1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:50 PM 16,919 active 1,443 known exploited

Catalog summary

16,919

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:50 PM 16,919 active 1,443 known exploited

Catalog summary

16,919

Active CVEs

8,493

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,851–5,900 of 16,919 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13454Medium
    MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter
    CVSS 6.5
    jetmonsters/MotoPress Appointment Bookinggeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  2. CVE-2026-10538High
    Improper deserialization handling in Control-M Components
    CVSS 8.0
    BMC/Control-M/Enterprise Manager, BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  3. CVE-2026-10539Critical
    Unauthenticated command injection in Control-M/Server communication command
    CVSS 9.0
    BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  4. CVE-2026-12158High
    RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter
    CVSS 8.8
    metagauss/RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Logingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  5. CVE-2026-13733Medium
    Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  6. CVE-2026-11387Critical
    SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
    CVSS 9.8
    cozyvision1/SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recoverygeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  7. CVE-2026-12408Medium
    Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
    CVSS 4.3
    rilwis/Slim SEO – A Fast & Automated SEO Plugin For WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  8. CVE-2026-10096Medium
    Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
    CVSS 4.3
    qodeinteractive/Qi Blocksgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  9. CVE-2026-12435Medium
    Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter
    CVSS 4.3
    stylemix/Motors – Car Dealership & Classified Listings Plugingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  10. CVE-2026-12732Medium
    LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute
    CVSS 6.4
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  11. CVE-2026-10540Medium
    Weak password hash protection in Control-M/Entreprise Manager
    CVSS 5.6
    BMC/Control-M/Enterprise Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  12. CVE-2026-12577High
    DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
    CVSS 8.7
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  13. CVE-2026-12576High
    DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  14. CVE-2026-12575High
    DVP80ES3 Improper Resource Shutdown or Release Vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  15. CVE-2026-12224High
    Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint
    CVSS 8.8
    wedevs/Dokan Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2026-11887Medium
    Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass
    CVSS 4.3
    Unknown/Salon Booking Systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  17. CVE-2026-11883High
    WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass
    CVSS 7.2
    Unknown/WebAuthn Provider for Two Factorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  18. CVE-2026-11880Low
    Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
    CVSS 3.1
    Unknown/Fluent Formsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  19. CVE-2026-11794High
    Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
    CVSS 8.1
    Unknown/Advanced Form Integration — Connect Forms to 200+ Appsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  20. CVE-2026-11570Medium
    User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name
    CVSS 4.2
    Unknown/User Submitted Postsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  21. CVE-2026-11568High
    Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
    CVSS 7.5
    Unknown/Product Configurator for WooCommercegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  22. CVE-2026-11562Medium
    WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
    CVSS 4.3
    Unknown/WS Form LITEgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  23. CVE-2026-10750High
    Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
    CVSS 8.1
    Unknown/Royal MCPgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  24. CVE-2025-15666Medium
    Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow
    CVSS 5.3
    Open Asset Import Library/Assimpgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  25. CVE-2026-1239High
    Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
    CVSS 7.5
    kstover/Ninja Forms – The Contact Form Builder That Grows With Yougeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  26. CVE-2026-11823High
    BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
    CVSS 7.5
    Repute Infosystems/BookingPress Appointment Booking Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-14193High
    DVP80ES300T - Improper Validation of Array Index Vulnerability
    CVSS 7.5
    deltaww/DVP80ES300Tgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  28. CVE-2026-12579High
    AS228T - Authentication Bypass Vulnerability
    CVSS 7.4
    deltaww/AS228Tgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  29. CVE-2026-11380Medium
    JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting
    CVSS 6.4
    jetmonsters/JetWidgets For Elementorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  30. CVE-2026-12127Medium
    WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name
    CVSS 5.3
    smub/WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & Moregeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  31. CVE-2026-11988Medium
    LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter
    CVSS 6.5
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  32. CVE-2026-11981Medium
    GiveWP <= 4.15.3 - Cross-Site Request Forgery
    CVSS 4.3
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  33. CVE-2026-2387Medium
    Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode
    CVSS 6.4
    stephenharris/Event Organisergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-12113Medium
    Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure
    CVSS 4.3
    codepeople/Appointment Booking Calendargeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-12135Medium
    FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode
    CVSS 6.4
    foliovision/FV Flowplayer Video Playergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  36. CVE-2026-12090Medium
    Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter
    CVSS 6.5
    taskbuilder/Taskbuilder – Project Management & Task Management Tool With Kanban Boardgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  37. CVE-2026-12923High
    Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter
    CVSS 7.5
    emarket-design/Video Gallery – YouTube Gallery, Playlist & Video Gridgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  38. CVE-2026-13015Medium
    WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter
    CVSS 6.1
    jgwhite33/WP Google Review Slidergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-12902Medium
    Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions
    CVSS 4.3
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-12110Medium
    Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter
    CVSS 6.5
    taskbuilder/Taskbuilder – Project Management & Task Management Tool With Kanban Boardgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  41. CVE-2026-13443Medium
    Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title
    CVSS 6.4
    themeum/Tutor LMS – eLearning and online course solutiongeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  42. CVE-2026-13468High
    Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint
    CVSS 7.5
    themeisle/Visualizer – Tables & Charts Manager with Built-in AI Generatorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  43. CVE-2026-12904Medium
    Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter
    CVSS 4.3
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  44. CVE-2026-13731High
    WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter
    CVSS 7.2
    quantumcloud/WPBot – AI ChatBot for Live Support, Lead Generation, AI Servicesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  45. CVE-2026-13246Medium
    GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute
    CVSS 6.4
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  46. CVE-2026-12133Medium
    JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action
    CVSS 4.3
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  47. CVE-2026-7840Critical
    UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)
    CVSS 9.8
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-7839Critical
    UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access
    CVSS 9.1
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-7838High
    UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length
    CVSS 8.8
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2026-7831High
    UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
    CVSS 7.6
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
Page 118 of 339
Previous116117118119120Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,493

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,851–5,900 of 16,919 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13454Medium
    MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter
    CVSS 6.5
    jetmonsters/MotoPress Appointment Bookinggeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  2. CVE-2026-10538High
    Improper deserialization handling in Control-M Components
    CVSS 8.0
    BMC/Control-M/Enterprise Manager, BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  3. CVE-2026-10539Critical
    Unauthenticated command injection in Control-M/Server communication command
    CVSS 9.0
    BMC/Control-M/Servergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  4. CVE-2026-12158High
    RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter
    CVSS 8.8
    metagauss/RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Logingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  5. CVE-2026-13733Medium
    Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  6. CVE-2026-11387Critical
    SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
    CVSS 9.8
    cozyvision1/SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recoverygeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  7. CVE-2026-12408Medium
    Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
    CVSS 4.3
    rilwis/Slim SEO – A Fast & Automated SEO Plugin For WordPressgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  8. CVE-2026-10096Medium
    Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
    CVSS 4.3
    qodeinteractive/Qi Blocksgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  9. CVE-2026-12435Medium
    Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter
    CVSS 4.3
    stylemix/Motors – Car Dealership & Classified Listings Plugingeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  10. CVE-2026-12732Medium
    LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute
    CVSS 6.4
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  11. CVE-2026-10540Medium
    Weak password hash protection in Control-M/Entreprise Manager
    CVSS 5.6
    BMC/Control-M/Enterprise Managergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  12. CVE-2026-12577High
    DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
    CVSS 8.7
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  13. CVE-2026-12576High
    DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  14. CVE-2026-12575High
    DVP80ES3 Improper Resource Shutdown or Release Vulnerability
    CVSS 7.5
    deltaww/DVP80ES3generic
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  15. CVE-2026-12224High
    Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint
    CVSS 8.8
    wedevs/Dokan Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2026-11887Medium
    Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass
    CVSS 4.3
    Unknown/Salon Booking Systemgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  17. CVE-2026-11883High
    WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass
    CVSS 7.2
    Unknown/WebAuthn Provider for Two Factorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  18. CVE-2026-11880Low
    Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
    CVSS 3.1
    Unknown/Fluent Formsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  19. CVE-2026-11794High
    Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
    CVSS 8.1
    Unknown/Advanced Form Integration — Connect Forms to 200+ Appsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  20. CVE-2026-11570Medium
    User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name
    CVSS 4.2
    Unknown/User Submitted Postsgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  21. CVE-2026-11568High
    Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
    CVSS 7.5
    Unknown/Product Configurator for WooCommercegeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  22. CVE-2026-11562Medium
    WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
    CVSS 4.3
    Unknown/WS Form LITEgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  23. CVE-2026-10750High
    Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
    CVSS 8.1
    Unknown/Royal MCPgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  24. CVE-2025-15666Medium
    Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow
    CVSS 5.3
    Open Asset Import Library/Assimpgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  25. CVE-2026-1239High
    Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
    CVSS 7.5
    kstover/Ninja Forms – The Contact Form Builder That Grows With Yougeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  26. CVE-2026-11823High
    BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
    CVSS 7.5
    Repute Infosystems/BookingPress Appointment Booking Progeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-14193High
    DVP80ES300T - Improper Validation of Array Index Vulnerability
    CVSS 7.5
    deltaww/DVP80ES300Tgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  28. CVE-2026-12579High
    AS228T - Authentication Bypass Vulnerability
    CVSS 7.4
    deltaww/AS228Tgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  29. CVE-2026-11380Medium
    JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting
    CVSS 6.4
    jetmonsters/JetWidgets For Elementorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  30. CVE-2026-12127Medium
    WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name
    CVSS 5.3
    smub/WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & Moregeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  31. CVE-2026-11988Medium
    LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter
    CVSS 6.5
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  32. CVE-2026-11981Medium
    GiveWP <= 4.15.3 - Cross-Site Request Forgery
    CVSS 4.3
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  33. CVE-2026-2387Medium
    Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode
    CVSS 6.4
    stephenharris/Event Organisergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-12113Medium
    Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure
    CVSS 4.3
    codepeople/Appointment Booking Calendargeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-12135Medium
    FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode
    CVSS 6.4
    foliovision/FV Flowplayer Video Playergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  36. CVE-2026-12090Medium
    Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter
    CVSS 6.5
    taskbuilder/Taskbuilder – Project Management & Task Management Tool With Kanban Boardgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  37. CVE-2026-12923High
    Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter
    CVSS 7.5
    emarket-design/Video Gallery – YouTube Gallery, Playlist & Video Gridgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  38. CVE-2026-13015Medium
    WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter
    CVSS 6.1
    jgwhite33/WP Google Review Slidergeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-12902Medium
    Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions
    CVSS 4.3
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-12110Medium
    Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter
    CVSS 6.5
    taskbuilder/Taskbuilder – Project Management & Task Management Tool With Kanban Boardgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  41. CVE-2026-13443Medium
    Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title
    CVSS 6.4
    themeum/Tutor LMS – eLearning and online course solutiongeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  42. CVE-2026-13468High
    Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint
    CVSS 7.5
    themeisle/Visualizer – Tables & Charts Manager with Built-in AI Generatorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  43. CVE-2026-12904Medium
    Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter
    CVSS 4.3
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  44. CVE-2026-13731High
    WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter
    CVSS 7.2
    quantumcloud/WPBot – AI ChatBot for Live Support, Lead Generation, AI Servicesgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  45. CVE-2026-13246Medium
    GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute
    CVSS 6.4
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  46. CVE-2026-12133Medium
    JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action
    CVSS 4.3
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 1, 2026View HOL analysis
  47. CVE-2026-7840Critical
    UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)
    CVSS 9.8
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-7839Critical
    UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access
    CVSS 9.1
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-7838High
    UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length
    CVSS 8.8
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2026-7831High
    UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
    CVSS 7.6
    uvnc/UltraVNCgeneric
    PublishedJul 1, 2026First seen at HOL Jul 1, 2026Updated Jul 9, 2026View HOL analysis
Page 118 of 339
Previous116117118119120Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard