1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:55 AM 17,161 active 1,443 known exploited

Catalog summary

17,161

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:55 AM 17,161 active 1,443 known exploited

Catalog summary

17,161

Active CVEs

8,565

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,701–6,750 of 17,161 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13742Medium
    Lack of signature verification before execution of downloaded content
    CVSS 5.9
    Honeywell Technologies/IQ MultiAccessgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-13581Medium
    Edimax EW-7478APC POST Request formStaDrvSetup os command injection
    CVSS 6.3
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  3. CVE-2026-13580High
    Edimax EW-7478APC POST Request formQoS buffer overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-13579Medium
    itsourcecode Hospital Management System patientchangepassword.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-13578Medium
    itsourcecode Hospital Management System patientdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13574Low
    llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
    CVSS 3.3
    llvm/llvm-projectgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 7, 2026View HOL analysis
  7. CVE-2026-13573Low
    llvm llvm-project ValueSymbolTable ValueSymbolTable.cpp insert stack-based overflow
    CVSS 3.3
    llvm/llvm-projectgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 7, 2026View HOL analysis
  8. CVE-2026-13572Medium
    itsourcecode Hospital Management System insertbillingrecord.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  9. CVE-2026-13571Medium
    SourceCodester Simple Food Ordering System cart.php logic error
    CVSS 5.3
    SourceCodester/Simple Food Ordering Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  10. CVE-2026-12616Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Eclipse Foundation/Eclipse CSI - PIAgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  11. CVE-2026-13676High
    fast-uri vulnerable to host confusion via failed IDN canonicalization
    CVSS 7.5
    fast-uri, fast-uri/fast-urigeneric · npm
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-11979High
    Stack-Based Buffer Overflow in libxml2
    CVSS 7.8
    xmlsoft/libxml2generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  13. CVE-2026-13570Low
    SourceCodester Inventory Management System User Registration Endpoint users_handler.php cross site scripting
    CVSS 3.5
    SourceCodester/Inventory Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-13569Medium
    weng-xianhu EyouCMS API index.php sql injection
    CVSS 4.7
    weng-xianhu/EyouCMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  15. CVE-2026-13568High
    SourceCodester Inventory Management System User Registration Endpoint users_handler.php access control
    CVSS 7.3
    SourceCodester/Inventory Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2026-54371High
    attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
    CVSS 7.1
    attr project/attrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-54369High
    acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
    CVSS 7.1
    acl project/aclgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-12856High
    Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extension
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-40521High
    FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
    CVSS 8.8
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-13567Medium
    code-projects Online Music Site POST Request Feedback.php cross site scripting
    CVSS 4.3
    code-projects/Online Music Sitegeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  21. CVE-2026-40522High
    FrontAccounting < 2.4.20 SQL Injection via rep601.php
    CVSS 7.1
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-40523High
    FrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php
    CVSS 8.1
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2026-40524High
    FrontAccounting < 2.4.20 SQL Injection via get_gl_transactions()
    CVSS 8.1
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-13165High
    Remote Code Execution in SzafirHost
    CVSS 8.6
    Krajowa Izba Rozliczeniowa/SzafirHostgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  25. CVE-2026-13566High
    SourceCodester Class and Exam Timetabling System preview3.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  26. CVE-2026-13565High
    SourceCodester Class and Exam Timetabling System edit_class1.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  27. CVE-2026-13564High
    Edimax EW-7478APC POST Request formPPPoESetup stack-based overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-13563High
    Edimax EW-7478APC POST Request formL2TPSetup stack-based overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  29. CVE-2026-13562High
    Edimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  30. CVE-2026-13561Medium
    Edimax EW-7478APC POST Request formiNICbasic os command injection
    CVSS 6.3
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-13560Medium
    Edimax EW-7478APC POST Request formAccept os command injection
    CVSS 6.3
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2026-13559High
    code-projects Real State Services single-list_sale.php add sql injection
    CVSS 7.3
    code-projects/Real State Servicesgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-41992High
    Global Buffer Overflow in GNU gzip
    CVSS 7.5
    GNU/gzipgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-41991Medium
    Predictable Temporary File in GNU gzip
    CVSS 4.7
    GNU/gzipgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-13558Low
    CodeAstro Complaint Management System Report addreport cross site scripting
    CVSS 3.5
    CodeAstro/Complaint Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  36. CVE-2026-25707High
    Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp
    CVSS 8.8
    SUSE/libzyppgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  37. CVE-2026-13557Medium
    itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
    CVSS 4.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  38. CVE-2026-13556Medium
    itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
    CVSS 4.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-13555High
    itsourcecode Online Hotel Management System controller.php add sql injection
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2026-13601High
    Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-13554Medium
    itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
    CVSS 4.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  42. CVE-2026-13553High
    itsourcecode Online Hotel Management System controller.php add unrestricted upload
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-13552High
    itsourcecode Online Hotel Management System controller.php edit sql injection
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2026-13551High
    itsourcecode Baptism Information Management System editBaptism.php sql injection
    CVSS 7.3
    itsourcecode/Baptism Information Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-57676Medium
    WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 4.3
    Matteo Manna/Simple User Avatargeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 8, 2026View HOL analysis
  46. CVE-2026-13550High
    itsourcecode Baptism Information Management System delbaptism.php sql injection
    CVSS 7.3
    itsourcecode/Baptism Information Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  47. CVE-2026-13595Medium
    Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 8, 2026View HOL analysis
  48. CVE-2026-22078High
    O+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability.
    CVSS 7.3
    OPPO/O+ Connectgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2026-13549Medium
    CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
    CVSS 5.4
    CodeAstro/Complaint Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  50. CVE-2026-13548Medium
    itsourcecode Hospital Management System doctortimings.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
Page 135 of 344
Previous133134135136137Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,565

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,701–6,750 of 17,161 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13742Medium
    Lack of signature verification before execution of downloaded content
    CVSS 5.9
    Honeywell Technologies/IQ MultiAccessgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-13581Medium
    Edimax EW-7478APC POST Request formStaDrvSetup os command injection
    CVSS 6.3
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  3. CVE-2026-13580High
    Edimax EW-7478APC POST Request formQoS buffer overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-13579Medium
    itsourcecode Hospital Management System patientchangepassword.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-13578Medium
    itsourcecode Hospital Management System patientdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13574Low
    llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
    CVSS 3.3
    llvm/llvm-projectgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 7, 2026View HOL analysis
  7. CVE-2026-13573Low
    llvm llvm-project ValueSymbolTable ValueSymbolTable.cpp insert stack-based overflow
    CVSS 3.3
    llvm/llvm-projectgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 7, 2026View HOL analysis
  8. CVE-2026-13572Medium
    itsourcecode Hospital Management System insertbillingrecord.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  9. CVE-2026-13571Medium
    SourceCodester Simple Food Ordering System cart.php logic error
    CVSS 5.3
    SourceCodester/Simple Food Ordering Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  10. CVE-2026-12616Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Eclipse Foundation/Eclipse CSI - PIAgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  11. CVE-2026-13676High
    fast-uri vulnerable to host confusion via failed IDN canonicalization
    CVSS 7.5
    fast-uri, fast-uri/fast-urigeneric · npm
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-11979High
    Stack-Based Buffer Overflow in libxml2
    CVSS 7.8
    xmlsoft/libxml2generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  13. CVE-2026-13570Low
    SourceCodester Inventory Management System User Registration Endpoint users_handler.php cross site scripting
    CVSS 3.5
    SourceCodester/Inventory Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-13569Medium
    weng-xianhu EyouCMS API index.php sql injection
    CVSS 4.7
    weng-xianhu/EyouCMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  15. CVE-2026-13568High
    SourceCodester Inventory Management System User Registration Endpoint users_handler.php access control
    CVSS 7.3
    SourceCodester/Inventory Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  16. CVE-2026-54371High
    attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
    CVSS 7.1
    attr project/attrgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-54369High
    acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
    CVSS 7.1
    acl project/aclgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-12856High
    Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extension
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-40521High
    FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
    CVSS 8.8
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-13567Medium
    code-projects Online Music Site POST Request Feedback.php cross site scripting
    CVSS 4.3
    code-projects/Online Music Sitegeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  21. CVE-2026-40522High
    FrontAccounting < 2.4.20 SQL Injection via rep601.php
    CVSS 7.1
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-40523High
    FrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php
    CVSS 8.1
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  23. CVE-2026-40524High
    FrontAccounting < 2.4.20 SQL Injection via get_gl_transactions()
    CVSS 8.1
    FrontAccounting/FrontAccountinggeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-13165High
    Remote Code Execution in SzafirHost
    CVSS 8.6
    Krajowa Izba Rozliczeniowa/SzafirHostgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  25. CVE-2026-13566High
    SourceCodester Class and Exam Timetabling System preview3.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  26. CVE-2026-13565High
    SourceCodester Class and Exam Timetabling System edit_class1.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  27. CVE-2026-13564High
    Edimax EW-7478APC POST Request formPPPoESetup stack-based overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-13563High
    Edimax EW-7478APC POST Request formL2TPSetup stack-based overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  29. CVE-2026-13562High
    Edimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow
    CVSS 8.8
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  30. CVE-2026-13561Medium
    Edimax EW-7478APC POST Request formiNICbasic os command injection
    CVSS 6.3
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-13560Medium
    Edimax EW-7478APC POST Request formAccept os command injection
    CVSS 6.3
    Edimax/EW-7478APCgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  32. CVE-2026-13559High
    code-projects Real State Services single-list_sale.php add sql injection
    CVSS 7.3
    code-projects/Real State Servicesgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-41992High
    Global Buffer Overflow in GNU gzip
    CVSS 7.5
    GNU/gzipgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  34. CVE-2026-41991Medium
    Predictable Temporary File in GNU gzip
    CVSS 4.7
    GNU/gzipgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  35. CVE-2026-13558Low
    CodeAstro Complaint Management System Report addreport cross site scripting
    CVSS 3.5
    CodeAstro/Complaint Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  36. CVE-2026-25707High
    Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp
    CVSS 8.8
    SUSE/libzyppgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  37. CVE-2026-13557Medium
    itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
    CVSS 4.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  38. CVE-2026-13556Medium
    itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
    CVSS 4.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-13555High
    itsourcecode Online Hotel Management System controller.php add sql injection
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2026-13601High
    Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
    CVSS 7.1
    Affected software not mappedEcosystem not listed
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-13554Medium
    itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
    CVSS 4.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  42. CVE-2026-13553High
    itsourcecode Online Hotel Management System controller.php add unrestricted upload
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-13552High
    itsourcecode Online Hotel Management System controller.php edit sql injection
    CVSS 7.3
    itsourcecode/Online Hotel Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2026-13551High
    itsourcecode Baptism Information Management System editBaptism.php sql injection
    CVSS 7.3
    itsourcecode/Baptism Information Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-57676Medium
    WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 4.3
    Matteo Manna/Simple User Avatargeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 8, 2026View HOL analysis
  46. CVE-2026-13550High
    itsourcecode Baptism Information Management System delbaptism.php sql injection
    CVSS 7.3
    itsourcecode/Baptism Information Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  47. CVE-2026-13595Medium
    Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jul 8, 2026View HOL analysis
  48. CVE-2026-22078High
    O+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability.
    CVSS 7.3
    OPPO/O+ Connectgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2026-13549Medium
    CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
    CVSS 5.4
    CodeAstro/Complaint Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  50. CVE-2026-13548Medium
    itsourcecode Hospital Management System doctortimings.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
Page 135 of 344
Previous133134135136137Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard