1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 7:25 AM 16,422 active 1,443 known exploited

Catalog summary

16,422

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 7:25 AM 16,422 active 1,443 known exploited

Catalog summary

16,422

Active CVEs

8,468

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,001–5,050 of 16,422 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14693Medium
    SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization
    CVSS 5.4
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  2. CVE-2026-14692Medium
    SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php save_shop_type sql injection
    CVSS 6.3
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  3. CVE-2026-14691Medium
    SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSettings.php update_settings_info code injection
    CVSS 6.3
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  4. CVE-2026-14570High
    Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
    CVSS 7.5
    TIMLEGGE/Crypt::DSAgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-14690High
    SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization
    CVSS 7.3
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  6. CVE-2026-14689Medium
    CodeAstro Apartment Visitor Management System add-apartment.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 7, 2026View HOL analysis
  7. CVE-2026-14688High
    itsourcecode Online Hotel Management System login.php sql injection
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  8. CVE-2026-14687Medium
    666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
    CVSS 5.3
    666ghj/BettaFishgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  9. CVE-2026-14686Low
    HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  10. CVE-2026-14685Low
    HdrHistogram AbstractHistogram AbstractHistogram.java recordValueWithCount state issue
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  11. CVE-2026-14684Low
    HdrHistogram AbstractHistogram.java memory allocation
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  12. CVE-2026-14683Low
    HdrHistogram AbstractHistogram.java memory allocation
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  13. CVE-2026-14660High
    code-projects Online Job Portal login.php sql injection
    CVSS 7.3
    code-projects/Online Job Portalgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  14. CVE-2026-14659Medium
    itsourcecode Hospital Management System patientappointment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  15. CVE-2026-14658Medium
    code-projects Assessment Management marking-scheme.php sql injection
    CVSS 6.3
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  16. CVE-2026-14657Medium
    code-projects Assessment Management Database Query marking-scheme.php sql injection
    CVSS 6.3
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  17. CVE-2026-14656Medium
    code-projects Assessment Management remove-user.php cross site scripting
    CVSS 4.3
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  18. CVE-2026-14655Low
    code-projects Assessment Management view-users.php cross site scripting
    CVSS 2.4
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  19. CVE-2026-14654High
    SourceCodester Simple and Nice Shopping Cart Script girlsproductdeletequery.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  20. CVE-2026-14653High
    SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  21. CVE-2024-1248Medium
    Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
    CVSS 4.8
    WSO2/WSO2 API Manager, WSO2/WSO2 Identity Server +3generic
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  22. CVE-2026-14652High
    SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  23. CVE-2026-14651Low
    connorskees grass visitor denial of service
    CVSS 3.3
    connorskees/grassgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  24. CVE-2026-14650Low
    connorskees grass UTF-8 Character raw_to_parse_error denial of service
    CVSS 3.3
    connorskees/grassgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  25. CVE-2026-14649High
    code-projects Online Voting System saveVote.php test_input sql injection
    CVSS 7.3
    code-projects/Online Voting Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  26. CVE-2026-14648High
    code-projects Online Voting System Login authentication.php test_input sql injection
    CVSS 7.3
    code-projects/Online Voting Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  27. CVE-2026-14647Medium
    onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
    CVSS 4.3
    n/a/onnxgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  28. CVE-2026-14642High
    SourceCodester Class and Exam Timetabling System edit_class2.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  29. CVE-2026-14641High
    SourceCodester Class and Exam Timetabling System edit_course.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  30. CVE-2026-14640High
    CodeAstro Apartment Visitor Management System Login index.php sql injection
    CVSS 7.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  31. CVE-2026-14639Medium
    CodeAstro Ecommerce Website my_account.php sql injection
    CVSS 6.3
    CodeAstro/Ecommerce Websitegeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  32. CVE-2026-12740High
    Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter
    CVSS 8.1
    CORNELIUS/Plack::Middleware::OAuthgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  33. CVE-2026-12746High
    Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter
    CVSS 8.1
    BIAFRA/Dancer2::Plugin::Auth::OAuth::Providergeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-14638Medium
    itsourcecode Hospital Management System patient.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  35. CVE-2026-14637High
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserialization
    CVSS 8.2
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  36. CVE-2026-14636Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversal
    CVSS 5.4
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  37. CVE-2026-14635High
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
    CVSS 7.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  38. CVE-2026-14634Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Controller.php checkForPostRequests cross site scripting
    CVSS 4.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  39. CVE-2026-14633Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scripting
    CVSS 4.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  40. CVE-2026-14632Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Trusted Backend MY_Controller.php setReferrer redirect
    CVSS 4.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  41. CVE-2026-14630Low
    ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
    CVSS 3.1
    ForceInjection/AI-fundermentalsgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  42. CVE-2026-14535High
    Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()
    CVSS 8.8
    trailofbits/ficklinggeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-14534High
    Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)
    CVSS 8.8
    trailofbits/ficklinggeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-14629Medium
    RT-Thread Parameter lwp_syscall.c sys_ioctl divide by zero
    CVSS 4.3
    n/a/RT-Threadgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  45. CVE-2026-14628Medium
    NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
    CVSS 5.3
    NousResearch/hermes-agentgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  46. CVE-2025-13475Low
    Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure
    CVSS 3.5
    WSO2/WSO2 API Manager, WSO2/WSO2 Identity Servergeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  47. CVE-2026-14627Medium
    NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
    CVSS 5.6
    NousResearch/hermes-agentgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  48. CVE-2026-12196High
    HestiaCP Admin Takeover
    CVSS 8.3
    hestiacp/hestiacpgeneric
    PublishedJul 4, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-14626Medium
    NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service
    CVSS 4.3
    NousResearch/hermes-agentgeneric
    PublishedJul 4, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  50. CVE-2026-53362Unknown severity
    ipv6: account for fraggap on the paged allocation path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 101 of 329
Previous99100101102103Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,468

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,001–5,050 of 16,422 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14693Medium
    SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization
    CVSS 5.4
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  2. CVE-2026-14692Medium
    SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php save_shop_type sql injection
    CVSS 6.3
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  3. CVE-2026-14691Medium
    SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSettings.php update_settings_info code injection
    CVSS 6.3
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  4. CVE-2026-14570High
    Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
    CVSS 7.5
    TIMLEGGE/Crypt::DSAgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-14690High
    SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization
    CVSS 7.3
    SourceCodester/Multi-Vendor Online Grocery Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  6. CVE-2026-14689Medium
    CodeAstro Apartment Visitor Management System add-apartment.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 7, 2026View HOL analysis
  7. CVE-2026-14688High
    itsourcecode Online Hotel Management System login.php sql injection
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  8. CVE-2026-14687Medium
    666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
    CVSS 5.3
    666ghj/BettaFishgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  9. CVE-2026-14686Low
    HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  10. CVE-2026-14685Low
    HdrHistogram AbstractHistogram AbstractHistogram.java recordValueWithCount state issue
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  11. CVE-2026-14684Low
    HdrHistogram AbstractHistogram.java memory allocation
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  12. CVE-2026-14683Low
    HdrHistogram AbstractHistogram.java memory allocation
    CVSS 3.3
    n/a/HdrHistogramgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 16, 2026View HOL analysis
  13. CVE-2026-14660High
    code-projects Online Job Portal login.php sql injection
    CVSS 7.3
    code-projects/Online Job Portalgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  14. CVE-2026-14659Medium
    itsourcecode Hospital Management System patientappointment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  15. CVE-2026-14658Medium
    code-projects Assessment Management marking-scheme.php sql injection
    CVSS 6.3
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  16. CVE-2026-14657Medium
    code-projects Assessment Management Database Query marking-scheme.php sql injection
    CVSS 6.3
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  17. CVE-2026-14656Medium
    code-projects Assessment Management remove-user.php cross site scripting
    CVSS 4.3
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  18. CVE-2026-14655Low
    code-projects Assessment Management view-users.php cross site scripting
    CVSS 2.4
    code-projects/Assessment Managementgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  19. CVE-2026-14654High
    SourceCodester Simple and Nice Shopping Cart Script girlsproductdeletequery.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  20. CVE-2026-14653High
    SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  21. CVE-2024-1248Medium
    Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
    CVSS 4.8
    WSO2/WSO2 API Manager, WSO2/WSO2 Identity Server +3generic
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  22. CVE-2026-14652High
    SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  23. CVE-2026-14651Low
    connorskees grass visitor denial of service
    CVSS 3.3
    connorskees/grassgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  24. CVE-2026-14650Low
    connorskees grass UTF-8 Character raw_to_parse_error denial of service
    CVSS 3.3
    connorskees/grassgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  25. CVE-2026-14649High
    code-projects Online Voting System saveVote.php test_input sql injection
    CVSS 7.3
    code-projects/Online Voting Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  26. CVE-2026-14648High
    code-projects Online Voting System Login authentication.php test_input sql injection
    CVSS 7.3
    code-projects/Online Voting Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  27. CVE-2026-14647Medium
    onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
    CVSS 4.3
    n/a/onnxgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  28. CVE-2026-14642High
    SourceCodester Class and Exam Timetabling System edit_class2.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  29. CVE-2026-14641High
    SourceCodester Class and Exam Timetabling System edit_course.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  30. CVE-2026-14640High
    CodeAstro Apartment Visitor Management System Login index.php sql injection
    CVSS 7.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  31. CVE-2026-14639Medium
    CodeAstro Ecommerce Website my_account.php sql injection
    CVSS 6.3
    CodeAstro/Ecommerce Websitegeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  32. CVE-2026-12740High
    Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter
    CVSS 8.1
    CORNELIUS/Plack::Middleware::OAuthgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  33. CVE-2026-12746High
    Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter
    CVSS 8.1
    BIAFRA/Dancer2::Plugin::Auth::OAuth::Providergeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-14638Medium
    itsourcecode Hospital Management System patient.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  35. CVE-2026-14637High
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserialization
    CVSS 8.2
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  36. CVE-2026-14636Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversal
    CVSS 5.4
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  37. CVE-2026-14635High
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
    CVSS 7.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  38. CVE-2026-14634Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Controller.php checkForPostRequests cross site scripting
    CVSS 4.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  39. CVE-2026-14633Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scripting
    CVSS 4.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 7, 2026View HOL analysis
  40. CVE-2026-14632Medium
    kirilkirkov Ecommerce-CodeIgniter-Bootstrap Trusted Backend MY_Controller.php setReferrer redirect
    CVSS 4.3
    kirilkirkov/Ecommerce-CodeIgniter-Bootstrapgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  41. CVE-2026-14630Low
    ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
    CVSS 3.1
    ForceInjection/AI-fundermentalsgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  42. CVE-2026-14535High
    Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()
    CVSS 8.8
    trailofbits/ficklinggeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-14534High
    Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)
    CVSS 8.8
    trailofbits/ficklinggeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-14629Medium
    RT-Thread Parameter lwp_syscall.c sys_ioctl divide by zero
    CVSS 4.3
    n/a/RT-Threadgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  45. CVE-2026-14628Medium
    NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
    CVSS 5.3
    NousResearch/hermes-agentgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  46. CVE-2025-13475Low
    Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure
    CVSS 3.5
    WSO2/WSO2 API Manager, WSO2/WSO2 Identity Servergeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  47. CVE-2026-14627Medium
    NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
    CVSS 5.6
    NousResearch/hermes-agentgeneric
    PublishedJul 4, 2026First seen at HOL Jul 4, 2026Updated Jul 6, 2026View HOL analysis
  48. CVE-2026-12196High
    HestiaCP Admin Takeover
    CVSS 8.3
    hestiacp/hestiacpgeneric
    PublishedJul 4, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-14626Medium
    NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service
    CVSS 4.3
    NousResearch/hermes-agentgeneric
    PublishedJul 4, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  50. CVE-2026-53362Unknown severity
    ipv6: account for fraggap on the paged allocation path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 101 of 329
Previous99100101102103Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard