1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 5:25 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 5:25 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

8,465

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,751–4,800 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-34049Low
    Coolify: Command Injection via unsanitized MongoDB collection names in database backup
    CVSS 3.3
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  2. CVE-2026-34599High
    Coolify: Authenticated Remote Code Execution in GetLogs Livewire Component
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  3. CVE-2026-43918High
    Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows
    CVSS 8.7
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  4. CVE-2026-42204High
    Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  5. CVE-2026-42148Low
    Coolify: Command Injection via Unescaped Version String in Docker Build
    CVSS 3.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  6. CVE-2026-34153High
    Coolify LocalFileVolume fs_path command injection enables RCE
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  7. CVE-2026-41899Medium
    Coolify unauthenticated feedback endpoint allows Discord webhook abuse
    CVSS 6.5
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  8. CVE-2026-34050Medium
    Coolify Settings/Updates Livewire component missing instance administrator authorization
    CVSS 6.5
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  9. CVE-2026-32718Medium
    Coolify read-scoped API tokens can perform state-changing validation operations
    CVSS 6.5
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  10. CVE-2026-42331High
    FOSSBilling missing authorization in guest Invoice API endpoints
    CVSS 7.7
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  11. CVE-2026-14468High
    Path traversal allows arbitrary file read in Terraform Enterprise container
    CVSS 7.7
    HashiCorp/Terraform Enterprisegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-33734Medium
    FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters
    CVSS 6.9
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  13. CVE-2026-42341Critical
    FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
    CVSS 9.2
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  14. CVE-2026-34038Critical
    Coolify authenticated remote command injection leading to RCE and secret exfiltration
    CVSS 9.9
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  15. CVE-2026-54763Critical
    Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
    CVSS 10.0
    github.com/traefik/traefik/v2, github.com/traefik/traefik/v3 +1generic · go
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  16. CVE-2026-14471High
    Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry
    CVSS 8.1
    AWS/MCP Gateway & Registrygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  17. CVE-2026-57572Critical
    Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
    CVSS 10.0
    unclecode/crawl4aigeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-57571Critical
    Crawl4AI arbitrary file write via download filename path traversal
    CVSS 9.6
    unclecode/crawl4aigeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  19. CVE-2026-25271High
    Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service
    CVSS 7.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  20. CVE-2026-25268High
    Stack-based Buffer Overflow in WLAN Host
    CVSS 8.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  21. CVE-2026-21384Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  22. CVE-2026-21383High
    Reusing a Nonce, Key Pair in Encryption in HLOS
    CVSS 7.1
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-21379High
    Buffer Over-read in Windows Compute
    CVSS 7.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  24. CVE-2026-21370Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  25. CVE-2026-21369Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  26. CVE-2026-21368Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  27. CVE-2025-59617Medium
    Use After Free in Computer Vision
    CVSS 6.6
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  28. CVE-2025-59616Medium
    Use After Free in Computer Vision
    CVSS 6.6
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  29. CVE-2025-59615Medium
    Use After Free in Computer Vision
    CVSS 6.6
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  30. CVE-2026-50135Medium
    Hugo: Symlink confinement bypass in resources.Get
    CVSS 6.9
    github.com/gohugoio/hugo, gohugoio/hugogeneric · go
    PublishedJul 6, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-48267Medium
    DNG SDK | NULL Pointer Dereference (CWE-476)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  32. CVE-2026-50134Medium
    Hugo: security.http.urls allow-list bypass via HTTP redirects
    CVSS 6.3
    github.com/gohugoio/hugo, gohugoio/hugogeneric · go
    PublishedJul 6, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-14898Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    OpenAI/Codex desktop app for macOSgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-44362Medium
    OP-TEE's subkey rollback protection can be bypassed with older subkey versions
    CVSS 5.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  35. CVE-2026-42546Low
    OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references
    CVSS 3.8
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  36. CVE-2026-41516Low
    OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle
    CVSS 2.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  37. CVE-2026-41515Low
    OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery
    CVSS 2.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  38. CVE-2026-14536High
    CISA ADP Vulnrichment
    CVSS 8.8
    Devolutions/Servergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  39. CVE-2026-11405Critical
    Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
    CVSS 9.8
    Tenda/firmwaregeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  40. CVE-2026-58404Medium
    Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings
    CVSS 6.8
    gohugoio/hugogeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  41. CVE-2026-41514Low
    OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery
    CVSS 2.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  42. CVE-2026-54059High
    Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
    CVSS 7.5
    python-pillow/Pillowgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  43. CVE-2026-55798Medium
    Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
    CVSS 4.5
    python-pillow/Pillowgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  44. CVE-2026-9181Critical
    Directory Traversal in ArcGIS Server
    CVSS 9.8
    Esri/ArcGIS Servergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  45. CVE-2026-9182Critical
    Unvalidated File Upload vulnerability in ArcGIS Server.
    CVSS 9.8
    Esri/ArcGIS Servergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  46. CVE-2026-13753High
    CVE-2026-13753
    CVSS 7.5
    HP Inc./HP 2800 Printer Seriesgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  47. CVE-2026-12154Medium
    Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute
    CVSS 6.4
    widgetpack/Reviews Widgets for Google, TripAdvisor, Yelp & Recommendationsgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  48. CVE-2026-41434Low
    OP-TEE has unbounded recursion in sanitize_client_object()
    CVSS 3.3
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  49. CVE-2026-40257Medium
    OP-TEE has SHA-3 accelerated finalize heap overflow
    CVSS 5.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  50. CVE-2025-53831High
    DrawIO for ownCloud 10 is vulnerable to Stored XSS
    CVSS 8.2
    owncloud/DrawIO for ownCloud, owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
Page 96 of 328
Previous9495969798Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,465

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,751–4,800 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-34049Low
    Coolify: Command Injection via unsanitized MongoDB collection names in database backup
    CVSS 3.3
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  2. CVE-2026-34599High
    Coolify: Authenticated Remote Code Execution in GetLogs Livewire Component
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  3. CVE-2026-43918High
    Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows
    CVSS 8.7
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  4. CVE-2026-42204High
    Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  5. CVE-2026-42148Low
    Coolify: Command Injection via Unescaped Version String in Docker Build
    CVSS 3.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  6. CVE-2026-34153High
    Coolify LocalFileVolume fs_path command injection enables RCE
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  7. CVE-2026-41899Medium
    Coolify unauthenticated feedback endpoint allows Discord webhook abuse
    CVSS 6.5
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  8. CVE-2026-34050Medium
    Coolify Settings/Updates Livewire component missing instance administrator authorization
    CVSS 6.5
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  9. CVE-2026-32718Medium
    Coolify read-scoped API tokens can perform state-changing validation operations
    CVSS 6.5
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  10. CVE-2026-42331High
    FOSSBilling missing authorization in guest Invoice API endpoints
    CVSS 7.7
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  11. CVE-2026-14468High
    Path traversal allows arbitrary file read in Terraform Enterprise container
    CVSS 7.7
    HashiCorp/Terraform Enterprisegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-33734Medium
    FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters
    CVSS 6.9
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  13. CVE-2026-42341Critical
    FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
    CVSS 9.2
    FOSSBilling/FOSSBillinggeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  14. CVE-2026-34038Critical
    Coolify authenticated remote command injection leading to RCE and secret exfiltration
    CVSS 9.9
    coollabsio/coolifygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  15. CVE-2026-54763Critical
    Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
    CVSS 10.0
    github.com/traefik/traefik/v2, github.com/traefik/traefik/v3 +1generic · go
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  16. CVE-2026-14471High
    Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry
    CVSS 8.1
    AWS/MCP Gateway & Registrygeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  17. CVE-2026-57572Critical
    Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
    CVSS 10.0
    unclecode/crawl4aigeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-57571Critical
    Crawl4AI arbitrary file write via download filename path traversal
    CVSS 9.6
    unclecode/crawl4aigeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  19. CVE-2026-25271High
    Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service
    CVSS 7.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  20. CVE-2026-25268High
    Stack-based Buffer Overflow in WLAN Host
    CVSS 8.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  21. CVE-2026-21384Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  22. CVE-2026-21383High
    Reusing a Nonce, Key Pair in Encryption in HLOS
    CVSS 7.1
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-21379High
    Buffer Over-read in Windows Compute
    CVSS 7.8
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  24. CVE-2026-21370Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  25. CVE-2026-21369Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  26. CVE-2026-21368Medium
    Out-of-bounds Write in Camera Driver
    CVSS 5.3
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  27. CVE-2025-59617Medium
    Use After Free in Computer Vision
    CVSS 6.6
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  28. CVE-2025-59616Medium
    Use After Free in Computer Vision
    CVSS 6.6
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  29. CVE-2025-59615Medium
    Use After Free in Computer Vision
    CVSS 6.6
    Qualcomm, Inc./Snapdragongeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  30. CVE-2026-50135Medium
    Hugo: Symlink confinement bypass in resources.Get
    CVSS 6.9
    github.com/gohugoio/hugo, gohugoio/hugogeneric · go
    PublishedJul 6, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-48267Medium
    DNG SDK | NULL Pointer Dereference (CWE-476)
    CVSS 5.5
    Adobe/DNG SDKgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  32. CVE-2026-50134Medium
    Hugo: security.http.urls allow-list bypass via HTTP redirects
    CVSS 6.3
    github.com/gohugoio/hugo, gohugoio/hugogeneric · go
    PublishedJul 6, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-14898Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    OpenAI/Codex desktop app for macOSgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-44362Medium
    OP-TEE's subkey rollback protection can be bypassed with older subkey versions
    CVSS 5.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  35. CVE-2026-42546Low
    OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references
    CVSS 3.8
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  36. CVE-2026-41516Low
    OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle
    CVSS 2.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  37. CVE-2026-41515Low
    OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery
    CVSS 2.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  38. CVE-2026-14536High
    CISA ADP Vulnrichment
    CVSS 8.8
    Devolutions/Servergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  39. CVE-2026-11405Critical
    Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
    CVSS 9.8
    Tenda/firmwaregeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  40. CVE-2026-58404Medium
    Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings
    CVSS 6.8
    gohugoio/hugogeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  41. CVE-2026-41514Low
    OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery
    CVSS 2.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  42. CVE-2026-54059High
    Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
    CVSS 7.5
    python-pillow/Pillowgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  43. CVE-2026-55798Medium
    Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
    CVSS 4.5
    python-pillow/Pillowgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  44. CVE-2026-9181Critical
    Directory Traversal in ArcGIS Server
    CVSS 9.8
    Esri/ArcGIS Servergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  45. CVE-2026-9182Critical
    Unvalidated File Upload vulnerability in ArcGIS Server.
    CVSS 9.8
    Esri/ArcGIS Servergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  46. CVE-2026-13753High
    CVE-2026-13753
    CVSS 7.5
    HP Inc./HP 2800 Printer Seriesgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  47. CVE-2026-12154Medium
    Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute
    CVSS 6.4
    widgetpack/Reviews Widgets for Google, TripAdvisor, Yelp & Recommendationsgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  48. CVE-2026-41434Low
    OP-TEE has unbounded recursion in sanitize_client_object()
    CVSS 3.3
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  49. CVE-2026-40257Medium
    OP-TEE has SHA-3 accelerated finalize heap overflow
    CVSS 5.5
    OP-TEE/optee_osgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  50. CVE-2025-53831High
    DrawIO for ownCloud 10 is vulnerable to Stored XSS
    CVSS 8.2
    owncloud/DrawIO for ownCloud, owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
Page 96 of 328
Previous9495969798Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard