1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:55 AM 17,161 active 1,443 known exploited

Catalog summary

17,161

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 1:55 AM 17,161 active 1,443 known exploited

Catalog summary

17,161

Active CVEs

8,565

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,751–6,800 of 17,161 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13547High
    Hanwang e-Face General Management Platform upload.do unrestricted upload
    CVSS 7.3
    Hanwang/e-Face General Management Platformgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-13546High
    Feehi CMS REST API Endpoint articles missing authentication
    CVSS 7.3
    Feehi/CMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-13545High
    D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
    CVSS 8.8
    D-Link/DCS-935Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  4. CVE-2026-13544Medium
    Feehi CMS API users access control
    CVSS 6.3
    Feehi/CMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-13543Medium
    Documenso Google OAuth Login handle-oauth-callback-url.ts improper authentication
    CVSS 5.6
    n/a/Documensogeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13542Medium
    itsourcecode Hospital Management System doctorprofile.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  7. CVE-2026-13541Medium
    itsourcecode Hospital Management System doctorchangepassword.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  8. CVE-2026-10083High
    APCu Manager < 4.5.0 - Unauthenticated Stored XSS via Cache Key Pollution
    CVSS 7.5
    Unknown/APCu Managergeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  9. CVE-2025-2902High
    Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform
    CVSS 8.3
    Hitachi/Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H, Hitachi/Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H +1generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  10. CVE-2026-13540Medium
    GitBucket RepositoryCreationService.scala Git.cloneRepository.setURI server-side request forgery
    CVSS 6.3
    n/a/GitBucketgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  11. CVE-2025-0824Low
    lack of validation for firmware update in Hitachi Virtual Storage
    CVSS 3.7
    Hitachi/Hitachi Virtual Storage Platform One Block 23, 24, 26, 28generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  12. CVE-2026-13539High
    Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow
    CVSS 8.8
    Wavlink/WL-NU516U1-Ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  13. CVE-2025-7386Medium
    Information exposure vulnerability in Hitachi Storage Navigator
    CVSS 6.8
    Hitachi/Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8, Hitachi/Hitachi Virtual Storage Platform G1000, G1500, F1500, VX7generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  14. CVE-2026-13538Medium
    Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection
    CVSS 6.3
    Wavlink/WL-NU516U1-Ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  15. CVE-2026-13537Medium
    CodeAstro Human Resource Management System cross-site request forgery
    CVSS 4.3
    CodeAstro/Human Resource Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-13536Medium
    GotoHTTP reg.12x cross site scripting
    CVSS 4.3
    n/a/GotoHTTPgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  17. CVE-2026-13535Medium
    CodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sql injection
    CVSS 6.3
    CodeAstro/Human Resource Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-13534Medium
    CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
    CVSS 5.0
    CherryHQ/cherry-studiogeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  19. CVE-2026-13533Medium
    agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
    CVSS 5.3
    agentejo/Cockpit CMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  20. CVE-2026-13532Medium
    itsourcecode Hospital Management System departmentDoctor.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  21. CVE-2026-13531Medium
    itsourcecode Hospital Management System department.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  22. CVE-2026-13530Medium
    itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2026-13529Medium
    YzmCMS index.php sql injection
    CVSS 5.6
    n/a/YzmCMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  24. CVE-2026-13528High
    YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal
    CVSS 7.3
    YunaiV/ruoyi-vue-pro, zhijiantianya/ruoyi-vue-progeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  25. CVE-2026-13527High
    SourceCodester Class and Exam Timetabling System preview4.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  26. CVE-2026-13526High
    SourceCodester Class and Exam Timetabling System edit_class.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  27. CVE-2026-13525Medium
    CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php emselectByCode sql injection
    CVSS 6.3
    CodeAstro/Human Resource Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-13524Medium
    CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization
    CVSS 5.6
    CherryHQ/cherry-studiogeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  29. CVE-2026-13523Low
    GPAC ISOBMFF base_encoding.c data amplification
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-13522Medium
    Investintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-bounds
    CVSS 4.3
    Investintech/SlimPDFReadergeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-13521High
    SourceCodester Class and Exam Timetabling System preview5.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-13520Medium
    itsourcecode Hospital Management System Appointment appointmentapproval.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-13519High
    Tenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  34. CVE-2026-13518High
    Tenda JD12L addressNat fromAddressNat stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  35. CVE-2026-13517High
    Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  36. CVE-2026-31016Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2026-36848High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  38. CVE-2026-37637Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  39. CVE-2026-13516High
    Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2026-13515High
    Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  41. CVE-2026-13514Low
    Chess Play and Learn App com.chess AndroidManifest.xml backup
    CVSS 2.4
    Chess/Play and Learn Appgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-13513Medium
    MyScale MyScaleDB SegmentId.h getCacheKey data authenticity
    CVSS 5.0
    MyScale/MyScaleDBgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-13512Medium
    Databend Tenant client_session_manager.rs state_key authorization
    CVSS 6.3
    n/a/Databendgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  44. CVE-2026-13511Low
    VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization
    CVSS 3.1
    n/a/VoltAgentgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-13510Low
    SimStudioAI sim Password Protection deployment.ts weak hash
    CVSS 3.7
    SimStudioAI/simgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2026-13509Medium
    RAGapp Knowledge File files.py FileHandler.remove_file path traversal
    CVSS 6.3
    n/a/RAGappgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  47. CVE-2026-13508Medium
    khoj-ai khoj Conversation Sharing api_chat.py authorization
    CVSS 5.5
    khoj-ai/khojgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  48. CVE-2026-13507Medium
    volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 data authenticity
    CVSS 5.0
    volcengine/OpenVikinggeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2026-13504Low
    code-projects Project Management System Mail Compose mail.php cross site scripting
    CVSS 3.5
    code-projects/Project Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 30, 2026View HOL analysis
  50. CVE-2026-13503Medium
    antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
    CVSS 5.3
    antlr/ANTLR4generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
Page 136 of 344
Previous134135136137138Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,565

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,751–6,800 of 17,161 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13547High
    Hanwang e-Face General Management Platform upload.do unrestricted upload
    CVSS 7.3
    Hanwang/e-Face General Management Platformgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-13546High
    Feehi CMS REST API Endpoint articles missing authentication
    CVSS 7.3
    Feehi/CMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-13545High
    D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
    CVSS 8.8
    D-Link/DCS-935Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  4. CVE-2026-13544Medium
    Feehi CMS API users access control
    CVSS 6.3
    Feehi/CMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-13543Medium
    Documenso Google OAuth Login handle-oauth-callback-url.ts improper authentication
    CVSS 5.6
    n/a/Documensogeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13542Medium
    itsourcecode Hospital Management System doctorprofile.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  7. CVE-2026-13541Medium
    itsourcecode Hospital Management System doctorchangepassword.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  8. CVE-2026-10083High
    APCu Manager < 4.5.0 - Unauthenticated Stored XSS via Cache Key Pollution
    CVSS 7.5
    Unknown/APCu Managergeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  9. CVE-2025-2902High
    Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform
    CVSS 8.3
    Hitachi/Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H, Hitachi/Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H +1generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  10. CVE-2026-13540Medium
    GitBucket RepositoryCreationService.scala Git.cloneRepository.setURI server-side request forgery
    CVSS 6.3
    n/a/GitBucketgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  11. CVE-2025-0824Low
    lack of validation for firmware update in Hitachi Virtual Storage
    CVSS 3.7
    Hitachi/Hitachi Virtual Storage Platform One Block 23, 24, 26, 28generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  12. CVE-2026-13539High
    Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow
    CVSS 8.8
    Wavlink/WL-NU516U1-Ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  13. CVE-2025-7386Medium
    Information exposure vulnerability in Hitachi Storage Navigator
    CVSS 6.8
    Hitachi/Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8, Hitachi/Hitachi Virtual Storage Platform G1000, G1500, F1500, VX7generic
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  14. CVE-2026-13538Medium
    Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection
    CVSS 6.3
    Wavlink/WL-NU516U1-Ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  15. CVE-2026-13537Medium
    CodeAstro Human Resource Management System cross-site request forgery
    CVSS 4.3
    CodeAstro/Human Resource Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-13536Medium
    GotoHTTP reg.12x cross site scripting
    CVSS 4.3
    n/a/GotoHTTPgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  17. CVE-2026-13535Medium
    CodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sql injection
    CVSS 6.3
    CodeAstro/Human Resource Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-13534Medium
    CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
    CVSS 5.0
    CherryHQ/cherry-studiogeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  19. CVE-2026-13533Medium
    agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
    CVSS 5.3
    agentejo/Cockpit CMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  20. CVE-2026-13532Medium
    itsourcecode Hospital Management System departmentDoctor.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  21. CVE-2026-13531Medium
    itsourcecode Hospital Management System department.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  22. CVE-2026-13530Medium
    itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  23. CVE-2026-13529Medium
    YzmCMS index.php sql injection
    CVSS 5.6
    n/a/YzmCMSgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  24. CVE-2026-13528High
    YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal
    CVSS 7.3
    YunaiV/ruoyi-vue-pro, zhijiantianya/ruoyi-vue-progeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  25. CVE-2026-13527High
    SourceCodester Class and Exam Timetabling System preview4.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  26. CVE-2026-13526High
    SourceCodester Class and Exam Timetabling System edit_class.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  27. CVE-2026-13525Medium
    CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php emselectByCode sql injection
    CVSS 6.3
    CodeAstro/Human Resource Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-13524Medium
    CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization
    CVSS 5.6
    CherryHQ/cherry-studiogeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  29. CVE-2026-13523Low
    GPAC ISOBMFF base_encoding.c data amplification
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-13522Medium
    Investintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-bounds
    CVSS 4.3
    Investintech/SlimPDFReadergeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-13521High
    SourceCodester Class and Exam Timetabling System preview5.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-13520Medium
    itsourcecode Hospital Management System Appointment appointmentapproval.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-13519High
    Tenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  34. CVE-2026-13518High
    Tenda JD12L addressNat fromAddressNat stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  35. CVE-2026-13517High
    Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  36. CVE-2026-31016Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  37. CVE-2026-36848High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  38. CVE-2026-37637Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJun 29, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  39. CVE-2026-13516High
    Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2026-13515High
    Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
    CVSS 8.8
    Tenda/JD12Lgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  41. CVE-2026-13514Low
    Chess Play and Learn App com.chess AndroidManifest.xml backup
    CVSS 2.4
    Chess/Play and Learn Appgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-13513Medium
    MyScale MyScaleDB SegmentId.h getCacheKey data authenticity
    CVSS 5.0
    MyScale/MyScaleDBgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-13512Medium
    Databend Tenant client_session_manager.rs state_key authorization
    CVSS 6.3
    n/a/Databendgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 30, 2026View HOL analysis
  44. CVE-2026-13511Low
    VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization
    CVSS 3.1
    n/a/VoltAgentgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-13510Low
    SimStudioAI sim Password Protection deployment.ts weak hash
    CVSS 3.7
    SimStudioAI/simgeneric
    PublishedJun 28, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2026-13509Medium
    RAGapp Knowledge File files.py FileHandler.remove_file path traversal
    CVSS 6.3
    n/a/RAGappgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  47. CVE-2026-13508Medium
    khoj-ai khoj Conversation Sharing api_chat.py authorization
    CVSS 5.5
    khoj-ai/khojgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  48. CVE-2026-13507Medium
    volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 data authenticity
    CVSS 5.0
    volcengine/OpenVikinggeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  49. CVE-2026-13504Low
    code-projects Project Management System Mail Compose mail.php cross site scripting
    CVSS 3.5
    code-projects/Project Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 30, 2026View HOL analysis
  50. CVE-2026-13503Medium
    antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
    CVSS 5.3
    antlr/ANTLR4generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
Page 136 of 344
Previous134135136137138Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard