1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:40 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:40 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

8,462

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,601–4,650 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-36027Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  2. CVE-2026-36028Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-39178Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-39179Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-50812Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  6. CVE-2026-50813Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-51535High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-52200Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  9. CVE-2026-55428High
    Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
    CVSS 8.2
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-55427High
    Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
    CVSS 8.3
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-55079Medium
    Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
    CVSS 4.9
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-55078Medium
    Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
    CVSS 6.5
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-55077High
    Coder: User-admin role can reset owner account password
    CVSS 7.2
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  14. CVE-2026-55076High
    Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
    CVSS 7.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-14895High
    String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
    CVSS 7.5
    BAKERSCOT/String::Utilgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  16. CVE-2026-14740Critical
    DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
    CVSS 9.1
    HMBRAND/DBIgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  17. CVE-2026-14739Critical
    DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
    CVSS 9.8
    HMBRAND/DBIgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-14380High
    DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
    CVSS 8.8
    HMBRAND/DBIgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  19. CVE-2026-49033High
    Stack-Based Buffer Overflow in Labcenter Proteus
    CVSS 7.8
    Labcenter/Proteusgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-42958High
    Use After Free in Labcenter Proteus
    CVSS 7.8
    Labcenter/Proteusgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  21. CVE-2026-42953High
    Out-of-bounds write in Labcenter Proteus
    CVSS 8.4
    Labcenter/Proteusgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-55075High
    Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
    CVSS 7.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-54698Medium
    Hasura: Row-level authorization bypass on table computed fields
    CVSS 6.0
    hasura/graphql-enginegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  24. CVE-2026-54602High
    FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord
    CVSS 7.1
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  25. CVE-2026-54607High
    FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)
    CVSS 7.7
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2026-55418High
    FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)
    CVSS 8.6
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  27. CVE-2026-54601Medium
    FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion
    CVSS 6.3
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-58266Medium
    Anki: User scripts in iframes have access to the internal Anki API
    CVSS 6.5
    ankitects/anki, aqtgeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-59153High
    Anki's local HTTP server does not sufficiently validate requests
    CVSS 2.1
    ankitects/anki, aqtgeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jun 19, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  30. CVE-2026-46354Critical
    Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
    CVSS 9.1
    coder/codergeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-55490Medium
    OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service
    CVSS 6.5
    openwrt/openwrtgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  32. CVE-2026-28378Low
    Cross-Organization Public Dashboard Deletion via Missing Org Isolation
    CVSS 3.1
    Grafana/Grafana Enterprise, Grafana/Grafana OSSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 29, 2026View HOL analysis
  33. CVE-2026-45796Medium
    Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint
    CVSS 6.5
    coder/codergeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  34. CVE-2026-55408High
    Koodo Reader: Remote code execution via malicious epub file
    CVSS 8.4
    koodo-reader/koodo-readergeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  35. CVE-2026-49229High
    Actual: Disabled OpenID users keep access through existing session tokens
    CVSS 8.3
    @actual-app/sync-server, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 23, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  36. CVE-2026-50179Medium
    Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
    CVSS 4.2
    @actual-app/web, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 23, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-46700Medium
    Actual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
    CVSS 4.3
    @actual-app/sync-server, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-46672Medium
    Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper
    CVSS 4.6
    @actual-app/cli, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-50007High
    Actual: Shared users can perform owner-only file management actions
    CVSS 7.2
    actualbudget/actualgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  40. CVE-2026-49471High
    Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
    CVSS 8.3
    oraios/serena, serena-agentgeneric · pip
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  41. CVE-2026-55592Low
    Dashy: XSS in workspace url parameter
    CVSS 3.9
    lissy93/dashygeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  42. CVE-2026-53511High
    calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
    CVSS 8.5
    kovidgoyal/calibregeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-53935Medium
    CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
    CVSS 6.9
    cilium/cilium, github.com/cilium/ciliumgeneric · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-50530High
    DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets
    CVSS 7.1
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  45. CVE-2026-50529High
    DataEase: Link Token Leakage Prior to Share Password/Ticket Validation
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  46. CVE-2026-55647Medium
    DataEase: authenticated stored XSS in the dashboard text components
    CVSS 5.1
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  47. CVE-2026-55635High
    DataEase: Authenticated SQL Injection in Chart Quota Filters
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-57172High
    DataEase: Hardcoded JWT Signing Secret in ShareLink
    CVSS 8.3
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  49. CVE-2026-53751High
    DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-53730High
    DataEase: Unauthorized Access to Engine Database via previewSql Endpoint
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
Page 93 of 328
Previous9192939495Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,462

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,601–4,650 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-36027Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  2. CVE-2026-36028Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-39178Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-39179Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-50812Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  6. CVE-2026-50813Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-51535High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-52200Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  9. CVE-2026-55428High
    Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
    CVSS 8.2
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-55427High
    Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
    CVSS 8.3
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-55079Medium
    Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
    CVSS 4.9
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-55078Medium
    Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
    CVSS 6.5
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-55077High
    Coder: User-admin role can reset owner account password
    CVSS 7.2
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  14. CVE-2026-55076High
    Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
    CVSS 7.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-14895High
    String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
    CVSS 7.5
    BAKERSCOT/String::Utilgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  16. CVE-2026-14740Critical
    DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
    CVSS 9.1
    HMBRAND/DBIgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  17. CVE-2026-14739Critical
    DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
    CVSS 9.8
    HMBRAND/DBIgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-14380High
    DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
    CVSS 8.8
    HMBRAND/DBIgeneric
    PublishedJul 7, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  19. CVE-2026-49033High
    Stack-Based Buffer Overflow in Labcenter Proteus
    CVSS 7.8
    Labcenter/Proteusgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-42958High
    Use After Free in Labcenter Proteus
    CVSS 7.8
    Labcenter/Proteusgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  21. CVE-2026-42953High
    Out-of-bounds write in Labcenter Proteus
    CVSS 8.4
    Labcenter/Proteusgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-55075High
    Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
    CVSS 7.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-54698Medium
    Hasura: Row-level authorization bypass on table computed fields
    CVSS 6.0
    hasura/graphql-enginegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  24. CVE-2026-54602High
    FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord
    CVSS 7.1
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  25. CVE-2026-54607High
    FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)
    CVSS 7.7
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2026-55418High
    FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)
    CVSS 8.6
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  27. CVE-2026-54601Medium
    FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion
    CVSS 6.3
    labring/FastGPTgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-58266Medium
    Anki: User scripts in iframes have access to the internal Anki API
    CVSS 6.5
    ankitects/anki, aqtgeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-59153High
    Anki's local HTTP server does not sufficiently validate requests
    CVSS 2.1
    ankitects/anki, aqtgeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jun 19, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  30. CVE-2026-46354Critical
    Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
    CVSS 9.1
    coder/codergeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-55490Medium
    OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service
    CVSS 6.5
    openwrt/openwrtgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  32. CVE-2026-28378Low
    Cross-Organization Public Dashboard Deletion via Missing Org Isolation
    CVSS 3.1
    Grafana/Grafana Enterprise, Grafana/Grafana OSSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 29, 2026View HOL analysis
  33. CVE-2026-45796Medium
    Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint
    CVSS 6.5
    coder/codergeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  34. CVE-2026-55408High
    Koodo Reader: Remote code execution via malicious epub file
    CVSS 8.4
    koodo-reader/koodo-readergeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  35. CVE-2026-49229High
    Actual: Disabled OpenID users keep access through existing session tokens
    CVSS 8.3
    @actual-app/sync-server, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 23, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  36. CVE-2026-50179Medium
    Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
    CVSS 4.2
    @actual-app/web, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 23, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-46700Medium
    Actual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
    CVSS 4.3
    @actual-app/sync-server, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-46672Medium
    Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper
    CVSS 4.6
    @actual-app/cli, actualbudget/actualgeneric · npm
    PublishedJul 7, 2026First seen at HOL Jun 22, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-50007High
    Actual: Shared users can perform owner-only file management actions
    CVSS 7.2
    actualbudget/actualgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  40. CVE-2026-49471High
    Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
    CVSS 8.3
    oraios/serena, serena-agentgeneric · pip
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  41. CVE-2026-55592Low
    Dashy: XSS in workspace url parameter
    CVSS 3.9
    lissy93/dashygeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  42. CVE-2026-53511High
    calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
    CVSS 8.5
    kovidgoyal/calibregeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-53935Medium
    CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
    CVSS 6.9
    cilium/cilium, github.com/cilium/ciliumgeneric · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  44. CVE-2026-50530High
    DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets
    CVSS 7.1
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  45. CVE-2026-50529High
    DataEase: Link Token Leakage Prior to Share Password/Ticket Validation
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  46. CVE-2026-55647Medium
    DataEase: authenticated stored XSS in the dashboard text components
    CVSS 5.1
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  47. CVE-2026-55635High
    DataEase: Authenticated SQL Injection in Chart Quota Filters
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-57172High
    DataEase: Hardcoded JWT Signing Secret in ShareLink
    CVSS 8.3
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  49. CVE-2026-53751High
    DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-53730High
    DataEase: Unauthorized Access to Engine Database via previewSql Endpoint
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
Page 93 of 328
Previous9192939495Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard