1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 12:15 PM 16,237 active 1,443 known exploited

Catalog summary

16,237

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 12:15 PM 16,237 active 1,443 known exploited

Catalog summary

16,237

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 451–500 of 16,237 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-18276Medium
    Missing Authorization in eScriptorium
    CVSS 4.3
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-3430High
    Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
    CVSS 8.6
    Unknown/Creative Mailgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-19047Medium
    NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection
    CVSS 5.3
    NocteDefensor/LudusMCPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  4. CVE-2026-18427High
    @fastify/static vulnerable to route guard bypass via non-canonical path segments
    CVSS 7.5
    @fastify/static/@fastify/staticgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-68750High
    Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
    CVSS 8.2
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-68749High
    Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
    CVSS 8.2
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-68747Low
    CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
    CVSS 2.3
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  8. CVE-2026-66829Low
    html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
    CVSS 2.3
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-66370Medium
    html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
    CVSS 4.8
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-66843Low
    html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
    CVSS 2.3
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-19046Low
    NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversal
    CVSS 3.3
    NocteDefensor/LudusMCPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-53977High
    OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown
    CVSS 7.5
    Bohdan Triapitsyn/OpenChambergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-70646High
    aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
    CVSS 7.5
    aiosend, vovchic17/aiosendgeneric · pip
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  14. CVE-2025-49506High
    Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
    CVSS 7.5
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-32327Critical
    Apache Portable Runtime Utility: apr-util XML stack recursion crash
    CVSS 9.1
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-34191Critical
    Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
    CVSS 9.1
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-34501High
    Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
    CVSS 7.5
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-34502High
    Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
    CVSS 7.5
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-19045Medium
    NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.showSecretDialog command injection
    CVSS 5.3
    NocteDefensor/LudusMCPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-66711High
    WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Amir Helzer/WooCommerce Multilingual & Multicurrencygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-66710High
    WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability
    CVSS 8.1
    E2Pdf/e2pdfgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-66709Critical
    WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability
    CVSS 9.1
    WebAppick/CTX Feedgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-66708High
    WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
    CVSS 8.2
    BoldGrid/Total Upkeepgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-66707High
    WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Facebook/Facebook for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  25. CVE-2026-66706Medium
    WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 5.9
    Mark Jaquith/Subscribe to Commentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-66705High
    WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Facebook/Facebook for WordPressgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-66703Medium
    WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    properfraction/MailOptingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-66702High
    WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Rank Math SEO/Rank Math SEOgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-66701Medium
    WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability
    CVSS 5.3
    Cozmoslabs/Profile Buildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  30. CVE-2026-66699Medium
    WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability
    CVSS 5.3
    Dokan, Inc./Dokangeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-66696Medium
    WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability
    CVSS 4.3
    Nexcess/Gutenberg Blocks by Kadence Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-66695Medium
    WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
    CVSS 6.5
    BoldGrid/W3 Total Cachegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-66694High
    WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Thrive Themes Coupon/Thrive Architectgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  34. CVE-2026-66692Medium
    WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 4.3
    Colissimo/Colissimo Officiel : Méthodes de livraison pour WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  35. CVE-2026-66690High
    WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Nexcess/GiveWPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-66688Medium
    WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Brainstorm Force/Ultimate Addons for Elementorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-66686Medium
    WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 6.5
    Vladimir Garagulya/Plugins Garbage Collector (Database Cleanup)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-66685Medium
    WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Alex/Featured Video Plusgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-66684Medium
    WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Akshay Menariya/Export Import Menusgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  40. CVE-2026-66683Medium
    WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    WP Zone/Custom CSS and JavaScriptgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-66681Medium
    WordPress theme My Login plugin <= 7.1.14 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 4.3
    Jeff Farthing/Theme My Logingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-66678Medium
    WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken Access Control vulnerability
    CVSS 4.3
    Justin Kruit/Advanced Custom Fields: Font Awesome Fieldgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-66665Critical
    WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability
    CVSS 10.0
    Brandexponents/Type Hubgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-66664High
    WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    SEO Squirrly/SEO Plugin by Squirrly SEOgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  45. CVE-2026-66663High
    WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Passionate Programmer Peter/WP Data Accessgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-66662Critical
    WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability
    CVSS 9.8
    Shabti Kaplan/Frontend Admin by DynamiAppsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-66470High
    WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability
    CVSS 7.1
    Shabti Kaplan/Frontend Admin by DynamiAppsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-66457High
    WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    @msykes/Events Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-66452Medium
    WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Broken Access Control vulnerability
    CVSS 6.5
    IT-Recht Kanzlei/Legal Text Connector of the IT-Recht Kanzleigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  50. CVE-2026-66451Medium
    WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerability
    CVSS 6.5
    Arraytics/WP Event SOlutiongeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 10 of 325
Previous89101112Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 451–500 of 16,237 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-18276Medium
    Missing Authorization in eScriptorium
    CVSS 4.3
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-3430High
    Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
    CVSS 8.6
    Unknown/Creative Mailgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-19047Medium
    NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection
    CVSS 5.3
    NocteDefensor/LudusMCPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  4. CVE-2026-18427High
    @fastify/static vulnerable to route guard bypass via non-canonical path segments
    CVSS 7.5
    @fastify/static/@fastify/staticgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-68750High
    Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
    CVSS 8.2
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-68749High
    Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
    CVSS 8.2
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-68747Low
    CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
    CVSS 2.3
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  8. CVE-2026-66829Low
    html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
    CVSS 2.3
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-66370Medium
    html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
    CVSS 4.8
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  10. CVE-2026-66843Low
    html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
    CVSS 2.3
    rrrene/html_sanitize_exgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-19046Low
    NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversal
    CVSS 3.3
    NocteDefensor/LudusMCPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-53977High
    OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown
    CVSS 7.5
    Bohdan Triapitsyn/OpenChambergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-70646High
    aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
    CVSS 7.5
    aiosend, vovchic17/aiosendgeneric · pip
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  14. CVE-2025-49506High
    Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
    CVSS 7.5
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-32327Critical
    Apache Portable Runtime Utility: apr-util XML stack recursion crash
    CVSS 9.1
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-34191Critical
    Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
    CVSS 9.1
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-34501High
    Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
    CVSS 7.5
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-34502High
    Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
    CVSS 7.5
    Apache Software Foundation/Apache Portable Runtime Utilitygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-19045Medium
    NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.showSecretDialog command injection
    CVSS 5.3
    NocteDefensor/LudusMCPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-66711High
    WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Amir Helzer/WooCommerce Multilingual & Multicurrencygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-66710High
    WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability
    CVSS 8.1
    E2Pdf/e2pdfgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-66709Critical
    WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability
    CVSS 9.1
    WebAppick/CTX Feedgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-66708High
    WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
    CVSS 8.2
    BoldGrid/Total Upkeepgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-66707High
    WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Facebook/Facebook for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  25. CVE-2026-66706Medium
    WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 5.9
    Mark Jaquith/Subscribe to Commentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-66705High
    WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Facebook/Facebook for WordPressgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-66703Medium
    WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    properfraction/MailOptingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-66702High
    WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Rank Math SEO/Rank Math SEOgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-66701Medium
    WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability
    CVSS 5.3
    Cozmoslabs/Profile Buildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  30. CVE-2026-66699Medium
    WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability
    CVSS 5.3
    Dokan, Inc./Dokangeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-66696Medium
    WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability
    CVSS 4.3
    Nexcess/Gutenberg Blocks by Kadence Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-66695Medium
    WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
    CVSS 6.5
    BoldGrid/W3 Total Cachegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-66694High
    WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Thrive Themes Coupon/Thrive Architectgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  34. CVE-2026-66692Medium
    WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 4.3
    Colissimo/Colissimo Officiel : Méthodes de livraison pour WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  35. CVE-2026-66690High
    WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Nexcess/GiveWPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-66688Medium
    WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Brainstorm Force/Ultimate Addons for Elementorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-66686Medium
    WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 6.5
    Vladimir Garagulya/Plugins Garbage Collector (Database Cleanup)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-66685Medium
    WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Alex/Featured Video Plusgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-66684Medium
    WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Akshay Menariya/Export Import Menusgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  40. CVE-2026-66683Medium
    WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    WP Zone/Custom CSS and JavaScriptgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-66681Medium
    WordPress theme My Login plugin <= 7.1.14 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 4.3
    Jeff Farthing/Theme My Logingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-66678Medium
    WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken Access Control vulnerability
    CVSS 4.3
    Justin Kruit/Advanced Custom Fields: Font Awesome Fieldgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-66665Critical
    WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability
    CVSS 10.0
    Brandexponents/Type Hubgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-66664High
    WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    SEO Squirrly/SEO Plugin by Squirrly SEOgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  45. CVE-2026-66663High
    WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Passionate Programmer Peter/WP Data Accessgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-66662Critical
    WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability
    CVSS 9.8
    Shabti Kaplan/Frontend Admin by DynamiAppsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-66470High
    WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability
    CVSS 7.1
    Shabti Kaplan/Frontend Admin by DynamiAppsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-66457High
    WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    @msykes/Events Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-66452Medium
    WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Broken Access Control vulnerability
    CVSS 6.5
    IT-Recht Kanzlei/Legal Text Connector of the IT-Recht Kanzleigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  50. CVE-2026-66451Medium
    WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerability
    CVSS 6.5
    Arraytics/WP Event SOlutiongeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 10 of 325
Previous89101112Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard