HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 29, 2026, 5:54 AM 40,847 active 1,504 known exploited

Catalog summary

40,847

Active CVEs

21,026

Critical + high

1,504

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,701–5,750 of 40,847 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-89328Low
    FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modification
    CVSS 3.8
    Unknown/FluentBoardsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  2. CVE-2026-89327Low
    FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' Parameter
    CVSS 3.8
    Unknown/FluentBoardsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  3. CVE-2026-88910Medium
    KBoard < 6.7 - Unauthenticated Board Media Deletion via IDOR
    CVSS 5.3
    Unknown/kboardgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  4. CVE-2026-87959Medium
    WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update
    CVSS 5.4
    Unknown/WPBotgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  5. CVE-2026-87907Medium
    Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure via Service and Category REST Routes
    CVSS 5.3
    Unknown/Rox Appointment Bookinggeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  6. CVE-2026-87896Medium
    Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Agent REST Route
    CVSS 5.3
    Unknown/Rox Appointment Bookinggeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  7. CVE-2026-87860Medium
    Subscriptions for WooCommerce < 2.0.3 - Subscription Cancellation via CSRF
    CVSS 4.3
    Unknown/Subscriptions for WooCommercegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  8. CVE-2026-87854Medium
    Subscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass
    CVSS 5.3
    Unknown/Subscriptions for WooCommercegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  9. CVE-2026-87828Medium
    Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Update
    CVSS 5.7
    Unknown/Seraphinite Acceleratorgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  10. CVE-2026-86823Medium
    Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter
    CVSS 5.3
    Unknown/Newslettergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  11. CVE-2026-86784Medium
    Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source
    CVSS 6.8
    Unknown/Visualizergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  12. CVE-2026-86449Medium
    LearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST API
    CVSS 5.3
    Unknown/LearnPressgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  13. CVE-2026-86448Low
    LearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_order
    CVSS 3.7
    Unknown/LearnPressgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  14. CVE-2026-86447Medium
    LearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_content_via_ajax
    CVSS 5.3
    Unknown/LearnPressgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  15. CVE-2026-86445Medium
    LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax
    CVSS 5.3
    Unknown/LearnPressgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  16. CVE-2026-86444High
    LearnPress < 4.4.7 - Reflected XSS via 'skin' Parameter
    CVSS 7.1
    Unknown/LearnPressgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  17. CVE-2026-85641Medium
    Formidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' Parameter
    CVSS 4.3
    Unknown/Formidable Formsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  18. CVE-2026-85572Medium
    Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure
    CVSS 4.3
    Unknown/Tutor LMSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  19. CVE-2026-85569High
    Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification
    CVSS 7.2
    Unknown/Tutor LMSgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  20. CVE-2026-85530High
    GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch
    CVSS 8.1
    Unknown/GiveWPgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  21. CVE-2026-85349Medium
    FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR
    CVSS 4.3
    Unknown/FluentBoardsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  22. CVE-2026-85131Medium
    WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF
    CVSS 6.5
    Unknown/WPLP Cookie Consentgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  23. CVE-2026-84907Low
    Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoint
    CVSS 3.7
    Unknown/Eventingeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  24. CVE-2026-84905Low
    Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation
    CVSS 2.7
    Unknown/Eventingeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  25. CVE-2026-84829High
    Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter
    CVSS 8.8
    Unknown/Optimolegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  26. CVE-2026-84088Medium
    Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget
    CVSS 6.8
    Unknown/Xpro Addons — 140+ Widgets for Elementorgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  27. CVE-2026-82126Low
    Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content Disclosure via AI Schema Generation
    CVSS 2.7
    Unknown/Schema & Structured Data for WP & AMPgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  28. CVE-2026-82125Medium
    Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Content Disclosure via IDOR
    CVSS 5.3
    Unknown/Schema & Structured Data for WP & AMPgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  29. CVE-2026-82124Medium
    Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output
    CVSS 5.3
    Unknown/Schema & Structured Data for WP & AMPgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  30. CVE-2026-78474Medium
    Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter
    CVSS 5.3
    Unknown/Ni WooCommerce Sales Reportgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  31. CVE-2026-78472High
    Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' Parameter
    CVSS 8.6
    Unknown/Ni WooCommerce Sales Reportgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  32. CVE-2026-77702Medium
    Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token
    CVSS 5.3
    Unknown/Eventingeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  33. CVE-2026-76559Medium
    WP Import Export Lite < 3.9.33 - Admin+ SSRF via Import URL Handling
    CVSS 4.1
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  34. CVE-2026-76558Medium
    WP Import Export Lite < 3.9.33 - Contributor+ Stored DOM XSS via Custom Field Names
    CVSS 6.8
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  35. CVE-2026-76557Medium
    WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options
    CVSS 6.8
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  36. CVE-2026-76556Medium
    WP Import Export Lite < 3.9.33 - Authenticated SQLi via Export Filter Rules
    CVSS 6.8
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-76555Medium
    WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File Import Path Traversal
    CVSS 6.8
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-76553Medium
    WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path Traversal
    CVSS 6.5
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  39. CVE-2026-76552High
    WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image Import
    CVSS 8.8
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-76551High
    WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function
    CVSS 7.2
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  41. CVE-2026-76550High
    WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal
    CVSS 7.2
    Unknown/WP Import Export Litegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-74926High
    MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint
    CVSS 7.1
    Unknown/MultiVendorXgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026 Fix availableView HOL analysis
  43. CVE-2026-92358Medium
    Keycloak-services: keycloak-services: residual cross-browser account-link proof allows silent re-linking
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026View HOL analysis
  44. CVE-2026-18555Medium
    Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress <= 2.15.22 - Reflected Cross-Site Scripting via 'icn' Parameter
    CVSS 6.1
    wordplus/Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Botsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 18, 2026View HOL analysis
  45. CVE-2026-89063High
    Online Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter
    CVSS 7.5
    ladela/Online Scheduling and Appointment Booking System – Booklygeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026View HOL analysis
  46. CVE-2026-5920Medium
    Bold Page Builder <= 5.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode_content' Parameter
    CVSS 6.4
    boldthemes/Bold Page Buildergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  47. CVE-2026-11996Medium
    Advanced Popups <= 1.2.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field
    CVSS 6.4
    codesupplyco/Advanced Popupsgeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  48. CVE-2026-18595High
    WP-Lister Lite for eBay <= 3.8.9 - Unauthenticated Stored Cross-Site Scripting via AJAX Cron Handler Request
    CVSS 7.2
    wp-lab/WP-Lister Lite for eBaygeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  49. CVE-2026-78088High
    Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter
    CVSS 8.8
    contest-gallery/Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripegeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 16, 2026View HOL analysis
  50. CVE-2026-12793Critical
    JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter
    CVSS 9.8
    jetmonsters/JetFormBuilder — Dynamic Blocks Form Buildergeneric
    PublishedSep 16, 2026First seen at HOL Sep 16, 2026Updated Sep 17, 2026View HOL analysis
Page 115 of 817
Previous113114115116117Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard