1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 2:45 AM 17,170 active 1,443 known exploited

Catalog summary

17,170

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 2:45 AM 17,170 active 1,443 known exploited

Catalog summary

17,170

Active CVEs

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,801–6,850 of 17,170 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13501Medium
    antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
    CVSS 5.3
    antlr/ANTLR4generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-13500High
    antlr ANTLR4 Grammar Action Block OutputFile.java code injection
    CVSS 7.3
    antlr/ANTLR4generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-13499Medium
    yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
    CVSS 4.3
    yashpokharna2555/restaurent-management-systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-13498High
    yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
    CVSS 7.3
    yashpokharna2555/restaurent-management-systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 30, 2026View HOL analysis
  5. CVE-2026-13497Medium
    itsourcecode Hospital Management System appointment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13496Medium
    itsourcecode Hospital Management System ajaxmedicine.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  7. CVE-2026-13495Medium
    itsourcecode Hospital Management System adminprofile.php sql injection
    CVSS 4.7
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  8. CVE-2026-13493Low
    AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
    CVSS 3.1
    AIDC-AI/ComfyUI-Copilotgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  9. CVE-2026-13491Low
    78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service
    CVSS 3.7
    78/xiaozhi-esp32generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  10. CVE-2026-13490Low
    glpi-project glpi Document document.send.php canViewFile authorization
    CVSS 3.7
    glpi-project/glpigeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 30, 2026View HOL analysis
  11. CVE-2026-13489Low
    78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization
    CVSS 3.1
    78/xiaozhi-esp32generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  12. CVE-2026-13488High
    SourceCodester Class and Exam Timetabling System preview7.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  13. CVE-2026-13487High
    SourceCodester Class and Exam Timetabling System archive.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-13486High
    SourceCodester Class and Exam Timetabling System preview6.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  15. CVE-2026-13485High
    SourceCodester Class and Exam Timetabling System preview.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-13484Medium
    MLflow Experiment-scoped Label Schema CRUD API authorization
    CVSS 5.0
    n/a/MLflowgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jul 1, 2026View HOL analysis
  17. CVE-2026-13483Low
    arc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authenticity
    CVSS 3.1
    arc53/DocsGPTgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-13482Low
    skypilot-org skypilot User ID server.py username.encode weak hash
    CVSS 3.7
    skypilot-org/skypilotgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  19. CVE-2026-10593Medium
    Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-10646High
    Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation
    CVSS 7.4
    zephyrproject/zephyrgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-10644Medium
    Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer
    CVSS 4.2
    zephyrproject/zephyrgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-58049High
    FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()
    CVSS 8.6
    FFmpeg/FFmpeggeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-10643High
    Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)
    CVSS 8.7
    zephyrproject/zephyrgeneric
    PublishedJun 27, 2026First seen at HOL Jun 28, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-45259Medium
    sigqueue(2) missing capability mode restriction
    CVSS 6.5
    FreeBSD/FreeBSDgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  25. CVE-2026-45258High
    Multiple vulnerabilities in the sound(4) mmap path
    CVSS 7.8
    FreeBSD/FreeBSDgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  26. CVE-2026-12399Medium
    Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter
    CVSS 4.4
    jegstudio/Gutenverse – WordPress Blocks, Page Builder & Site Editorgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  27. CVE-2026-3462Medium
    Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
    CVSS 6.5
    reepaydenmark/Frisbii Paygeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-12432Medium
    Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
    CVSS 5.3
    themeisle/Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptionsgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  29. CVE-2026-11597Medium
    Surbma | Infusionsoft Shortcode <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    surbma/Surbma | Infusionsoft Shortcodegeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-13295Medium
    Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter
    CVSS 6.4
    gpriday/Page Builder by SiteOrigingeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-12471Medium
    Spexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation
    CVSS 4.3
    templatescoderthemes/Spexogeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-11773Medium
    Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification
    CVSS 4.3
    masteriyo/Masteriyo LMS – LMS Course Builder, Quizzes & Certificatesgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-11364Medium
    Product Specifications for Woocommerce <= 0.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions
    CVSS 4.3
    dornaweb/Product Specifications for Woocommercegeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  34. CVE-2026-11783Medium
    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU
    CVSS 6.4
    dokaninc/Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsygeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  35. CVE-2026-11987Medium
    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter
    CVSS 4.3
    dokaninc/Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsygeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  36. CVE-2026-10820High
    ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
    CVSS 8.1
    Unknown/Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Contentgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  37. CVE-2026-12404Medium
    NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class
    CVSS 5.3
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  38. CVE-2026-13245Medium
    MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter
    CVSS 6.1
    maxfoundry/MaxButtons – Create buttonsgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  39. CVE-2026-12415Critical
    Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
    CVSS 9.8
    pravel/Invoice Generatorgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2025-59868Medium
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposure
    CVSS 5.5
    HCLSoftware/Traveler for Microsoft Outlookgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 6, 2026View HOL analysis
  41. CVE-2026-13422Medium
    HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers
    CVSS 4.3
    harmonic_design/HD Quizgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-11356Medium
    Ivory Search <= 5.5.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings
    CVSS 4.4
    vinod-dalvi/Ivory Search – WordPress Search Plugingeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-13333Medium
    Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2026-13335Medium
    CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta
    CVSS 6.4
    codepeople/CodePeople Post Map for Google Mapsgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-13331Medium
    Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2023-37524High
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service
    CVSS 7.7
    HCLSoftware/Traveler for Microsoft Outlookgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 6, 2026View HOL analysis
  47. CVE-2026-31928High
    Daktronics Controller Firmware Use of Hard-coded Credentials
    CVSS 8.1
    Daktronics/DMP-5000, Daktronics/DMP-8000 +1generic
    PublishedJun 26, 2026First seen at HOL Jun 27, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  48. CVE-2026-33560High
    Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
    CVSS 7.1
    Daktronics/DMP-5000, Daktronics/DMP-8000 +1generic
    PublishedJun 26, 2026First seen at HOL Jun 27, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-28701Critical
    Daktronics Controller Firmware Path Traversal
    CVSS 9.8
    Daktronics/DMP-5000, Daktronics/DMP-8000 +1generic
    PublishedJun 26, 2026First seen at HOL Jun 27, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  50. CVE-2026-45807High
    Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints allows arbitrary file read
    CVSS 7.7
    kestra-io/kestrageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026View HOL analysis
Page 137 of 344
Previous135136137138139Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,801–6,850 of 17,170 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-13501Medium
    antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
    CVSS 5.3
    antlr/ANTLR4generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  2. CVE-2026-13500High
    antlr ANTLR4 Grammar Action Block OutputFile.java code injection
    CVSS 7.3
    antlr/ANTLR4generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-13499Medium
    yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
    CVSS 4.3
    yashpokharna2555/restaurent-management-systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-13498High
    yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
    CVSS 7.3
    yashpokharna2555/restaurent-management-systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 30, 2026View HOL analysis
  5. CVE-2026-13497Medium
    itsourcecode Hospital Management System appointment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-13496Medium
    itsourcecode Hospital Management System ajaxmedicine.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  7. CVE-2026-13495Medium
    itsourcecode Hospital Management System adminprofile.php sql injection
    CVSS 4.7
    itsourcecode/Hospital Management Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  8. CVE-2026-13493Low
    AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
    CVSS 3.1
    AIDC-AI/ComfyUI-Copilotgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  9. CVE-2026-13491Low
    78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service
    CVSS 3.7
    78/xiaozhi-esp32generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  10. CVE-2026-13490Low
    glpi-project glpi Document document.send.php canViewFile authorization
    CVSS 3.7
    glpi-project/glpigeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 30, 2026View HOL analysis
  11. CVE-2026-13489Low
    78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization
    CVSS 3.1
    78/xiaozhi-esp32generic
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  12. CVE-2026-13488High
    SourceCodester Class and Exam Timetabling System preview7.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  13. CVE-2026-13487High
    SourceCodester Class and Exam Timetabling System archive.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  14. CVE-2026-13486High
    SourceCodester Class and Exam Timetabling System preview6.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  15. CVE-2026-13485High
    SourceCodester Class and Exam Timetabling System preview.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  16. CVE-2026-13484Medium
    MLflow Experiment-scoped Label Schema CRUD API authorization
    CVSS 5.0
    n/a/MLflowgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jul 1, 2026View HOL analysis
  17. CVE-2026-13483Low
    arc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authenticity
    CVSS 3.1
    arc53/DocsGPTgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-13482Low
    skypilot-org skypilot User ID server.py username.encode weak hash
    CVSS 3.7
    skypilot-org/skypilotgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jun 29, 2026View HOL analysis
  19. CVE-2026-10593Medium
    Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-10646High
    Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation
    CVSS 7.4
    zephyrproject/zephyrgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-10644Medium
    Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer
    CVSS 4.2
    zephyrproject/zephyrgeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-58049High
    FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()
    CVSS 8.6
    FFmpeg/FFmpeggeneric
    PublishedJun 28, 2026First seen at HOL Jun 28, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-10643High
    Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)
    CVSS 8.7
    zephyrproject/zephyrgeneric
    PublishedJun 27, 2026First seen at HOL Jun 28, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-45259Medium
    sigqueue(2) missing capability mode restriction
    CVSS 6.5
    FreeBSD/FreeBSDgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  25. CVE-2026-45258High
    Multiple vulnerabilities in the sound(4) mmap path
    CVSS 7.8
    FreeBSD/FreeBSDgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  26. CVE-2026-12399Medium
    Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter
    CVSS 4.4
    jegstudio/Gutenverse – WordPress Blocks, Page Builder & Site Editorgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  27. CVE-2026-3462Medium
    Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
    CVSS 6.5
    reepaydenmark/Frisbii Paygeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  28. CVE-2026-12432Medium
    Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
    CVSS 5.3
    themeisle/Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptionsgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  29. CVE-2026-11597Medium
    Surbma | Infusionsoft Shortcode <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    surbma/Surbma | Infusionsoft Shortcodegeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  30. CVE-2026-13295Medium
    Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter
    CVSS 6.4
    gpriday/Page Builder by SiteOrigingeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  31. CVE-2026-12471Medium
    Spexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation
    CVSS 4.3
    templatescoderthemes/Spexogeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  32. CVE-2026-11773Medium
    Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification
    CVSS 4.3
    masteriyo/Masteriyo LMS – LMS Course Builder, Quizzes & Certificatesgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  33. CVE-2026-11364Medium
    Product Specifications for Woocommerce <= 0.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions
    CVSS 4.3
    dornaweb/Product Specifications for Woocommercegeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  34. CVE-2026-11783Medium
    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU
    CVSS 6.4
    dokaninc/Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsygeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  35. CVE-2026-11987Medium
    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter
    CVSS 4.3
    dokaninc/Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsygeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  36. CVE-2026-10820High
    ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
    CVSS 8.1
    Unknown/Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Contentgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  37. CVE-2026-12404Medium
    NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class
    CVSS 5.3
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  38. CVE-2026-13245Medium
    MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter
    CVSS 6.1
    maxfoundry/MaxButtons – Create buttonsgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  39. CVE-2026-12415Critical
    Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
    CVSS 9.8
    pravel/Invoice Generatorgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  40. CVE-2025-59868Medium
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposure
    CVSS 5.5
    HCLSoftware/Traveler for Microsoft Outlookgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 6, 2026View HOL analysis
  41. CVE-2026-13422Medium
    HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers
    CVSS 4.3
    harmonic_design/HD Quizgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-11356Medium
    Ivory Search <= 5.5.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings
    CVSS 4.4
    vinod-dalvi/Ivory Search – WordPress Search Plugingeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-13333Medium
    Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2026-13335Medium
    CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta
    CVSS 6.4
    codepeople/CodePeople Post Map for Google Mapsgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-13331Medium
    Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2023-37524High
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service
    CVSS 7.7
    HCLSoftware/Traveler for Microsoft Outlookgeneric
    PublishedJun 27, 2026First seen at HOL Jun 29, 2026Updated Jul 6, 2026View HOL analysis
  47. CVE-2026-31928High
    Daktronics Controller Firmware Use of Hard-coded Credentials
    CVSS 8.1
    Daktronics/DMP-5000, Daktronics/DMP-8000 +1generic
    PublishedJun 26, 2026First seen at HOL Jun 27, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  48. CVE-2026-33560High
    Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
    CVSS 7.1
    Daktronics/DMP-5000, Daktronics/DMP-8000 +1generic
    PublishedJun 26, 2026First seen at HOL Jun 27, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-28701Critical
    Daktronics Controller Firmware Path Traversal
    CVSS 9.8
    Daktronics/DMP-5000, Daktronics/DMP-8000 +1generic
    PublishedJun 26, 2026First seen at HOL Jun 27, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  50. CVE-2026-45807High
    Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints allows arbitrary file read
    CVSS 7.7
    kestra-io/kestrageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026View HOL analysis
Page 137 of 344
Previous135136137138139Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard