1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 3:43 AM 17,172 active 1,443 known exploited

Catalog summary

17,172

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 3:43 AM 17,172 active 1,443 known exploited

Catalog summary

17,172

Active CVEs

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,901–6,950 of 17,172 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12411High
    Broken Access Control in Canonical LXD DevLXD API
    CVSS 8.4
    Canonical/lxdgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  2. CVE-2026-45195High
    GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-21734High
    GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
    CVSS 7.7
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-24547Medium
    WordPress SiteGround Email Marketing plugin <= 1.7.5 - Broken Access Control vulnerability
    CVSS 5.3
    SiteGround/SiteGround Email Marketinggeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  5. CVE-2025-68075Medium
    WordPress BNE Testimonials plugin <= 2.0.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Kerry/BNE Testimonialsgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2025-68074Medium
    WordPress Image Carousel plugin <= 1.0.0.41 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    GhozyLab/Image Carouselgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  7. CVE-2025-68064High
    WordPress Goya Core plugin < 1.0.9.4 - Local File Inclusion vulnerability
    CVSS 7.5
    Everthemess/Goya Coregeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2025-68063High
    WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hockey theme <= 4.4.3 - Local File Inclusion vulnerability
    CVSS 7.5
    StylemixThemes/Splash - Sport Club WordPress Theme for Basketball, Football, Hockeygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  9. CVE-2025-68052High
    WordPress Eagle Booking plugin <= 1.3.4.3 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 8.8
    Eagle-Themes/Eagle Bookinggeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2025-66123Medium
    WordPress BookPro plugin <= 1.1.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 5.3
    About Envato/BookProgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2025-64637Medium
    WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability
    CVSS 5.3
    Opal_WP/Auros Coregeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  12. CVE-2025-64636Medium
    WordPress Donation Thermometer plugin <= 2.2.7 - Broken Access Control vulnerability
    CVSS 5.3
    rhewlif/Donation Thermometergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  13. CVE-2025-63079Medium
    WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Control vulnerability
    CVSS 4.3
    bdthemes/Live Copy Paste for Elementorgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  14. CVE-2025-63078Medium
    WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Control vulnerability
    CVSS 4.3
    jetmonsters/Restaurant Menu by MotoPressgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  15. CVE-2025-63041Medium
    WordPress Forget About Shortcode Buttons plugin <= 2.1.3 - Broken Access Control vulnerability
    CVSS 5.4
    Code Amp/Forget About Shortcode Buttonsgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  16. CVE-2026-45257High
    Arbitrary file overwrite via the KTLS receive path
    CVSS 7.8
    FreeBSD/FreeBSDgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  17. CVE-2026-4339Medium
    SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server
    CVSS 6.5
    Mattermost/Mattermostgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-45256Medium
    Missing permission check in thr_kill2(2)
    CVSS 5.5
    FreeBSD/FreeBSDgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  19. CVE-2026-3472Low
    Markdown image rendering bypass in AI bot tool result posts in Mattermost
    CVSS 3.5
    Mattermost/Mattermostgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  20. CVE-2026-13426Medium
    Client4 fails to validate path parameters
    CVSS 5.4
    Mattermost/github.com/mattermost/mattermost/server/publicgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  21. CVE-2026-40711High
    CISA ADP Vulnrichment
    CVSS 8.0
    Dell/Container Storage Modulesgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  22. CVE-2025-64152Critical
    Apache IoTDB: Path Traversal Vulnerability
    CVSS 9.1
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  23. CVE-2025-55017Critical
    Apache IoTDB: Path Traversal Vulnerability
    CVSS 9.1
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  24. CVE-2025-7958High
    CISA ADP Vulnrichment
    CVSS 7.1
    Trellix/Trellix Network Security NX, EX, FX, AX, and CMSgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  25. CVE-2026-11702High
    Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes
    CVSS 7.5
    DAVIDO/Bytes::Random::Secure::Tinygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026View HOL analysis
  26. CVE-2026-11625High
    Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
    CVSS 7.5
    DAVIDO/Bytes::Random::Securegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-1869Medium
    User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass
    CVSS 6.5
    wpeverest/User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buildergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  28. CVE-2026-2053High
    Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
    CVSS 8.3
    WSO2/WSO2 API Managergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  29. CVE-2026-10835High
    SALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection
    CVSS 7.7
    Unknown/SALESmanago & Leadoogeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  30. CVE-2026-10823High
    YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure
    CVSS 7.5
    Unknown/YMC Filtergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  31. CVE-2025-10268Medium
    Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversal
    CVSS 5.3
    Unknown/Printcart Web to Print Product Designer for WooCommercegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  32. CVE-2026-13226Medium
    Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  33. CVE-2026-48618Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    nodejs/nodegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 10, 2026View HOL analysis
  34. CVE-2026-48933High
    CISA ADP Vulnrichment
    CVSS 7.5
    nodejs/nodegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 10, 2026View HOL analysis
  35. CVE-2026-50740Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Revive/Adservergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026View HOL analysis
  36. CVE-2026-13322Low
    Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service
    CVSS 3.8
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  37. CVE-2026-30040Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-30041High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  39. CVE-2026-36478High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-36907Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  41. CVE-2026-36908Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-38571Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-38639High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2026-38641High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-39031Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2026-13083Medium
    Pen-drive: pen-drive: stored xss via unescaped cluster data in html report
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026View HOL analysis
  47. CVE-2026-13318Medium
    Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  48. CVE-2026-13218Medium
    Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  49. CVE-2026-12993Medium
    Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  50. CVE-2026-43920Medium
    FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution
    CVSS 6.9
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
Page 139 of 344
Previous137138139140141Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,601

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 6,901–6,950 of 17,172 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12411High
    Broken Access Control in Canonical LXD DevLXD API
    CVSS 8.4
    Canonical/lxdgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  2. CVE-2026-45195High
    GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  3. CVE-2026-21734High
    GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
    CVSS 7.7
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  4. CVE-2026-24547Medium
    WordPress SiteGround Email Marketing plugin <= 1.7.5 - Broken Access Control vulnerability
    CVSS 5.3
    SiteGround/SiteGround Email Marketinggeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  5. CVE-2025-68075Medium
    WordPress BNE Testimonials plugin <= 2.0.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Kerry/BNE Testimonialsgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2025-68074Medium
    WordPress Image Carousel plugin <= 1.0.0.41 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    GhozyLab/Image Carouselgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  7. CVE-2025-68064High
    WordPress Goya Core plugin < 1.0.9.4 - Local File Inclusion vulnerability
    CVSS 7.5
    Everthemess/Goya Coregeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  8. CVE-2025-68063High
    WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hockey theme <= 4.4.3 - Local File Inclusion vulnerability
    CVSS 7.5
    StylemixThemes/Splash - Sport Club WordPress Theme for Basketball, Football, Hockeygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  9. CVE-2025-68052High
    WordPress Eagle Booking plugin <= 1.3.4.3 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 8.8
    Eagle-Themes/Eagle Bookinggeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  10. CVE-2025-66123Medium
    WordPress BookPro plugin <= 1.1.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 5.3
    About Envato/BookProgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  11. CVE-2025-64637Medium
    WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability
    CVSS 5.3
    Opal_WP/Auros Coregeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  12. CVE-2025-64636Medium
    WordPress Donation Thermometer plugin <= 2.2.7 - Broken Access Control vulnerability
    CVSS 5.3
    rhewlif/Donation Thermometergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  13. CVE-2025-63079Medium
    WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Control vulnerability
    CVSS 4.3
    bdthemes/Live Copy Paste for Elementorgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  14. CVE-2025-63078Medium
    WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Control vulnerability
    CVSS 4.3
    jetmonsters/Restaurant Menu by MotoPressgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  15. CVE-2025-63041Medium
    WordPress Forget About Shortcode Buttons plugin <= 2.1.3 - Broken Access Control vulnerability
    CVSS 5.4
    Code Amp/Forget About Shortcode Buttonsgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  16. CVE-2026-45257High
    Arbitrary file overwrite via the KTLS receive path
    CVSS 7.8
    FreeBSD/FreeBSDgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  17. CVE-2026-4339Medium
    SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server
    CVSS 6.5
    Mattermost/Mattermostgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  18. CVE-2026-45256Medium
    Missing permission check in thr_kill2(2)
    CVSS 5.5
    FreeBSD/FreeBSDgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  19. CVE-2026-3472Low
    Markdown image rendering bypass in AI bot tool result posts in Mattermost
    CVSS 3.5
    Mattermost/Mattermostgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  20. CVE-2026-13426Medium
    Client4 fails to validate path parameters
    CVSS 5.4
    Mattermost/github.com/mattermost/mattermost/server/publicgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  21. CVE-2026-40711High
    CISA ADP Vulnrichment
    CVSS 8.0
    Dell/Container Storage Modulesgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  22. CVE-2025-64152Critical
    Apache IoTDB: Path Traversal Vulnerability
    CVSS 9.1
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  23. CVE-2025-55017Critical
    Apache IoTDB: Path Traversal Vulnerability
    CVSS 9.1
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  24. CVE-2025-7958High
    CISA ADP Vulnrichment
    CVSS 7.1
    Trellix/Trellix Network Security NX, EX, FX, AX, and CMSgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  25. CVE-2026-11702High
    Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes
    CVSS 7.5
    DAVIDO/Bytes::Random::Secure::Tinygeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026View HOL analysis
  26. CVE-2026-11625High
    Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
    CVSS 7.5
    DAVIDO/Bytes::Random::Securegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 1, 2026View HOL analysis
  27. CVE-2026-1869Medium
    User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass
    CVSS 6.5
    wpeverest/User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buildergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  28. CVE-2026-2053High
    Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
    CVSS 8.3
    WSO2/WSO2 API Managergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  29. CVE-2026-10835High
    SALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection
    CVSS 7.7
    Unknown/SALESmanago & Leadoogeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  30. CVE-2026-10823High
    YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure
    CVSS 7.5
    Unknown/YMC Filtergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  31. CVE-2025-10268Medium
    Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversal
    CVSS 5.3
    Unknown/Printcart Web to Print Product Designer for WooCommercegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  32. CVE-2026-13226Medium
    Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  33. CVE-2026-48618Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    nodejs/nodegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 10, 2026View HOL analysis
  34. CVE-2026-48933High
    CISA ADP Vulnrichment
    CVSS 7.5
    nodejs/nodegeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Aug 10, 2026View HOL analysis
  35. CVE-2026-50740Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Revive/Adservergeneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026View HOL analysis
  36. CVE-2026-13322Low
    Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service
    CVSS 3.8
    Affected software not mappedEcosystem not listed
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  37. CVE-2026-30040Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-30041High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
  39. CVE-2026-36478High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jul 5, 2026View HOL analysis
  40. CVE-2026-36907Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  41. CVE-2026-36908Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-38571Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  43. CVE-2026-38639High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  44. CVE-2026-38641High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  45. CVE-2026-39031Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJun 26, 2026First seen at HOL Jun 26, 2026Updated Jun 29, 2026View HOL analysis
  46. CVE-2026-13083Medium
    Pen-drive: pen-drive: stored xss via unescaped cluster data in html report
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 8, 2026View HOL analysis
  47. CVE-2026-13318Medium
    Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  48. CVE-2026-13218Medium
    Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher
    CVSS 4.2
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  49. CVE-2026-12993Medium
    Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jul 6, 2026View HOL analysis
  50. CVE-2026-43920Medium
    FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution
    CVSS 6.9
    FOSSBilling/FOSSBillinggeneric
    PublishedJun 25, 2026First seen at HOL Jun 26, 2026Updated Jun 26, 2026View HOL analysis
Page 139 of 344
Previous137138139140141Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard