1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 11:50 PM 17,128 active 1,443 known exploited

Catalog summary

17,128

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 11:50 PM 17,128 active 1,443 known exploited

Catalog summary

17,128

Active CVEs

8,546

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,551–6,600 of 17,128 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-27883Medium
    Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure
    CVSS 5.0
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  2. CVE-2026-48192Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Siemens/Mendix Studio Pro 10.11, Siemens/Mendix Studio Pro 10.12 +24generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  3. CVE-2026-27881Medium
    Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} (IDOR)
    CVSS 5.0
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  4. CVE-2026-27882Medium
    Coolify: Timing Attack in GitLab Webhook Token Validation
    CVSS 4.8
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  5. CVE-2026-44947Medium
    Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
    CVSS 6.9
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  6. CVE-2026-14178Medium
    openGauss存在非法内存访问导致DoS漏洞
    CVSS 5.9
    openGauss-server/openGauss-server-7.0.0-RC1, openGauss-server/openGauss-server-7.0.0-RC2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  7. CVE-2026-35098Medium
    Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK
    CVSS 6.9
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  8. CVE-2026-35097Medium
    Weak Password Requirements in KTM System e-BOK
    CVSS 6.9
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  9. CVE-2026-35096Medium
    Cross-Site Request Forgery (CSRF) in KTM System e-BOK
    CVSS 5.1
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  10. CVE-2026-35095Medium
    Session fixation in KTM System e-BOK
    CVSS 4.8
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  11. CVE-2025-53648Medium
    Apache Gravitino: SQL misconfiguration can access or truncate files
    CVSS 5.4
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  12. CVE-2026-14241Critical
    Memory safety bugs fixed in Firefox 152.0.4
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  13. CVE-2026-13474High
    Denial of service via malformed HTTP/2 requests
    CVSS 8.7
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  14. CVE-2026-58016High
    Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
    CVSS 7.5
    GNOME/GLibgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-10817High
    Insufficient input validation leading to memory overread
    CVSS 7.5
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  16. CVE-2026-10816High
    Arbitrary File Read (Unauthenticated)
    CVSS 7.5
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  17. CVE-2026-44946Critical
    SAML Authentication Replay in Rancher
    CVSS 9.5
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  18. CVE-2026-12388Medium
    Keycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  19. CVE-2026-4629Medium
    Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  20. CVE-2026-14209Medium
    Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-13766Critical
    DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers
    CVSS 9.8
    EXODIST/DBIx::QuickORMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  22. CVE-2026-14162Critical
    Advantech|Hospital Quering Management - Missing Authentication
    CVSS 9.8
    Advantech/Hospital Quering Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  23. CVE-2026-14161High
    Advantech|Hospital Queuing Management - Sensitive Data Exposure
    CVSS 7.5
    Advantech/Hospital Queuing Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  24. CVE-2026-13316Medium
    Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  25. CVE-2026-10763High
    CISA ADP Vulnrichment
    CVSS 7.0
    Hitachi Energy/PROMOD Vgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  26. CVE-2026-12076Critical
    SQL Injection in Raytha CMS
    CVSS 9.3
    Raytha/Raythageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  27. CVE-2025-7406High
    A Sudo Privilege Escalation Vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2025-24816Medium
    An Improper Access Control vulnerability in Nokia MantaRay NM
    CVSS 6.5
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  29. CVE-2025-24815High
    An unrestricted file upload vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  30. CVE-2026-13149High
    CISA ADP Vulnrichment
    CVSS 7.7
    juliangruber/brace-expansiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-12610Medium
    Sssd: use-after-free crash in sssd' 'sssd_pam' process
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2026-45822Medium
    CISA ADP Vulnrichment
    CVSS 6.6
    SamVerschueren/decode-uri-componentgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  33. CVE-2026-12578High
    DTMSoft - Deserialization of Untrusted Data Vulnerability
    CVSS 8.4
    deltaww/DTMSoftgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  34. CVE-2026-12240High
    Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field
    CVSS 8.0
    qlstudio/Export User Datageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  35. CVE-2026-14164High
    Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026View HOL analysis
  36. CVE-2026-12819Critical
    DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2026-12818Critical
    DVP-12SE Exposure of Sensitive Information Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  38. CVE-2026-56809Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Ricoh Company, Ltd./Multiple laser printers and MFPs which implement Ricoh Web Image Monitorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-11590High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys
    CVSS 8.6
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  40. CVE-2026-11589High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload
    CVSS 8.8
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  41. CVE-2026-11581Medium
    Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
    CVSS 5.9
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  42. CVE-2026-12073Critical
    ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
    CVSS 9.8
    metagauss/ProfileGrid – User Profiles, Groups and Communitiesgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  43. CVE-2026-11367Medium
    PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
    CVSS 6.5
    andrasweb/PixMagix – WordPress Image Editorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  44. CVE-2026-12349Medium
    Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions
    CVSS 5.3
    octagonwebstudio/Premium Addons for KingComposergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  45. CVE-2026-12560Medium
    Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field
    CVSS 4.4
    wpqode/Editorial Rating – Product Review & Rating Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  46. CVE-2026-12114Medium
    Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter
    CVSS 4.4
    wpmart/Team Members – Multi Language Supported Team Plugingeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  47. CVE-2026-14160Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    Samsung Open Source/Escargotgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  48. CVE-2026-12243Unknown severity
    Path Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()
    Not scoredSource severity not reported
    nltk/nltk/nltkgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  49. CVE-2026-37106Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 21, 2026View HOL analysis
  50. CVE-2026-10648Medium
    NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion
    CVSS 6.2
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 132 of 343
Previous130131132133134Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,546

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,551–6,600 of 17,128 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-27883Medium
    Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure
    CVSS 5.0
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  2. CVE-2026-48192Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Siemens/Mendix Studio Pro 10.11, Siemens/Mendix Studio Pro 10.12 +24generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  3. CVE-2026-27881Medium
    Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} (IDOR)
    CVSS 5.0
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  4. CVE-2026-27882Medium
    Coolify: Timing Attack in GitLab Webhook Token Validation
    CVSS 4.8
    coollabsio/coolifygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  5. CVE-2026-44947Medium
    Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
    CVSS 6.9
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  6. CVE-2026-14178Medium
    openGauss存在非法内存访问导致DoS漏洞
    CVSS 5.9
    openGauss-server/openGauss-server-7.0.0-RC1, openGauss-server/openGauss-server-7.0.0-RC2generic
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  7. CVE-2026-35098Medium
    Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK
    CVSS 6.9
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  8. CVE-2026-35097Medium
    Weak Password Requirements in KTM System e-BOK
    CVSS 6.9
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  9. CVE-2026-35096Medium
    Cross-Site Request Forgery (CSRF) in KTM System e-BOK
    CVSS 5.1
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  10. CVE-2026-35095Medium
    Session fixation in KTM System e-BOK
    CVSS 4.8
    KTM System/e-BOKgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  11. CVE-2025-53648Medium
    Apache Gravitino: SQL misconfiguration can access or truncate files
    CVSS 5.4
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  12. CVE-2026-14241Critical
    Memory safety bugs fixed in Firefox 152.0.4
    CVSS 9.8
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  13. CVE-2026-13474High
    Denial of service via malformed HTTP/2 requests
    CVSS 8.7
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  14. CVE-2026-58016High
    Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
    CVSS 7.5
    GNOME/GLibgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-10817High
    Insufficient input validation leading to memory overread
    CVSS 7.5
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  16. CVE-2026-10816High
    Arbitrary File Read (Unauthenticated)
    CVSS 7.5
    NetScaler/ADC, NetScaler/Gatewaygeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  17. CVE-2026-44946Critical
    SAML Authentication Replay in Rancher
    CVSS 9.5
    SUSE/Ranchergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  18. CVE-2026-12388Medium
    Keycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  19. CVE-2026-4629Medium
    Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  20. CVE-2026-14209Medium
    Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-13766Critical
    DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers
    CVSS 9.8
    EXODIST/DBIx::QuickORMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  22. CVE-2026-14162Critical
    Advantech|Hospital Quering Management - Missing Authentication
    CVSS 9.8
    Advantech/Hospital Quering Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  23. CVE-2026-14161High
    Advantech|Hospital Queuing Management - Sensitive Data Exposure
    CVSS 7.5
    Advantech/Hospital Queuing Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  24. CVE-2026-13316Medium
    Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  25. CVE-2026-10763High
    CISA ADP Vulnrichment
    CVSS 7.0
    Hitachi Energy/PROMOD Vgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  26. CVE-2026-12076Critical
    SQL Injection in Raytha CMS
    CVSS 9.3
    Raytha/Raythageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  27. CVE-2025-7406High
    A Sudo Privilege Escalation Vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2025-24816Medium
    An Improper Access Control vulnerability in Nokia MantaRay NM
    CVSS 6.5
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  29. CVE-2025-24815High
    An unrestricted file upload vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  30. CVE-2026-13149High
    CISA ADP Vulnrichment
    CVSS 7.7
    juliangruber/brace-expansiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-12610Medium
    Sssd: use-after-free crash in sssd' 'sssd_pam' process
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2026-45822Medium
    CISA ADP Vulnrichment
    CVSS 6.6
    SamVerschueren/decode-uri-componentgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  33. CVE-2026-12578High
    DTMSoft - Deserialization of Untrusted Data Vulnerability
    CVSS 8.4
    deltaww/DTMSoftgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  34. CVE-2026-12240High
    Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field
    CVSS 8.0
    qlstudio/Export User Datageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  35. CVE-2026-14164High
    Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026View HOL analysis
  36. CVE-2026-12819Critical
    DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2026-12818Critical
    DVP-12SE Exposure of Sensitive Information Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  38. CVE-2026-56809Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Ricoh Company, Ltd./Multiple laser printers and MFPs which implement Ricoh Web Image Monitorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-11590High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys
    CVSS 8.6
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  40. CVE-2026-11589High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload
    CVSS 8.8
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  41. CVE-2026-11581Medium
    Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
    CVSS 5.9
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  42. CVE-2026-12073Critical
    ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
    CVSS 9.8
    metagauss/ProfileGrid – User Profiles, Groups and Communitiesgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  43. CVE-2026-11367Medium
    PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
    CVSS 6.5
    andrasweb/PixMagix – WordPress Image Editorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  44. CVE-2026-12349Medium
    Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions
    CVSS 5.3
    octagonwebstudio/Premium Addons for KingComposergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  45. CVE-2026-12560Medium
    Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field
    CVSS 4.4
    wpqode/Editorial Rating – Product Review & Rating Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  46. CVE-2026-12114Medium
    Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter
    CVSS 4.4
    wpmart/Team Members – Multi Language Supported Team Plugingeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  47. CVE-2026-14160Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    Samsung Open Source/Escargotgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  48. CVE-2026-12243Unknown severity
    Path Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()
    Not scoredSource severity not reported
    nltk/nltk/nltkgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  49. CVE-2026-37106Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 21, 2026View HOL analysis
  50. CVE-2026-10648Medium
    NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion
    CVSS 6.2
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
Page 132 of 343
Previous130131132133134Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard