1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:30 AM 16,232 active 1,443 known exploited

Catalog summary

16,232

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:30 AM 16,232 active 1,443 known exploited

Catalog summary

16,232

Active CVEs

8,389

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity

Showing 1–50 of 16,232 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-19270Unknown severity
    Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal
    Not scoredSource severity not reported
    Hulupeep/mcp-ui-probegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  2. CVE-2026-19268Unknown severity
    abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection
    Not scoredSource severity not reported
    abdullah1854/MCPGatewaygeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  3. CVE-2026-19266Unknown severity
    Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection
    Not scoredSource severity not reported
    Kirachon/context-enginegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  4. CVE-2026-19263Unknown severity
    INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection
    Not scoredSource severity not reported
    INQUIRELAB/mcp-bridge-apigeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  5. CVE-2026-14526Unknown severity
    AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route
    Not scoredSource severity not reported
    wupsales/AI Copilot – Content Generatorgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  6. CVE-2026-16955Unknown severity
    AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
    Not scoredSource severity not reported
    Unknown/AI Enginegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-16953Unknown severity
    AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie
    Not scoredSource severity not reported
    Unknown/AI Enginegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-16948Unknown severity
    Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
    Not scoredSource severity not reported
    Unknown/Solace Extrageneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-16608Unknown severity
    Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
    Not scoredSource severity not reported
    Unknown/Download Monitorgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-16595Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-16594Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-16590Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-16589Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-16578Unknown severity
    Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route
    Not scoredSource severity not reported
    Unknown/Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protectiongeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-16574Unknown severity
    Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
    Not scoredSource severity not reported
    Unknown/Dokan: AI Powered WooCommerce Multivendor Marketplace Solutiongeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  16. CVE-2026-16562Unknown severity
    WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
    Not scoredSource severity not reported
    Unknown/WP Statisticsgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  17. CVE-2026-16559Unknown severity
    YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
    Not scoredSource severity not reported
    Unknown/YMC Filtergeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-16558Unknown severity
    YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
    Not scoredSource severity not reported
    Unknown/YMC Filtergeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-16535Unknown severity
    Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
    Not scoredSource severity not reported
    Unknown/Link Librarygeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  20. CVE-2026-16282Unknown severity
    Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter
    Not scoredSource severity not reported
    Unknown/Appointment Hour Bookinggeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  21. CVE-2026-16269Unknown severity
    Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling
    Not scoredSource severity not reported
    Unknown/Newslettersgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  22. CVE-2026-16267Unknown severity
    Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
    Not scoredSource severity not reported
    Unknown/Newslettersgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-19259Unknown severity
    MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow
    Not scoredSource severity not reported
    MZ Automation/libiec61850generic
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  24. CVE-2026-18988Medium
    Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute
    CVSS 6.4
    shapedplugin/Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  25. CVE-2026-13505High
    Zeroisation of sensitive key material on garbage collection relies on finalization
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJAgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-8798High
    Native entropy source retries the CPU entropy instructions without limit
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJAgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  27. CVE-2026-52880High
    Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-47127Medium
    Ghostfolio has a Stripe subscription bypass
    CVSS 6.5
    ghostfolio/ghostfoliogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-48122Medium
    Workspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extension
    CVSS 5.4
    Shopify/ruby-lspgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  30. CVE-2026-52879High
    Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  31. CVE-2026-48120High
    Kakoune has a Critical RCE via Autorestore Backup Filename Injection
    CVSS 8.6
    mawww/kakounegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  32. CVE-2026-52878High
    Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-48026High
    lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML
    CVSS 8.7
    treeverse/lakeFS, treeverse/lakeFS-enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  34. CVE-2026-49343Medium
    Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
    CVSS 5.9
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-46409Critical
    OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
    CVSS 9.6
    openyak/openyakgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-48047Medium
    XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
    CVSS 5.9
    xwiki/xwiki-platformgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-47249High
    Klever-Go KVM: Hash-array amplification in P2P resolver request handling
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-58262High
    Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum
    CVSS 7.1
    klever-io/klever-gogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-64676Medium
    Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
    CVSS 5.7
    kata-containers/kata-containersgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  40. CVE-2026-47243Critical
    Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
    CVSS 9.2
    kata-containers/kata-containersgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  41. CVE-2026-48170Critical
    scimPatch vulnerable to prototype pollution via unfiltered keys in patch
    CVSS 9.1
    scim-patch, thomaspoignant/scim-patchgeneric · npm
    PublishedAug 7, 2026First seen at HOL Jun 22, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-48169High
    PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
    CVSS 8.8
    MervinPraison/praisonai-platform, praisonai-platformgeneric · pip
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-45808High
    OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
    CVSS 7.1
    openbao/openbaogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  44. CVE-2026-46405Medium
    OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
    CVSS 5.3
    openbao/openbaogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  45. CVE-2026-11743Medium
    Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write
    CVSS 6.6
    zephyrproject/zephyrgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-11742Low
    Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock
    CVSS 3.6
    zephyrproject/zephyrgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-19246Medium
    HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
    CVSS 6.3
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  48. CVE-2026-50540Critical
    Kata Containers: Config Path Annotation Arbitrary File Loading
    CVSS 9.6
    kata-containers/kata-containersgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  49. CVE-2026-54338Medium
    JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
    CVSS 5.3
    jupyterhub/jupyterhubgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  50. CVE-2026-69207Medium
    Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
    CVSS 5.3
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 1 of 325
Previous12345Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,389

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity

Showing 1–50 of 16,232 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-19270Unknown severity
    Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal
    Not scoredSource severity not reported
    Hulupeep/mcp-ui-probegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  2. CVE-2026-19268Unknown severity
    abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection
    Not scoredSource severity not reported
    abdullah1854/MCPGatewaygeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  3. CVE-2026-19266Unknown severity
    Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection
    Not scoredSource severity not reported
    Kirachon/context-enginegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  4. CVE-2026-19263Unknown severity
    INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection
    Not scoredSource severity not reported
    INQUIRELAB/mcp-bridge-apigeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  5. CVE-2026-14526Unknown severity
    AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route
    Not scoredSource severity not reported
    wupsales/AI Copilot – Content Generatorgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  6. CVE-2026-16955Unknown severity
    AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
    Not scoredSource severity not reported
    Unknown/AI Enginegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-16953Unknown severity
    AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie
    Not scoredSource severity not reported
    Unknown/AI Enginegeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-16948Unknown severity
    Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
    Not scoredSource severity not reported
    Unknown/Solace Extrageneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-16608Unknown severity
    Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
    Not scoredSource severity not reported
    Unknown/Download Monitorgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-16595Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-16594Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-16590Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-16589Unknown severity
    WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
    Not scoredSource severity not reported
    Unknown/WP Directory Kitgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-16578Unknown severity
    Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route
    Not scoredSource severity not reported
    Unknown/Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protectiongeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-16574Unknown severity
    Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
    Not scoredSource severity not reported
    Unknown/Dokan: AI Powered WooCommerce Multivendor Marketplace Solutiongeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  16. CVE-2026-16562Unknown severity
    WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
    Not scoredSource severity not reported
    Unknown/WP Statisticsgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  17. CVE-2026-16559Unknown severity
    YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
    Not scoredSource severity not reported
    Unknown/YMC Filtergeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-16558Unknown severity
    YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
    Not scoredSource severity not reported
    Unknown/YMC Filtergeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-16535Unknown severity
    Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
    Not scoredSource severity not reported
    Unknown/Link Librarygeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  20. CVE-2026-16282Unknown severity
    Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter
    Not scoredSource severity not reported
    Unknown/Appointment Hour Bookinggeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  21. CVE-2026-16269Unknown severity
    Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling
    Not scoredSource severity not reported
    Unknown/Newslettersgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  22. CVE-2026-16267Unknown severity
    Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
    Not scoredSource severity not reported
    Unknown/Newslettersgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-19259Unknown severity
    MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow
    Not scoredSource severity not reported
    MZ Automation/libiec61850generic
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  24. CVE-2026-18988Medium
    Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute
    CVSS 6.4
    shapedplugin/Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026View HOL analysis
  25. CVE-2026-13505High
    Zeroisation of sensitive key material on garbage collection relies on finalization
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJAgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-8798High
    Native entropy source retries the CPU entropy instructions without limit
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJAgeneric
    PublishedAug 8, 2026First seen at HOL Aug 8, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  27. CVE-2026-52880High
    Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-47127Medium
    Ghostfolio has a Stripe subscription bypass
    CVSS 6.5
    ghostfolio/ghostfoliogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-48122Medium
    Workspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extension
    CVSS 5.4
    Shopify/ruby-lspgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  30. CVE-2026-52879High
    Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  31. CVE-2026-48120High
    Kakoune has a Critical RCE via Autorestore Backup Filename Injection
    CVSS 8.6
    mawww/kakounegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  32. CVE-2026-52878High
    Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-48026High
    lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML
    CVSS 8.7
    treeverse/lakeFS, treeverse/lakeFS-enterprisegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  34. CVE-2026-49343Medium
    Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
    CVSS 5.9
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-46409Critical
    OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
    CVSS 9.6
    openyak/openyakgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-48047Medium
    XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
    CVSS 5.9
    xwiki/xwiki-platformgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-47249High
    Klever-Go KVM: Hash-array amplification in P2P resolver request handling
    CVSS 7.5
    github.com/klever-io/klever-go, klever-io/klever-gogeneric · go
    PublishedAug 7, 2026First seen at HOL Jun 11, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-58262High
    Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum
    CVSS 7.1
    klever-io/klever-gogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-64676Medium
    Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
    CVSS 5.7
    kata-containers/kata-containersgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  40. CVE-2026-47243Critical
    Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
    CVSS 9.2
    kata-containers/kata-containersgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  41. CVE-2026-48170Critical
    scimPatch vulnerable to prototype pollution via unfiltered keys in patch
    CVSS 9.1
    scim-patch, thomaspoignant/scim-patchgeneric · npm
    PublishedAug 7, 2026First seen at HOL Jun 22, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-48169High
    PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
    CVSS 8.8
    MervinPraison/praisonai-platform, praisonai-platformgeneric · pip
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-45808High
    OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
    CVSS 7.1
    openbao/openbaogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  44. CVE-2026-46405Medium
    OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
    CVSS 5.3
    openbao/openbaogeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  45. CVE-2026-11743Medium
    Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write
    CVSS 6.6
    zephyrproject/zephyrgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-11742Low
    Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock
    CVSS 3.6
    zephyrproject/zephyrgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-19246Medium
    HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
    CVSS 6.3
    HKUDS/nanobotgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  48. CVE-2026-50540Critical
    Kata Containers: Config Path Annotation Arbitrary File Loading
    CVSS 9.6
    kata-containers/kata-containersgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  49. CVE-2026-54338Medium
    JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
    CVSS 5.3
    jupyterhub/jupyterhubgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  50. CVE-2026-69207Medium
    Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
    CVSS 5.3
    hono, honojs/honogeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 1 of 325
Previous12345Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard