1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:50 PM 16,919 active 1,443 known exploited

Catalog summary

16,919

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:50 PM 16,919 active 1,443 known exploited

Catalog summary

16,919

Active CVEs

8,493

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,801–5,850 of 16,919 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-34100Critical
    Guardian Language-System Unauthenticated SQL Injection via id Parameter in media.php
    CVSS 9.8
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-34099Critical
    Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php
    CVSS 9.8
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  3. CVE-2026-27409Medium
    WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability
    CVSS 5.3
    Webba Plugins/Webba Bookinggeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  4. CVE-2026-34098Medium
    Guardian Language-System XSS via id Parameter in media.php
    CVSS 4.6
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  5. CVE-2026-34097Medium
    Guardian Language-System XSS via id Parameter in text_file.php
    CVSS 4.6
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  6. CVE-2026-34096Medium
    Guardian Language-System XSS via name Parameter in designer.php
    CVSS 4.6
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  7. CVE-2026-13211Medium
    Genucenter Disclosure of SNMP Credentials
    CVSS 4.3
    genua/genucentergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  8. CVE-2026-24270Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    NVIDIA/AIStore frameworkgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  9. CVE-2026-24266Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    NVIDIA/Triton Inference Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026View HOL analysis
  10. CVE-2026-24264High
    CISA ADP Vulnrichment
    CVSS 7.5
    NVIDIA/Triton Inference Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026View HOL analysis
  11. CVE-2026-24251High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  12. CVE-2026-24250High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  13. CVE-2026-24249High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  14. CVE-2026-24248High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  15. CVE-2026-24247High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  16. CVE-2026-24246High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  17. CVE-2026-24245High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  18. CVE-2026-24244High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2026-24243High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  20. CVE-2026-24242High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  21. CVE-2026-24240High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2025-23351Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    NVIDIA/BlueField GA, NVIDIA/BlueField LTS22 +8generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  23. CVE-2025-15646Critical
    HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion
    CVSS 9.8
    BPS/HTML::Gumbogeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  24. CVE-2025-23350Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    NVIDIA/BlueField GA, NVIDIA/BlueField LTS22 +6generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  25. CVE-2026-24260High
    CISA ADP Vulnrichment
    CVSS 8.5
    NVIDIA/Container Toolkit, NVIDIA/GPU Operatorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-13707Unknown severity
    Session fixation attacks on improperly configured OAuth 1.0a tools
    Not scoredSource severity not reported
    Wikimedia Foundation/OAuthgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-13706High
    UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG
    CVSS 8.8
    Wikimedia Foundation/UrlShortenergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-14330Medium
    Pipewire: pulse server alloca stack overflow
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  29. CVE-2026-14324Medium
    Pipewire: raop rtsp null deref
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  30. CVE-2026-2891High
    Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
    CVSS 8.2
    HP Inc/CCX, HP Inc/Edge E +1generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  31. CVE-2026-12374Medium
    Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
    CVSS 6.4
    Cato Networks/SDP Clientgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  32. CVE-2026-23537Critical
    Feast: unauthenticated arbitrary file write
    CVSS 9.1
    Feast/Feast Feature Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  33. CVE-2026-13602High
    Session takeover vulnerability
    CVSS 7.7
    pretix/pretix, pretix/pretix-bitpay +6generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  34. CVE-2026-53356Unknown severity
    drm/i915/gem: Fix phys BO pread/pwrite with offset
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-53355Unknown severity
    net: rds: clear i_sends on setup unwind
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-53354Unknown severity
    arm64: errata: Mitigate TLBI errata on various Arm CPUs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-53345Unknown severity
    KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  38. CVE-2026-53341Unknown severity
    fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-53330Unknown severity
    drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-53329Unknown severity
    drm/amd/display: Use krealloc_array() in dal_vector_reserve()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-13603Critical
    SSRF with API key leak in pretix-oppwa
    CVSS 9.0
    pretix/pretix-oppwageneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  42. CVE-2026-14181High
    @fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths
    CVSS 7.5
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  43. CVE-2026-14198Critical
    @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
    CVSS 9.1
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  44. CVE-2026-13323Medium
    CISA ADP Vulnrichment
    CVSS 4.1
    Eclipse Foundation/Eclipse Open VSXgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-12142High
    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter
    CVSS 7.2
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  46. CVE-2026-13228High
    LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
    CVSS 8.8
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  47. CVE-2026-10095Medium
    WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
    CVSS 6.4
    opajaap/WP Photo Album Plusgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  48. CVE-2026-14258Medium
    Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  49. CVE-2026-27435Medium
    WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
    CVSS 5.3
    WofficeIO/Wofficegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  50. CVE-2026-12754Medium
    VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter
    CVSS 6.1
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
Page 117 of 339
Previous115116117118119Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,493

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,801–5,850 of 16,919 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-34100Critical
    Guardian Language-System Unauthenticated SQL Injection via id Parameter in media.php
    CVSS 9.8
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-34099Critical
    Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php
    CVSS 9.8
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  3. CVE-2026-27409Medium
    WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability
    CVSS 5.3
    Webba Plugins/Webba Bookinggeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  4. CVE-2026-34098Medium
    Guardian Language-System XSS via id Parameter in media.php
    CVSS 4.6
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  5. CVE-2026-34097Medium
    Guardian Language-System XSS via id Parameter in text_file.php
    CVSS 4.6
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  6. CVE-2026-34096Medium
    Guardian Language-System XSS via name Parameter in designer.php
    CVSS 4.6
    guardian/language-systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 14, 2026View HOL analysis
  7. CVE-2026-13211Medium
    Genucenter Disclosure of SNMP Credentials
    CVSS 4.3
    genua/genucentergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  8. CVE-2026-24270Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    NVIDIA/AIStore frameworkgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  9. CVE-2026-24266Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    NVIDIA/Triton Inference Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026View HOL analysis
  10. CVE-2026-24264High
    CISA ADP Vulnrichment
    CVSS 7.5
    NVIDIA/Triton Inference Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026View HOL analysis
  11. CVE-2026-24251High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  12. CVE-2026-24250High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  13. CVE-2026-24249High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  14. CVE-2026-24248High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  15. CVE-2026-24247High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  16. CVE-2026-24246High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  17. CVE-2026-24245High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  18. CVE-2026-24244High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2026-24243High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  20. CVE-2026-24242High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  21. CVE-2026-24240High
    CISA ADP Vulnrichment
    CVSS 7.8
    NVIDIA/Megatron-Bridgegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2025-23351Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    NVIDIA/BlueField GA, NVIDIA/BlueField LTS22 +8generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  23. CVE-2025-15646Critical
    HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion
    CVSS 9.8
    BPS/HTML::Gumbogeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  24. CVE-2025-23350Critical
    CISA ADP Vulnrichment
    CVSS 9.0
    NVIDIA/BlueField GA, NVIDIA/BlueField LTS22 +6generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  25. CVE-2026-24260High
    CISA ADP Vulnrichment
    CVSS 8.5
    NVIDIA/Container Toolkit, NVIDIA/GPU Operatorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-13707Unknown severity
    Session fixation attacks on improperly configured OAuth 1.0a tools
    Not scoredSource severity not reported
    Wikimedia Foundation/OAuthgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-13706High
    UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG
    CVSS 8.8
    Wikimedia Foundation/UrlShortenergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-14330Medium
    Pipewire: pulse server alloca stack overflow
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  29. CVE-2026-14324Medium
    Pipewire: raop rtsp null deref
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 22, 2026View HOL analysis
  30. CVE-2026-2891High
    Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
    CVSS 8.2
    HP Inc/CCX, HP Inc/Edge E +1generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  31. CVE-2026-12374Medium
    Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
    CVSS 6.4
    Cato Networks/SDP Clientgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  32. CVE-2026-23537Critical
    Feast: unauthenticated arbitrary file write
    CVSS 9.1
    Feast/Feast Feature Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  33. CVE-2026-13602High
    Session takeover vulnerability
    CVSS 7.7
    pretix/pretix, pretix/pretix-bitpay +6generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  34. CVE-2026-53356Unknown severity
    drm/i915/gem: Fix phys BO pread/pwrite with offset
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-53355Unknown severity
    net: rds: clear i_sends on setup unwind
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-53354Unknown severity
    arm64: errata: Mitigate TLBI errata on various Arm CPUs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-53345Unknown severity
    KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  38. CVE-2026-53341Unknown severity
    fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-53330Unknown severity
    drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-53329Unknown severity
    drm/amd/display: Use krealloc_array() in dal_vector_reserve()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-13603Critical
    SSRF with API key leak in pretix-oppwa
    CVSS 9.0
    pretix/pretix-oppwageneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  42. CVE-2026-14181High
    @fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths
    CVSS 7.5
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  43. CVE-2026-14198Critical
    @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
    CVSS 9.1
    @fastify/middie/@fastify/middiegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  44. CVE-2026-13323Medium
    CISA ADP Vulnrichment
    CVSS 4.1
    Eclipse Foundation/Eclipse Open VSXgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-12142High
    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter
    CVSS 7.2
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  46. CVE-2026-13228High
    LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
    CVSS 8.8
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  47. CVE-2026-10095Medium
    WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
    CVSS 6.4
    opajaap/WP Photo Album Plusgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  48. CVE-2026-14258Medium
    Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  49. CVE-2026-27435Medium
    WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
    CVSS 5.3
    WofficeIO/Wofficegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  50. CVE-2026-12754Medium
    VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter
    CVSS 6.1
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
Page 117 of 339
Previous115116117118119Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard