1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 5:30 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 5:30 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

8,465

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,801–4,850 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-40141Critical
    High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access
    CVSS 9.9
    BeyondTrust/Privilege Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  2. CVE-2026-40140High
    High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
    CVSS 8.7
    BeyondTrust/Privileged Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  3. CVE-2026-40139Critical
    Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
    CVSS 9.8
    BeyondTrust/Privileged Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  4. CVE-2026-40138Critical
    Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
    CVSS 9.2
    BeyondTrust/Privileged Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  5. CVE-2026-43825High
    Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
    CVSS 7.3
    Apache Software Foundation/Apache OpenNLP :: Core :: ML :: LibSVMgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-5268Critical
    SFTP Server Authentication Weakness
    CVSS 9.1
    CIENA/6500 S-Series, CIENA/6500 T-Series +2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2025-53830Critical
    Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
    CVSS 9.1
    owncloud/Anti-Virus for ownCloud, owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  8. CVE-2026-59194High
    pnpm: patch-remove could delete project-selected files outside the patches directory
    CVSS 7.1
    pnpm/pnpmgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  9. CVE-2025-53829High
    ownCloud 10 is vulnerable to Relative Path Traversal
    CVSS 8.0
    owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  10. CVE-2025-53828High
    SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
    CVSS 8.5
    owncloud/SharePoint, owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  11. CVE-2026-13122Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    Openvpn/OpenVPNgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2025-53827Critical
    ownCloud Core: Updater has an exposed dangerous method or function
    CVSS 9.1
    owncloud/ownCloud Coregeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  13. CVE-2026-59152Medium
    Arbitrary server-side file read in LangSmith SDK TracingMiddleware
    CVSS 5.0
    langchain-ai/langsmith-sdk, langsmithgeneric · pip · pypi
    PublishedJul 6, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-13698High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenVPN/OpenVPNgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-13708High
    Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol
    CVSS 7.5
    TONYC/Imager::File::JPEGgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  16. CVE-2026-13705High
    Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
    CVSS 7.1
    TONYC/Imagergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  17. CVE-2025-15668Low
    GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  18. CVE-2025-15667Low
    GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  19. CVE-2026-4249High
    Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
    CVSS 8.6
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  20. CVE-2025-8591Medium
    Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
    CVSS 6.1
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +6generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  21. CVE-2026-46588High
    Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
    CVSS 7.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-46587High
    Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
    CVSS 7.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-12686Critical
    Incorrect authorisation in Adiss’s Biloop
    CVSS 9.3
    Adiss/Biloopgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  24. CVE-2026-44934High
    Exposed tokens in SUSE Rancher AI Agent logs
    CVSS 7.0
    SUSE/Ranchergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  25. CVE-2026-24013Critical
    Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
    CVSS 9.1
    Apache Software Foundation/Apache IoTDB, apache-iotdbgeneric · pypi
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-24012High
    Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
    CVSS 7.5
    Apache Software Foundation/Apache IoTDB, apache-iotdbgeneric · pypi
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  27. CVE-2026-43866High
    Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder
    CVSS 7.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-24014Critical
    Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
    CVSS 9.8
    Apache Software Foundation/Apache IoTDB, apache-iotdbgeneric · pypi
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-43867Critical
    Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-1433Medium
    uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure
    CVSS 4.8
    NT-ware/uniFLOW ULM (Universal Login Manager) Standalonegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  31. CVE-2026-48206Medium
    Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials
    CVSS 5.3
    Apache Software Foundation/Apache Camel JIRAgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-48205Critical
    Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
    CVSS 9.1
    Apache Software Foundation/Apache Camel DNS, org.apache.camel:camel-dnsgeneric · maven
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  33. CVE-2026-48204Critical
    Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration
    CVSS 9.8
    Apache Software Foundation/Apache Camel, org.apache.camel:camel-mongodb-gridfsgeneric · maven
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  34. CVE-2026-48203Critical
    Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
    CVSS 9.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-46726High
    Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
    CVSS 7.5
    Apache Software Foundation/Apache Camel Vertx Websocketgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-46592High
    Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
    CVSS 7.5
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  37. CVE-2026-46591High
    Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
    CVSS 8.2
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-46590High
    Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
    CVSS 8.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-46585High
    Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
    CVSS 7.5
    Apache Software Foundation/Apache Camel Lucenegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-46584Low
    Apache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters
    CVSS 3.7
    Apache Software Foundation/Apache Camel Mailgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  41. CVE-2026-46457High
    Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
    CVSS 7.5
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-46456Critical
    Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  43. CVE-2026-46455Critical
    Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  44. CVE-2026-46454Critical
    Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-46453Medium
    Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation
    CVSS 5.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-43865High
    Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
    CVSS 8.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-42527High
    Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
    CVSS 8.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-40859High
    Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
    CVSS 8.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-40047Critical
    Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
    CVSS 9.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  50. CVE-2026-14809High
    PROG MIS|Prog Management System - SQL Injection
    CVSS 7.5
    PROG MIS/Prog Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
Page 97 of 328
Previous9596979899Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,465

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,801–4,850 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-40141Critical
    High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access
    CVSS 9.9
    BeyondTrust/Privilege Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  2. CVE-2026-40140High
    High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
    CVSS 8.7
    BeyondTrust/Privileged Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  3. CVE-2026-40139Critical
    Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
    CVSS 9.8
    BeyondTrust/Privileged Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  4. CVE-2026-40138Critical
    Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
    CVSS 9.2
    BeyondTrust/Privileged Remote Access, BeyondTrust/Remote Supportgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  5. CVE-2026-43825High
    Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
    CVSS 7.3
    Apache Software Foundation/Apache OpenNLP :: Core :: ML :: LibSVMgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-5268Critical
    SFTP Server Authentication Weakness
    CVSS 9.1
    CIENA/6500 S-Series, CIENA/6500 T-Series +2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2025-53830Critical
    Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
    CVSS 9.1
    owncloud/Anti-Virus for ownCloud, owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  8. CVE-2026-59194High
    pnpm: patch-remove could delete project-selected files outside the patches directory
    CVSS 7.1
    pnpm/pnpmgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  9. CVE-2025-53829High
    ownCloud 10 is vulnerable to Relative Path Traversal
    CVSS 8.0
    owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  10. CVE-2025-53828High
    SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
    CVSS 8.5
    owncloud/SharePoint, owncloud/ownCloud 10generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  11. CVE-2026-13122Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    Openvpn/OpenVPNgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2025-53827Critical
    ownCloud Core: Updater has an exposed dangerous method or function
    CVSS 9.1
    owncloud/ownCloud Coregeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  13. CVE-2026-59152Medium
    Arbitrary server-side file read in LangSmith SDK TracingMiddleware
    CVSS 5.0
    langchain-ai/langsmith-sdk, langsmithgeneric · pip · pypi
    PublishedJul 6, 2026First seen at HOL Jun 19, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-13698High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenVPN/OpenVPNgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-13708High
    Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol
    CVSS 7.5
    TONYC/Imager::File::JPEGgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  16. CVE-2026-13705High
    Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle
    CVSS 7.1
    TONYC/Imagergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  17. CVE-2025-15668Low
    GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  18. CVE-2025-15667Low
    GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  19. CVE-2026-4249High
    Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
    CVSS 8.6
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  20. CVE-2025-8591Medium
    Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
    CVSS 6.1
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +6generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  21. CVE-2026-46588High
    Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
    CVSS 7.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-46587High
    Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
    CVSS 7.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-12686Critical
    Incorrect authorisation in Adiss’s Biloop
    CVSS 9.3
    Adiss/Biloopgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  24. CVE-2026-44934High
    Exposed tokens in SUSE Rancher AI Agent logs
    CVSS 7.0
    SUSE/Ranchergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  25. CVE-2026-24013Critical
    Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
    CVSS 9.1
    Apache Software Foundation/Apache IoTDB, apache-iotdbgeneric · pypi
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-24012High
    Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
    CVSS 7.5
    Apache Software Foundation/Apache IoTDB, apache-iotdbgeneric · pypi
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  27. CVE-2026-43866High
    Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder
    CVSS 7.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-24014Critical
    Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
    CVSS 9.8
    Apache Software Foundation/Apache IoTDB, apache-iotdbgeneric · pypi
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-43867Critical
    Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-1433Medium
    uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure
    CVSS 4.8
    NT-ware/uniFLOW ULM (Universal Login Manager) Standalonegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  31. CVE-2026-48206Medium
    Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials
    CVSS 5.3
    Apache Software Foundation/Apache Camel JIRAgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-48205Critical
    Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
    CVSS 9.1
    Apache Software Foundation/Apache Camel DNS, org.apache.camel:camel-dnsgeneric · maven
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  33. CVE-2026-48204Critical
    Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration
    CVSS 9.8
    Apache Software Foundation/Apache Camel, org.apache.camel:camel-mongodb-gridfsgeneric · maven
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  34. CVE-2026-48203Critical
    Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
    CVSS 9.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-46726High
    Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
    CVSS 7.5
    Apache Software Foundation/Apache Camel Vertx Websocketgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-46592High
    Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
    CVSS 7.5
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  37. CVE-2026-46591High
    Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
    CVSS 8.2
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-46590High
    Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
    CVSS 8.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-46585High
    Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
    CVSS 7.5
    Apache Software Foundation/Apache Camel Lucenegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-46584Low
    Apache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters
    CVSS 3.7
    Apache Software Foundation/Apache Camel Mailgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  41. CVE-2026-46457High
    Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
    CVSS 7.5
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-46456Critical
    Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  43. CVE-2026-46455Critical
    Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  44. CVE-2026-46454Critical
    Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers
    CVSS 9.8
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-46453Medium
    Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation
    CVSS 5.3
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-43865High
    Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
    CVSS 8.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-42527High
    Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
    CVSS 8.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-40859High
    Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
    CVSS 8.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-40047Critical
    Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
    CVSS 9.1
    Apache Software Foundation/Apache Camelgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  50. CVE-2026-14809High
    PROG MIS|Prog Management System - SQL Injection
    CVSS 7.5
    PROG MIS/Prog Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
Page 97 of 328
Previous9596979899Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard