1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 12:43 AM 17,161 active 1,443 known exploited

Catalog summary

17,161

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 12:43 AM 17,161 active 1,443 known exploited

Catalog summary

17,161

Active CVEs

8,565

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,601–6,650 of 17,161 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12388Medium
    Keycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  2. CVE-2026-4629Medium
    Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-14209Medium
    Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  4. CVE-2026-13766Critical
    DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers
    CVSS 9.8
    EXODIST/DBIx::QuickORMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  5. CVE-2026-14162Critical
    Advantech|Hospital Quering Management - Missing Authentication
    CVSS 9.8
    Advantech/Hospital Quering Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  6. CVE-2026-14161High
    Advantech|Hospital Queuing Management - Sensitive Data Exposure
    CVSS 7.5
    Advantech/Hospital Queuing Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  7. CVE-2026-13316Medium
    Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  8. CVE-2026-10763High
    CISA ADP Vulnrichment
    CVSS 7.0
    Hitachi Energy/PROMOD Vgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  9. CVE-2026-12076Critical
    SQL Injection in Raytha CMS
    CVSS 9.3
    Raytha/Raythageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  10. CVE-2025-7406High
    A Sudo Privilege Escalation Vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  11. CVE-2025-24816Medium
    An Improper Access Control vulnerability in Nokia MantaRay NM
    CVSS 6.5
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2025-24815High
    An unrestricted file upload vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  13. CVE-2026-13149High
    CISA ADP Vulnrichment
    CVSS 7.7
    juliangruber/brace-expansiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2026-12610Medium
    Sssd: use-after-free crash in sssd' 'sssd_pam' process
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  15. CVE-2026-45822Medium
    CISA ADP Vulnrichment
    CVSS 6.6
    SamVerschueren/decode-uri-componentgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  16. CVE-2026-12578High
    DTMSoft - Deserialization of Untrusted Data Vulnerability
    CVSS 8.4
    deltaww/DTMSoftgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  17. CVE-2026-12240High
    Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field
    CVSS 8.0
    qlstudio/Export User Datageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  18. CVE-2026-14164High
    Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026View HOL analysis
  19. CVE-2026-12819Critical
    DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  20. CVE-2026-12818Critical
    DVP-12SE Exposure of Sensitive Information Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  21. CVE-2026-56809Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Ricoh Company, Ltd./Multiple laser printers and MFPs which implement Ricoh Web Image Monitorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-11590High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys
    CVSS 8.6
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2026-11589High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload
    CVSS 8.8
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  24. CVE-2026-11581Medium
    Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
    CVSS 5.9
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  25. CVE-2026-12073Critical
    ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
    CVSS 9.8
    metagauss/ProfileGrid – User Profiles, Groups and Communitiesgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  26. CVE-2026-11367Medium
    PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
    CVSS 6.5
    andrasweb/PixMagix – WordPress Image Editorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  27. CVE-2026-12349Medium
    Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions
    CVSS 5.3
    octagonwebstudio/Premium Addons for KingComposergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  28. CVE-2026-12560Medium
    Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field
    CVSS 4.4
    wpqode/Editorial Rating – Product Review & Rating Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  29. CVE-2026-12114Medium
    Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter
    CVSS 4.4
    wpmart/Team Members – Multi Language Supported Team Plugingeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  30. CVE-2026-14160Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    Samsung Open Source/Escargotgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2026-12243Unknown severity
    Path Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()
    Not scoredSource severity not reported
    nltk/nltk/nltkgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2026-37106Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 21, 2026View HOL analysis
  33. CVE-2026-10648Medium
    NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion
    CVSS 6.2
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  34. CVE-2026-7656High
    Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
    CVSS 8.1
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-34592High
    Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and Infrastructure
    CVSS 7.7
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2026-10647Medium
    Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
    CVSS 5.3
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-57997Medium
    Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration
    CVSS 4.8
    strapi/strapigeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  38. CVE-2026-13758Low
    CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path
    CVSS 3.7
    MIK/CryptXgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  39. CVE-2026-34594High
    Coolify: Authenticated Remote Code Execution via Command Injection in Destination Network Management
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-34597High
    Coolify: Authenticated Host RCE
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  41. CVE-2026-41896High
    Coolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null Secret
    CVSS 7.5
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  42. CVE-2026-13763Critical
    HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF
    CVSS 9.8
    AWS/AWS Application Load Balancergeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  43. CVE-2026-13762Critical
    HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF
    CVSS 9.8
    AWS/Amazon CloudFrontgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  44. CVE-2026-43700Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  45. CVE-2026-43716Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +1generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  46. CVE-2026-43720Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  47. CVE-2026-39868Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  48. CVE-2026-43721High
    CISA ADP Vulnrichment
    CVSS 7.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  49. CVE-2026-39872Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  50. CVE-2026-43717Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +3generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
Page 133 of 344
Previous131132133134135Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,565

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,601–6,650 of 17,161 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12388Medium
    Keycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  2. CVE-2026-4629Medium
    Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-14209Medium
    Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
    CVSS 4.3
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 5, 2026View HOL analysis
  4. CVE-2026-13766Critical
    DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers
    CVSS 9.8
    EXODIST/DBIx::QuickORMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  5. CVE-2026-14162Critical
    Advantech|Hospital Quering Management - Missing Authentication
    CVSS 9.8
    Advantech/Hospital Quering Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  6. CVE-2026-14161High
    Advantech|Hospital Queuing Management - Sensitive Data Exposure
    CVSS 7.5
    Advantech/Hospital Queuing Managementgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  7. CVE-2026-13316Medium
    Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 6, 2026View HOL analysis
  8. CVE-2026-10763High
    CISA ADP Vulnrichment
    CVSS 7.0
    Hitachi Energy/PROMOD Vgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  9. CVE-2026-12076Critical
    SQL Injection in Raytha CMS
    CVSS 9.3
    Raytha/Raythageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  10. CVE-2025-7406High
    A Sudo Privilege Escalation Vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  11. CVE-2025-24816Medium
    An Improper Access Control vulnerability in Nokia MantaRay NM
    CVSS 6.5
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2025-24815High
    An unrestricted file upload vulnerability in Nokia MantaRay NM
    CVSS 7.8
    Nokia/MantaRay NMgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 10, 2026View HOL analysis
  13. CVE-2026-13149High
    CISA ADP Vulnrichment
    CVSS 7.7
    juliangruber/brace-expansiongeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2026-12610Medium
    Sssd: use-after-free crash in sssd' 'sssd_pam' process
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  15. CVE-2026-45822Medium
    CISA ADP Vulnrichment
    CVSS 6.6
    SamVerschueren/decode-uri-componentgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  16. CVE-2026-12578High
    DTMSoft - Deserialization of Untrusted Data Vulnerability
    CVSS 8.4
    deltaww/DTMSoftgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  17. CVE-2026-12240High
    Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field
    CVSS 8.0
    qlstudio/Export User Datageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  18. CVE-2026-14164High
    Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Aug 10, 2026View HOL analysis
  19. CVE-2026-12819Critical
    DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  20. CVE-2026-12818Critical
    DVP-12SE Exposure of Sensitive Information Vulnerability
    CVSS 9.3
    deltaww/DVP-12SEgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  21. CVE-2026-56809Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Ricoh Company, Ltd./Multiple laser printers and MFPs which implement Ricoh Web Image Monitorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-11590High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys
    CVSS 8.6
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2026-11589High
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload
    CVSS 8.8
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  24. CVE-2026-11581Medium
    Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
    CVSS 5.9
    Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  25. CVE-2026-12073Critical
    ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
    CVSS 9.8
    metagauss/ProfileGrid – User Profiles, Groups and Communitiesgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  26. CVE-2026-11367Medium
    PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
    CVSS 6.5
    andrasweb/PixMagix – WordPress Image Editorgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  27. CVE-2026-12349Medium
    Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions
    CVSS 5.3
    octagonwebstudio/Premium Addons for KingComposergeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  28. CVE-2026-12560Medium
    Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field
    CVSS 4.4
    wpqode/Editorial Rating – Product Review & Rating Systemgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 1, 2026View HOL analysis
  29. CVE-2026-12114Medium
    Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter
    CVSS 4.4
    wpmart/Team Members – Multi Language Supported Team Plugingeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  30. CVE-2026-14160Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    Samsung Open Source/Escargotgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  31. CVE-2026-12243Unknown severity
    Path Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()
    Not scoredSource severity not reported
    nltk/nltk/nltkgeneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2026-37106Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJun 30, 2026First seen at HOL Jun 30, 2026Updated Jul 21, 2026View HOL analysis
  33. CVE-2026-10648Medium
    NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion
    CVSS 6.2
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 30, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  34. CVE-2026-7656High
    Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
    CVSS 8.1
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 30, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-34592High
    Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and Infrastructure
    CVSS 7.7
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  36. CVE-2026-10647Medium
    Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
    CVSS 5.3
    zephyrproject/zephyrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-57997Medium
    Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration
    CVSS 4.8
    strapi/strapigeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  38. CVE-2026-13758Low
    CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path
    CVSS 3.7
    MIK/CryptXgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  39. CVE-2026-34594High
    Coolify: Authenticated Remote Code Execution via Command Injection in Destination Network Management
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  40. CVE-2026-34597High
    Coolify: Authenticated Host RCE
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  41. CVE-2026-41896High
    Coolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null Secret
    CVSS 7.5
    coollabsio/coolifygeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  42. CVE-2026-13763Critical
    HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF
    CVSS 9.8
    AWS/AWS Application Load Balancergeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  43. CVE-2026-13762Critical
    HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF
    CVSS 9.8
    AWS/Amazon CloudFrontgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  44. CVE-2026-43700Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  45. CVE-2026-43716Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +1generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  46. CVE-2026-43720Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  47. CVE-2026-39868Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Apple/iOS and iPadOS, Apple/macOS +3generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  48. CVE-2026-43721High
    CISA ADP Vulnrichment
    CVSS 7.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  49. CVE-2026-39872Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +4generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  50. CVE-2026-43717Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Apple/Safari, Apple/iOS and iPadOS +3generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
Page 133 of 344
Previous131132133134135Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard