webpki before 0.103.10 CRL Revocation Check Bypass
    CVSS 4.4
    rustls-webpki, rustls/webpkicrates.io · generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  37. CVE-2026-93601Low
    rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass
    CVSS 2.2
    rustls-webpki, rustls/webpkicrates.io · generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  38. CVE-2026-93600Low
    rustls webpki Name Constraints URI Validation Bypass
    CVSS 2.2
    rustls-webpki, rustls/webpkicrates.io · generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  39. CVE-2026-93599High
    rustls-webpki before 0.103.13 Panic via empty BIT STRING
    CVSS 7.5
    rustls-webpki, rustls/webpkicrates.io · generic
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 19, 2026 Fix availableView HOL analysis
  40. CVE-2026-93598Unknown severity
    ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle
    Not scoredSource severity not reported
    ArcadeData/arcadedbgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  41. CVE-2026-93597High
    ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses
    CVSS 7.7
    ArcadeData/arcadedbgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  42. CVE-2026-93596Medium
    ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect
    CVSS 4.3
    ArcadeData/arcadedbgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  43. CVE-2026-93595Unknown severity
    ArcadeDB before 26.9.1 ACL Bypass via query_database Tool
    Not scoredSource severity not reported
    ArcadeData/arcadedbgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  44. CVE-2026-93594High
    ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries
    CVSS 8.1
    ArcadeData/arcadedbgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  45. CVE-2026-93593Unknown severity
    ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission
    Not scoredSource severity not reported
    ArcadeData/arcadedbgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
  46. CVE-2026-93592Unknown severity
    vLLM before 0.28.0 Denial of Service via negative token ID
    Not scoredSource severity not reported
    vllm-project/vllmgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  47. CVE-2026-93591High
    SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go
    CVSS 7.6
    siyuan-note/siyuangeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  48. CVE-2026-93590Unknown severity
    ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder
    Not scoredSource severity not reported
    ImageMagick/ImageMagickgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 21, 2026 Fix availableView HOL analysis
  49. CVE-2026-93589Unknown severity
    ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder
    Not scoredSource severity not reported
    ImageMagick/ImageMagickgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 18, 2026 Fix availableView HOL analysis
  50. CVE-2026-93588Unknown severity
    ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM
    Not scoredSource severity not reported
    ImageMagick/ImageMagickgeneric
    PublishedSep 18, 2026First seen at HOL Sep 18, 2026Updated Sep 22, 2026 Fix availableView HOL analysis
Page 66 of 809
Previous6465666768Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard