1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 12:25 AM 16,365 active 1,443 known exploited

Catalog summary

16,365

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 12:25 AM 16,365 active 1,443 known exploited

Catalog summary

16,365

Active CVEs

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,301–4,350 of 16,365 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-5923Medium
    Poly Voice – Potential Unauthorized Modification of WebUI using CSRF Attack
    CVSS 6.0
    HP Inc./Poly CCX, HP Inc./Poly Edge E +1generic
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  2. CVE-2026-55471Critical
    HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
    CVSS 9.1
    ca.uhn.hapi.fhir:org.hl7.fhir.utilities, hapifhir/org.hl7.fhir.coregeneric · maven
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-55470High
    HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
    CVSS 7.5
    ca.uhn.hapi.fhir:org.hl7.fhir.convertors, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 +3generic · maven
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-44161High
    Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
    CVSS 7.2
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-44160High
    Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
    CVSS 7.5
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-44025High
    Fluentd: Exposure of Sensitive Information via Monitor Agent API
    CVSS 7.5
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-44024Critical
    Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
    CVSS 9.8
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-10037High
    Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal
    CVSS 8.8
    Canonical/Ubuntugeneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-55830High
    RestrictedPython guard hooks can be shadowed via positional-only arguments
    CVSS 8.3
    zopefoundation/RestrictedPythongeneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  10. CVE-2026-48492Medium
    Snipe-IT's selectlist visibility is too permissive
    CVSS 6.5
    grokability/snipe-it, snipe/snipe-itcomposer · generic
    PublishedJul 8, 2026First seen at HOL Jun 23, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  11. CVE-2026-55849High
    @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument
    CVSS 8.5
    @cyclonedx/cyclonedx-npm, CycloneDX/cyclonedx-node-npmgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-35211Medium
    OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS
    CVSS 6.5
    OpenCTI-Platform/openctigeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-35210High
    OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
    CVSS 7.1
    OpenCTI-Platform/openctigeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-54528High
    jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
    CVSS 7.1
    jupyterlab-git, jupyterlab/jupyterlab-gitgeneric · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-54527Critical
    JupyterLab Git: Stored XSS leading to RCE
    CVSS 9.3
    @jupyterlab/git, jupyterlab-git +2generic · npm · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-59818Medium
    etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
    CVSS 6.5
    etcd-io/etcdgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-58191Medium
    Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
    CVSS 6.5
    appium/appiumgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  18. CVE-2026-58192High
    Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin
    CVSS 8.6
    appium/appiumgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-15166Medium
    Stack-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  20. CVE-2026-57481Low
    Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change
    CVSS 2.3
    parse-community/parse-servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-57480High
    Parse Server: Denial of service via exponential-time processing of deeply nested query operators
    CVSS 8.7
    parse-community/parse-servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  22. CVE-2026-15174Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  23. CVE-2026-15172Medium
    Unchecked Input for Loop Condition in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  24. CVE-2026-15173Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 4.7
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  25. CVE-2026-15171Medium
    NULL Pointer Dereference in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  26. CVE-2026-15169Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  27. CVE-2026-15167High
    Stack-based Buffer Overflow in Wireshark
    CVSS 7.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  28. CVE-2026-55778Low
    Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
    CVSS 2.1
    parse-community/parse-server, parse-servergeneric · npm
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  29. CVE-2026-15170Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  30. CVE-2026-15165Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  31. CVE-2026-15163Medium
    Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  32. CVE-2026-15164Medium
    Heap-based Buffer Overflow in ciscodump
    CVSS 5.5
    Wireshark Foundation/ciscodumpgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  33. CVE-2025-12506Low
    Use of Incorrectly-Resolved Name or Reference in GitLab
    CVSS 3.5
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  34. CVE-2026-49866High
    libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
    CVSS 7.5
    @libp2p/gossipsub, libp2p/js-libp2pgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-6352Low
    Incorrect Authorization in GitLab
    CVSS 2.7
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  36. CVE-2026-6896High
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 8.7
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-7492Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  38. CVE-2026-8472Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-11827Medium
    Insufficiently Protected Credentials in GitLab
    CVSS 4.9
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  40. CVE-2026-13320High
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 7.3
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  41. CVE-2026-54590Medium
    AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion
    CVSS 5.9
    ronf/asyncsshgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-54591High
    AsyncSSH: SCP Path Traversal to Arbitrary File Write
    CVSS 8.1
    ronf/asyncsshgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-55542Medium
    Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
    CVSS 4.3
    grokability/snipe-it, snipe/snipe-itcomposer · generic
    PublishedJul 8, 2026First seen at HOL Jun 23, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-55206High
    py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
    CVSS 8.7
    miurahr/py7zr, py7zrgeneric · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-55195High
    py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
    CVSS 8.7
    miurahr/py7zr, py7zrgeneric · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-55596High
    Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
    CVSS 8.7
    udecode/plategeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-56669High
    Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
    CVSS 7.5
    elysiajs/elysiageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-58494Medium
    Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
    CVSS 6.5
    bytecodealliance/wasmtimegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-14896Medium
    Nomad vulnerable to cross-namespace host volume claim deletion
    CVSS 4.2
    HashiCorp/Nomad, HashiCorp/Nomad Enterprisegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-58208Medium
    NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
    CVSS 6.8
    nats-io/nats-servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
Page 87 of 328
Previous8586878889Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,301–4,350 of 16,365 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-5923Medium
    Poly Voice – Potential Unauthorized Modification of WebUI using CSRF Attack
    CVSS 6.0
    HP Inc./Poly CCX, HP Inc./Poly Edge E +1generic
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  2. CVE-2026-55471Critical
    HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
    CVSS 9.1
    ca.uhn.hapi.fhir:org.hl7.fhir.utilities, hapifhir/org.hl7.fhir.coregeneric · maven
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-55470High
    HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
    CVSS 7.5
    ca.uhn.hapi.fhir:org.hl7.fhir.convertors, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 +3generic · maven
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-44161High
    Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
    CVSS 7.2
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-44160High
    Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
    CVSS 7.5
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  6. CVE-2026-44025High
    Fluentd: Exposure of Sensitive Information via Monitor Agent API
    CVSS 7.5
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-44024Critical
    Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
    CVSS 9.8
    fluent/fluentd, fluentdgeneric · rubygems
    PublishedJul 8, 2026First seen at HOL Jun 26, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-10037High
    Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal
    CVSS 8.8
    Canonical/Ubuntugeneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  9. CVE-2026-55830High
    RestrictedPython guard hooks can be shadowed via positional-only arguments
    CVSS 8.3
    zopefoundation/RestrictedPythongeneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  10. CVE-2026-48492Medium
    Snipe-IT's selectlist visibility is too permissive
    CVSS 6.5
    grokability/snipe-it, snipe/snipe-itcomposer · generic
    PublishedJul 8, 2026First seen at HOL Jun 23, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  11. CVE-2026-55849High
    @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument
    CVSS 8.5
    @cyclonedx/cyclonedx-npm, CycloneDX/cyclonedx-node-npmgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-35211Medium
    OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS
    CVSS 6.5
    OpenCTI-Platform/openctigeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-35210High
    OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
    CVSS 7.1
    OpenCTI-Platform/openctigeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-54528High
    jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
    CVSS 7.1
    jupyterlab-git, jupyterlab/jupyterlab-gitgeneric · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-54527Critical
    JupyterLab Git: Stored XSS leading to RCE
    CVSS 9.3
    @jupyterlab/git, jupyterlab-git +2generic · npm · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-59818Medium
    etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
    CVSS 6.5
    etcd-io/etcdgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-58191Medium
    Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
    CVSS 6.5
    appium/appiumgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  18. CVE-2026-58192High
    Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin
    CVSS 8.6
    appium/appiumgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-15166Medium
    Stack-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  20. CVE-2026-57481Low
    Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change
    CVSS 2.3
    parse-community/parse-servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-57480High
    Parse Server: Denial of service via exponential-time processing of deeply nested query operators
    CVSS 8.7
    parse-community/parse-servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  22. CVE-2026-15174Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  23. CVE-2026-15172Medium
    Unchecked Input for Loop Condition in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  24. CVE-2026-15173Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 4.7
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  25. CVE-2026-15171Medium
    NULL Pointer Dereference in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  26. CVE-2026-15169Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  27. CVE-2026-15167High
    Stack-based Buffer Overflow in Wireshark
    CVSS 7.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  28. CVE-2026-55778Low
    Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
    CVSS 2.1
    parse-community/parse-server, parse-servergeneric · npm
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  29. CVE-2026-15170Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  30. CVE-2026-15165Medium
    Heap-based Buffer Overflow in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  31. CVE-2026-15163Medium
    Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
    CVSS 5.5
    Wireshark Foundation/Wiresharkgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  32. CVE-2026-15164Medium
    Heap-based Buffer Overflow in ciscodump
    CVSS 5.5
    Wireshark Foundation/ciscodumpgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  33. CVE-2025-12506Low
    Use of Incorrectly-Resolved Name or Reference in GitLab
    CVSS 3.5
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  34. CVE-2026-49866High
    libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
    CVSS 7.5
    @libp2p/gossipsub, libp2p/js-libp2pgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-6352Low
    Incorrect Authorization in GitLab
    CVSS 2.7
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  36. CVE-2026-6896High
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 8.7
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-7492Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  38. CVE-2026-8472Medium
    Missing Authorization in GitLab
    CVSS 4.3
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-11827Medium
    Insufficiently Protected Credentials in GitLab
    CVSS 4.9
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  40. CVE-2026-13320High
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    CVSS 7.3
    GitLab/GitLabgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  41. CVE-2026-54590Medium
    AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion
    CVSS 5.9
    ronf/asyncsshgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-54591High
    AsyncSSH: SCP Path Traversal to Arbitrary File Write
    CVSS 8.1
    ronf/asyncsshgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-55542Medium
    Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
    CVSS 4.3
    grokability/snipe-it, snipe/snipe-itcomposer · generic
    PublishedJul 8, 2026First seen at HOL Jun 23, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-55206High
    py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
    CVSS 8.7
    miurahr/py7zr, py7zrgeneric · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-55195High
    py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
    CVSS 8.7
    miurahr/py7zr, py7zrgeneric · pip
    PublishedJul 8, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-55596High
    Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
    CVSS 8.7
    udecode/plategeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-56669High
    Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
    CVSS 7.5
    elysiajs/elysiageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-58494Medium
    Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
    CVSS 6.5
    bytecodealliance/wasmtimegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-14896Medium
    Nomad vulnerable to cross-namespace host volume claim deletion
    CVSS 4.2
    HashiCorp/Nomad, HashiCorp/Nomad Enterprisegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-58208Medium
    NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
    CVSS 6.8
    nats-io/nats-servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
Page 87 of 328
Previous8586878889Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard