1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 1:15 PM 16,240 active 1,443 known exploited

Catalog summary

16,240

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 1:15 PM 16,240 active 1,443 known exploited

Catalog summary

16,240

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 551–600 of 16,240 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-32548Medium
    WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability
    CVSS 5.3
    SureCart/SureCartgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-32469Medium
    WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability
    CVSS 5.3
    WPKube/CAPTCHA 4WPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-28180Medium
    WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 5.3
    Mercado Pago/Mercado Pago payments for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-28179Medium
    WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 5.9
    Damian Góra/FiboSearchgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-28178Medium
    WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    codesupplyco/Powerkitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-28177High
    WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Daniel Iser/Popup Makergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-28172High
    WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerability
    CVSS 7.1
    Data443 Risk Mitigation, Inc./Tracking Code Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-28169Medium
    WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    YITHEMES/YITH WooCommerce Zoom Magnifiergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-28146Medium
    WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerability
    CVSS 6.5
    Unlimited Elements/Unlimited Elements For Elementor (Free Widgets, Addons, Templates)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-28143High
    WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPMU DEV/Forminatorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-28141High
    WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Syed Balkhi/NextGEN Gallerygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-28140High
    WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability
    CVSS 7.5
    jetmonsters/JetFormBuildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-28139Critical
    WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability
    CVSS 9.8
    wpdreams/Ajax Search Litegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-28111High
    WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability
    CVSS 8.8
    WPMU DEV/Forminatorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-28082High
    WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Crocoblock. Jetimpex Inc./JetEnginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-28005Critical
    WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability
    CVSS 9.8
    Nexcess/Kadence WooCommerce Email Designergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-25403Medium
    WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access Control vulnerability
    CVSS 6.5
    bdthemes/Ultimate Store Kit Elementor Addonsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-66712High
    WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability
    CVSS 7.5
    wp.insider/Simple Membershipgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-53976Critical
    OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter
    CVSS 9.1
    Bohdan Triapitsyn/OpenChambergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-15246Medium
    RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass
    CVSS 4.3
    Unknown/RealHomes Membershipsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-19044Medium
    LeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injection
    CVSS 5.3
    LeeSinLiang/godot-mcpgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-70637Medium
    LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
    CVSS 5.9
    hfiref0x/LightFTPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-53975Critical
    OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec
    CVSS 9.8
    Bohdan Triapitsyn/OpenChambergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-54489Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Dell/Virtual Storage Integrator for VMware vSphere Clientgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-67261Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Dell/Virtual Storage Integrator for VMware vSphere Clientgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  26. CVE-2026-64993Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Dell/RVToolsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-5134Critical
    SQLi in Loca Software's CMS
    CVSS 9.8
    Loca Software Informatics Technology Ltd. Co./CMSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-19041Medium
    MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection
    CVSS 6.3
    MissionSquad/mcp-apigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-18501Medium
    UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution
    CVSS 6.4
    stiofansisland/UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-12605Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Eclipse Foundation/Eclipse GlassFishgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2026-19040Medium
    MissionSquad mcp-api dcrClients.ts server-side request forgery
    CVSS 6.3
    MissionSquad/mcp-apigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-16731High
    Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout
    CVSS 8.3
    OMICRON electronics GmbH/OMICRON StationScoutgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-16316Medium
    Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard
    CVSS 4.3
    OMICRON electronics GmbH/OMICRON StationGuardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  34. CVE-2026-16315High
    Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard
    CVSS 8.7
    OMICRON electronics GmbH/OMICRON StationGuardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-19039Medium
    Kino-Kafkaesque ssh-mcp-server SSH index.ts ssh_exec command injection
    CVSS 5.3
    Kino-Kafkaesque/ssh-mcp-servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-66733High
    Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache
    CVSS 7.5
    Eukaryot/sonic3airgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-66732Medium
    Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager
    CVSS 5.9
    Eukaryot/sonic3airgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-65551High
    WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability
    CVSS 7.5
    Soflyy/Breakdancegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  39. CVE-2026-19038Medium
    MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversal
    CVSS 6.3
    MonomythDevelopment/la-forge-mcpgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-15599Low
    Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner
    CVSS 3.3
    TÜBİTAK BİLGEM Software Technologies Research Institute/pardus-domain-joinergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-19037Medium
    WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow
    CVSS 4.3
    n/a/WonderTradergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-0673Medium
    Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection
    CVSS 5.3
    bdthemes/Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addonsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-70556Medium
    Hubzilla 11.2.1 CSRF via OAuth2 /authorize Endpoint App Registration
    CVSS 4.3
    Hubzilla/Hubzillageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-19036High
    Shibby Tomato wanoptions sub_40F88C os command injection
    CVSS 7.2
    Shibby/Tomatogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-19035High
    Shibby Tomato qoslimit new_qoslimit_start os command injection
    CVSS 7.2
    Shibby/Tomatogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-8166Medium
    Stored XSS in Logo Software's e-Logo Purchasing Portal
    CVSS 5.4
    Logo Software Industry and Trade Inc./e-Logo Purchasing Portalgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2025-9266Medium
    Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation
    CVSS 4.3
    themegrill/Accelerategeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2025-15028High
    FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    wpwax/FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & Moregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-11983Medium
    Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax
    CVSS 5.3
    spacetime/Ad Inserter – Ad Manager & AdSense Adsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-5391Medium
    LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    latepoint/Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 12 of 325
Previous1011121314Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 551–600 of 16,240 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-32548Medium
    WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability
    CVSS 5.3
    SureCart/SureCartgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-32469Medium
    WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability
    CVSS 5.3
    WPKube/CAPTCHA 4WPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-28180Medium
    WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 5.3
    Mercado Pago/Mercado Pago payments for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-28179Medium
    WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 5.9
    Damian Góra/FiboSearchgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-28178Medium
    WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    codesupplyco/Powerkitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-28177High
    WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Daniel Iser/Popup Makergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-28172High
    WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerability
    CVSS 7.1
    Data443 Risk Mitigation, Inc./Tracking Code Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-28169Medium
    WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    YITHEMES/YITH WooCommerce Zoom Magnifiergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-28146Medium
    WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerability
    CVSS 6.5
    Unlimited Elements/Unlimited Elements For Elementor (Free Widgets, Addons, Templates)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-28143High
    WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPMU DEV/Forminatorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-28141High
    WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Syed Balkhi/NextGEN Gallerygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-28140High
    WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability
    CVSS 7.5
    jetmonsters/JetFormBuildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-28139Critical
    WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability
    CVSS 9.8
    wpdreams/Ajax Search Litegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-28111High
    WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability
    CVSS 8.8
    WPMU DEV/Forminatorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-28082High
    WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Crocoblock. Jetimpex Inc./JetEnginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-28005Critical
    WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability
    CVSS 9.8
    Nexcess/Kadence WooCommerce Email Designergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-25403Medium
    WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access Control vulnerability
    CVSS 6.5
    bdthemes/Ultimate Store Kit Elementor Addonsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-66712High
    WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability
    CVSS 7.5
    wp.insider/Simple Membershipgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-53976Critical
    OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter
    CVSS 9.1
    Bohdan Triapitsyn/OpenChambergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-15246Medium
    RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass
    CVSS 4.3
    Unknown/RealHomes Membershipsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-19044Medium
    LeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injection
    CVSS 5.3
    LeeSinLiang/godot-mcpgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-70637Medium
    LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
    CVSS 5.9
    hfiref0x/LightFTPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-53975Critical
    OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec
    CVSS 9.8
    Bohdan Triapitsyn/OpenChambergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-54489Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Dell/Virtual Storage Integrator for VMware vSphere Clientgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-67261Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Dell/Virtual Storage Integrator for VMware vSphere Clientgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  26. CVE-2026-64993Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Dell/RVToolsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-5134Critical
    SQLi in Loca Software's CMS
    CVSS 9.8
    Loca Software Informatics Technology Ltd. Co./CMSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-19041Medium
    MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection
    CVSS 6.3
    MissionSquad/mcp-apigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-18501Medium
    UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution
    CVSS 6.4
    stiofansisland/UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-12605Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Eclipse Foundation/Eclipse GlassFishgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2026-19040Medium
    MissionSquad mcp-api dcrClients.ts server-side request forgery
    CVSS 6.3
    MissionSquad/mcp-apigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-16731High
    Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout
    CVSS 8.3
    OMICRON electronics GmbH/OMICRON StationScoutgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-16316Medium
    Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard
    CVSS 4.3
    OMICRON electronics GmbH/OMICRON StationGuardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  34. CVE-2026-16315High
    Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard
    CVSS 8.7
    OMICRON electronics GmbH/OMICRON StationGuardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-19039Medium
    Kino-Kafkaesque ssh-mcp-server SSH index.ts ssh_exec command injection
    CVSS 5.3
    Kino-Kafkaesque/ssh-mcp-servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-66733High
    Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache
    CVSS 7.5
    Eukaryot/sonic3airgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-66732Medium
    Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager
    CVSS 5.9
    Eukaryot/sonic3airgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-65551High
    WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability
    CVSS 7.5
    Soflyy/Breakdancegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  39. CVE-2026-19038Medium
    MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversal
    CVSS 6.3
    MonomythDevelopment/la-forge-mcpgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-15599Low
    Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner
    CVSS 3.3
    TÜBİTAK BİLGEM Software Technologies Research Institute/pardus-domain-joinergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-19037Medium
    WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow
    CVSS 4.3
    n/a/WonderTradergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-0673Medium
    Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection
    CVSS 5.3
    bdthemes/Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addonsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-70556Medium
    Hubzilla 11.2.1 CSRF via OAuth2 /authorize Endpoint App Registration
    CVSS 4.3
    Hubzilla/Hubzillageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-19036High
    Shibby Tomato wanoptions sub_40F88C os command injection
    CVSS 7.2
    Shibby/Tomatogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-19035High
    Shibby Tomato qoslimit new_qoslimit_start os command injection
    CVSS 7.2
    Shibby/Tomatogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-8166Medium
    Stored XSS in Logo Software's e-Logo Purchasing Portal
    CVSS 5.4
    Logo Software Industry and Trade Inc./e-Logo Purchasing Portalgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2025-9266Medium
    Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation
    CVSS 4.3
    themegrill/Accelerategeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2025-15028High
    FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    wpwax/FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & Moregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-11983Medium
    Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax
    CVSS 5.3
    spacetime/Ad Inserter – Ad Manager & AdSense Adsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-5391Medium
    LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    latepoint/Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 12 of 325
Previous1011121314Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard