1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 12:05 PM 16,512 active 1,443 known exploited

Catalog summary

16,512

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 12:05 PM 16,512 active 1,443 known exploited

Catalog summary

16,512

Active CVEs

8,473

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,451–5,500 of 16,512 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13706High
    UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG
    CVSS 8.8
    Wikimedia Foundation/UrlShortenergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-14330Medium
    Pipewire: pulse server alloca stack overflow
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  3. CVE-2026-14324Medium
    Pipewire: raop rtsp null deref
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  4. CVE-2026-2891High
    Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
    CVSS 8.2
    HP Inc/CCX, HP Inc/Edge E +1generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  5. CVE-2026-12374Medium
    Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
    CVSS 6.4
    Cato Networks/SDP Clientgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  6. CVE-2026-23537Critical
    Feast: unauthenticated arbitrary file write
    CVSS 9.1
    Feast/Feast Feature Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  7. CVE-2026-13602High
    Session takeover vulnerability
    CVSS 7.7
    pretix/pretix, pretix/pretix-bitpay +6generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  8. CVE-2026-53356Unknown severity
    drm/i915/gem: Fix phys BO pread/pwrite with offset
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-53355Unknown severity
    net: rds: clear i_sends on setup unwind
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-53354Unknown severity
    arm64: errata: Mitigate TLBI errata on various Arm CPUs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-53345Unknown severity
    KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-53341Unknown severity
    fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-53330Unknown severity
    drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-53329Unknown severity
    drm/amd/display: Use krealloc_array() in dal_vector_reserve()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-13603Critical
    SSRF with API key leak in pretix-oppwa
    CVSS 9.0
    pretix/pretix-oppwageneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  16. CVE-2026-14181High
    @fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths
    CVSS 7.5
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  17. CVE-2026-14198Critical
    @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
    CVSS 9.1
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  18. CVE-2026-13323Medium
    CISA ADP Vulnrichment
    CVSS 4.1
    Eclipse Foundation/Eclipse Open VSXgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-12142High
    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter
    CVSS 7.2
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  20. CVE-2026-13228High
    LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
    CVSS 8.8
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  21. CVE-2026-10095Medium
    WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
    CVSS 6.4
    opajaap/WP Photo Album Plusgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  22. CVE-2026-14258Medium
    Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  23. CVE-2026-27435Medium
    WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
    CVSS 5.3
    WofficeIO/Wofficegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  24. CVE-2026-12754Medium
    VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter
    CVSS 6.1
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  25. CVE-2026-13454Medium
    MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter
    CVSS 6.5
    jetmonsters/MotoPress Appointment Bookinggeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  26. CVE-2026-10538High
    Improper deserialization handling in Control-M Components
    CVSS 8.0
    BMC/Control-M/Enterprise Manager, BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  27. CVE-2026-10539Critical
    Unauthenticated command injection in Control-M/Server communication command
    CVSS 9.0
    BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  28. CVE-2026-12158High
    RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter
    CVSS 8.8
    metagauss/RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Logingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  29. CVE-2026-13733Medium
    Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  30. CVE-2026-11387Critical
    SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
    CVSS 9.8
    cozyvision1/SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recoverygeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  31. CVE-2026-12408Medium
    Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
    CVSS 4.3
    rilwis/Slim SEO – A Fast & Automated SEO Plugin For WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  32. CVE-2026-10096Medium
    Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
    CVSS 4.3
    qodeinteractive/Qi Blocksgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  33. CVE-2026-12435Medium
    Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter
    CVSS 4.3
    stylemix/Motors – Car Dealership & Classified Listings Plugingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-12732Medium
    LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute
    CVSS 6.4
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-10540Medium
    Weak password hash protection in Control-M/Entreprise Manager
    CVSS 5.6
    BMC/Control-M/Enterprise Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  36. CVE-2026-12577High
    DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
    CVSS 8.7
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  37. CVE-2026-12576High
    DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  38. CVE-2026-12575High
    DVP80ES3 Improper Resource Shutdown or Release Vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-12224High
    Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint
    CVSS 8.8
    wedevs/Dokan Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-11887Medium
    Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass
    CVSS 4.3
    Unknown/Salon Booking Systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  41. CVE-2026-11883High
    WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass
    CVSS 7.2
    Unknown/WebAuthn Provider for Two Factorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  42. CVE-2026-11880Low
    Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
    CVSS 3.1
    Unknown/Fluent Formsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  43. CVE-2026-11794High
    Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
    CVSS 8.1
    Unknown/Advanced Form Integration — Connect Forms to 200+ Appsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  44. CVE-2026-11570Medium
    User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name
    CVSS 4.2
    Unknown/User Submitted Postsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  45. CVE-2026-11568High
    Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
    CVSS 7.5
    Unknown/Product Configurator for WooCommercegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  46. CVE-2026-11562Medium
    WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
    CVSS 4.3
    Unknown/WS Form LITEgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  47. CVE-2026-10750High
    Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
    CVSS 8.1
    Unknown/Royal MCPgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  48. CVE-2025-15666Medium
    Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow
    CVSS 5.3
    Open Asset Import Library/Assimpgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  49. CVE-2026-1239High
    Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
    CVSS 7.5
    kstover/Ninja Forms – The Contact Form Builder That Grows With Yougeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  50. CVE-2026-11823High
    BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
    CVSS 7.5
    Repute Infosystems/BookingPress Appointment Booking Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
Page 110 of 331
Previous108109110111112Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,473

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,451–5,500 of 16,512 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13706High
    UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG
    CVSS 8.8
    Wikimedia Foundation/UrlShortenergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-14330Medium
    Pipewire: pulse server alloca stack overflow
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  3. CVE-2026-14324Medium
    Pipewire: raop rtsp null deref
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  4. CVE-2026-2891High
    Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
    CVSS 8.2
    HP Inc/CCX, HP Inc/Edge E +1generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  5. CVE-2026-12374Medium
    Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
    CVSS 6.4
    Cato Networks/SDP Clientgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  6. CVE-2026-23537Critical
    Feast: unauthenticated arbitrary file write
    CVSS 9.1
    Feast/Feast Feature Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  7. CVE-2026-13602High
    Session takeover vulnerability
    CVSS 7.7
    pretix/pretix, pretix/pretix-bitpay +6generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  8. CVE-2026-53356Unknown severity
    drm/i915/gem: Fix phys BO pread/pwrite with offset
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-53355Unknown severity
    net: rds: clear i_sends on setup unwind
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-53354Unknown severity
    arm64: errata: Mitigate TLBI errata on various Arm CPUs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-53345Unknown severity
    KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-53341Unknown severity
    fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-53330Unknown severity
    drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-53329Unknown severity
    drm/amd/display: Use krealloc_array() in dal_vector_reserve()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-13603Critical
    SSRF with API key leak in pretix-oppwa
    CVSS 9.0
    pretix/pretix-oppwageneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  16. CVE-2026-14181High
    @fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths
    CVSS 7.5
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  17. CVE-2026-14198Critical
    @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
    CVSS 9.1
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  18. CVE-2026-13323Medium
    CISA ADP Vulnrichment
    CVSS 4.1
    Eclipse Foundation/Eclipse Open VSXgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-12142High
    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter
    CVSS 7.2
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  20. CVE-2026-13228High
    LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
    CVSS 8.8
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  21. CVE-2026-10095Medium
    WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
    CVSS 6.4
    opajaap/WP Photo Album Plusgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  22. CVE-2026-14258Medium
    Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  23. CVE-2026-27435Medium
    WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
    CVSS 5.3
    WofficeIO/Wofficegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  24. CVE-2026-12754Medium
    VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter
    CVSS 6.1
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  25. CVE-2026-13454Medium
    MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter
    CVSS 6.5
    jetmonsters/MotoPress Appointment Bookinggeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  26. CVE-2026-10538High
    Improper deserialization handling in Control-M Components
    CVSS 8.0
    BMC/Control-M/Enterprise Manager, BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  27. CVE-2026-10539Critical
    Unauthenticated command injection in Control-M/Server communication command
    CVSS 9.0
    BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  28. CVE-2026-12158High
    RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter
    CVSS 8.8
    metagauss/RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Logingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  29. CVE-2026-13733Medium
    Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  30. CVE-2026-11387Critical
    SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
    CVSS 9.8
    cozyvision1/SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recoverygeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  31. CVE-2026-12408Medium
    Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
    CVSS 4.3
    rilwis/Slim SEO – A Fast & Automated SEO Plugin For WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  32. CVE-2026-10096Medium
    Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
    CVSS 4.3
    qodeinteractive/Qi Blocksgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  33. CVE-2026-12435Medium
    Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter
    CVSS 4.3
    stylemix/Motors – Car Dealership & Classified Listings Plugingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-12732Medium
    LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute
    CVSS 6.4
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-10540Medium
    Weak password hash protection in Control-M/Entreprise Manager
    CVSS 5.6
    BMC/Control-M/Enterprise Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  36. CVE-2026-12577High
    DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
    CVSS 8.7
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  37. CVE-2026-12576High
    DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  38. CVE-2026-12575High
    DVP80ES3 Improper Resource Shutdown or Release Vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-12224High
    Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint
    CVSS 8.8
    wedevs/Dokan Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-11887Medium
    Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass
    CVSS 4.3
    Unknown/Salon Booking Systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  41. CVE-2026-11883High
    WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass
    CVSS 7.2
    Unknown/WebAuthn Provider for Two Factorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  42. CVE-2026-11880Low
    Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
    CVSS 3.1
    Unknown/Fluent Formsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  43. CVE-2026-11794High
    Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
    CVSS 8.1
    Unknown/Advanced Form Integration — Connect Forms to 200+ Appsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  44. CVE-2026-11570Medium
    User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name
    CVSS 4.2
    Unknown/User Submitted Postsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  45. CVE-2026-11568High
    Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
    CVSS 7.5
    Unknown/Product Configurator for WooCommercegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  46. CVE-2026-11562Medium
    WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
    CVSS 4.3
    Unknown/WS Form LITEgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  47. CVE-2026-10750High
    Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
    CVSS 8.1
    Unknown/Royal MCPgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  48. CVE-2025-15666Medium
    Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow
    CVSS 5.3
    Open Asset Import Library/Assimpgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  49. CVE-2026-1239High
    Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
    CVSS 7.5
    kstover/Ninja Forms – The Contact Form Builder That Grows With Yougeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  50. CVE-2026-11823High
    BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
    CVSS 7.5
    Repute Infosystems/BookingPress Appointment Booking Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
Page 110 of 331
Previous108109110111112Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard