1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 1:05 PM 16,890 active 1,443 known exploited

Catalog summary

16,890

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 1:05 PM 16,890 active 1,443 known exploited

Catalog summary

16,890

Active CVEs

8,491

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,551–5,600 of 16,890 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14614Medium
    Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Aug 5, 2026View HOL analysis
  2. CVE-2026-14613Medium
    Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-14612Medium
    Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  4. CVE-2026-14460High
    Missing Authorization in TUBITAK BILGEM's pardus-software
    CVSS 8.8
    TUBITAK BILGEM Software Technologies Research Institute/pardus-softwaregeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-14459High
    Argument Injection in TUBITAK BILGEM's pardus-software
    CVSS 8.8
    TUBITAK BILGEM Software Technologies Research Institute/pardus-softwaregeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  6. CVE-2026-46463Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-46464Medium
    CISA ADP Vulnrichment
    CVSS 4.9
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-46465Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-46466Low
    CISA ADP Vulnrichment
    CVSS 2.7
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-46467Medium
    CISA ADP Vulnrichment
    CVSS 5.8
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-46468Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-46730Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-26355Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-41123Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-41124Low
    CISA ADP Vulnrichment
    CVSS 2.3
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  16. CVE-2026-44268Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  17. CVE-2026-44269Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-10055High
    CISA ADP Vulnrichment
    CVSS 8.5
    Eclipse Foundation/Eclipse Theiageneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-13341High
    Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCP
    CVSS 7.4
    KongHQ/mcp-konnectgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-10054High
    CISA ADP Vulnrichment
    CVSS 8.8
    Eclipse Foundation/Eclipse Theiageneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-4322Medium
    XSS in Raera's Destekz
    CVSS 6.1
    Raera - Ankara Web Design and Digital Advertising Agency/Destekzgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  22. CVE-2026-4321Critical
    SQLi in Raera's Destekz
    CVSS 9.8
    Raera - Ankara Web Design and Digital Advertising Agency/Destekzgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  23. CVE-2026-35159Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Dell/14 Plus 2-in-1 DB04250, Dell/14 Plus DB14250 +228generic
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-11398Medium
    LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
    CVSS 5.3
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  25. CVE-2026-4804Medium
    Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API
    CVSS 6.4
    themegrill/Zakrageneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  26. CVE-2026-11778Medium
    CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter
    CVSS 5.4
    villatheme/CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.xgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  27. CVE-2026-11900Medium
    Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute
    CVSS 4.3
    spacetime/Ad Inserter – Ad Manager & AdSense Adsgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  28. CVE-2026-47896High
    Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server
    CVSS 8.9
    Apache Software Foundation/Apache Lucene.Netgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-47897High
    Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client
    CVSS 8.9
    Apache Software Foundation/Apache Lucene.Netgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-47898Critical
    Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser
    CVSS 9.8
    Apache Software Foundation/Apache Lucene.Netgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-14544Critical
    Hplip: incomplete fix for cve-2026-8631
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-12064High
    proto-default skips SSH verification
    CVSS 7.5
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  33. CVE-2026-11856Critical
    cross-origin Digest auth state leak
    CVSS 9.8
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  34. CVE-2026-11586High
    WS Auto-PONG memory exhaustion
    CVSS 7.5
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  35. CVE-2026-11564Critical
    Native CA trust persist
    CVSS 9.1
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  36. CVE-2026-11352High
    QUIC zero-length UDP datagrams busy-loop
    CVSS 7.5
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  37. CVE-2026-10536Critical
    HTTP/2 stream-dependency tree UAF
    CVSS 9.8
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  38. CVE-2026-11397Medium
    WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter
    CVSS 5.5
    vjinfotech/WP Import Export Litegeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  39. CVE-2026-9725Critical
    Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion
    CVSS 9.1
    printcart/Printcart Web to Print Product Designer for WooCommercegeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  40. CVE-2026-13040High
    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter
    CVSS 7.2
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  41. CVE-2026-14352High
    AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter
    CVSS 7.5
    webandprint/AR for WooCommercegeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  42. CVE-2026-12557Medium
    Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints
    CVSS 5.3
    SaturdayDrive/Ninja Forms - File Uploadsgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2022-4989High
    CISA ADP Vulnrichment
    CVSS 8.5
    ASUS/AI Suite 3generic
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  44. CVE-2022-4990High
    CISA ADP Vulnrichment
    CVSS 7.3
    ASUS/AI Suite 3generic
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  45. CVE-2026-12960Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    ASUS/Router appgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  46. CVE-2026-14327High
    AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter
    CVSS 7.5
    webandprint/AR for WordPressgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  47. CVE-2026-12731Medium
    weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes
    CVSS 6.4
    wedevs/weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbotgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  48. CVE-2026-12920Medium
    Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' Parameter
    CVSS 4.9
    wplegalpages/Cookie Banner for GDPR / CCPA – WPLP Cookie Consentgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  49. CVE-2026-12729Medium
    weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action
    CVSS 4.3
    wedevs/weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbotgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  50. CVE-2026-12734Medium
    weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute
    CVSS 6.4
    wedevs/weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbotgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
Page 112 of 338
Previous110111112113114Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,491

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,551–5,600 of 16,890 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14614Medium
    Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Aug 5, 2026View HOL analysis
  2. CVE-2026-14613Medium
    Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-14612Medium
    Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  4. CVE-2026-14460High
    Missing Authorization in TUBITAK BILGEM's pardus-software
    CVSS 8.8
    TUBITAK BILGEM Software Technologies Research Institute/pardus-softwaregeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-14459High
    Argument Injection in TUBITAK BILGEM's pardus-software
    CVSS 8.8
    TUBITAK BILGEM Software Technologies Research Institute/pardus-softwaregeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  6. CVE-2026-46463Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-46464Medium
    CISA ADP Vulnrichment
    CVSS 4.9
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-46465Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-46466Low
    CISA ADP Vulnrichment
    CVSS 2.7
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-46467Medium
    CISA ADP Vulnrichment
    CVSS 5.8
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-46468Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  12. CVE-2026-46730Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-26355Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-41123Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-41124Low
    CISA ADP Vulnrichment
    CVSS 2.3
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  16. CVE-2026-44268Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  17. CVE-2026-44269Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-10055High
    CISA ADP Vulnrichment
    CVSS 8.5
    Eclipse Foundation/Eclipse Theiageneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-13341High
    Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCP
    CVSS 7.4
    KongHQ/mcp-konnectgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-10054High
    CISA ADP Vulnrichment
    CVSS 8.8
    Eclipse Foundation/Eclipse Theiageneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-4322Medium
    XSS in Raera's Destekz
    CVSS 6.1
    Raera - Ankara Web Design and Digital Advertising Agency/Destekzgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  22. CVE-2026-4321Critical
    SQLi in Raera's Destekz
    CVSS 9.8
    Raera - Ankara Web Design and Digital Advertising Agency/Destekzgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  23. CVE-2026-35159Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Dell/14 Plus 2-in-1 DB04250, Dell/14 Plus DB14250 +228generic
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-11398Medium
    LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
    CVSS 5.3
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  25. CVE-2026-4804Medium
    Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API
    CVSS 6.4
    themegrill/Zakrageneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  26. CVE-2026-11778Medium
    CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter
    CVSS 5.4
    villatheme/CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.xgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  27. CVE-2026-11900Medium
    Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute
    CVSS 4.3
    spacetime/Ad Inserter – Ad Manager & AdSense Adsgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  28. CVE-2026-47896High
    Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server
    CVSS 8.9
    Apache Software Foundation/Apache Lucene.Netgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-47897High
    Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client
    CVSS 8.9
    Apache Software Foundation/Apache Lucene.Netgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-47898Critical
    Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser
    CVSS 9.8
    Apache Software Foundation/Apache Lucene.Netgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-14544Critical
    Hplip: incomplete fix for cve-2026-8631
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-12064High
    proto-default skips SSH verification
    CVSS 7.5
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  33. CVE-2026-11856Critical
    cross-origin Digest auth state leak
    CVSS 9.8
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  34. CVE-2026-11586High
    WS Auto-PONG memory exhaustion
    CVSS 7.5
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  35. CVE-2026-11564Critical
    Native CA trust persist
    CVSS 9.1
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  36. CVE-2026-11352High
    QUIC zero-length UDP datagrams busy-loop
    CVSS 7.5
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  37. CVE-2026-10536Critical
    HTTP/2 stream-dependency tree UAF
    CVSS 9.8
    curl/curlgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  38. CVE-2026-11397Medium
    WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter
    CVSS 5.5
    vjinfotech/WP Import Export Litegeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  39. CVE-2026-9725Critical
    Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion
    CVSS 9.1
    printcart/Printcart Web to Print Product Designer for WooCommercegeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  40. CVE-2026-13040High
    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter
    CVSS 7.2
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  41. CVE-2026-14352High
    AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter
    CVSS 7.5
    webandprint/AR for WooCommercegeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  42. CVE-2026-12557Medium
    Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints
    CVSS 5.3
    SaturdayDrive/Ninja Forms - File Uploadsgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2022-4989High
    CISA ADP Vulnrichment
    CVSS 8.5
    ASUS/AI Suite 3generic
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  44. CVE-2022-4990High
    CISA ADP Vulnrichment
    CVSS 7.3
    ASUS/AI Suite 3generic
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  45. CVE-2026-12960Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    ASUS/Router appgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  46. CVE-2026-14327High
    AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter
    CVSS 7.5
    webandprint/AR for WordPressgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  47. CVE-2026-12731Medium
    weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes
    CVSS 6.4
    wedevs/weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbotgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 7, 2026View HOL analysis
  48. CVE-2026-12920Medium
    Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' Parameter
    CVSS 4.9
    wplegalpages/Cookie Banner for GDPR / CCPA – WPLP Cookie Consentgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  49. CVE-2026-12729Medium
    weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action
    CVSS 4.3
    wedevs/weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbotgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
  50. CVE-2026-12734Medium
    weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute
    CVSS 6.4
    wedevs/weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbotgeneric
    PublishedJul 3, 2026First seen at HOL Jul 3, 2026Updated Jul 6, 2026View HOL analysis
Page 112 of 338
Previous110111112113114Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard