1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 2:05 PM 16,242 active 1,443 known exploited

Catalog summary

16,242

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 2:05 PM 16,242 active 1,443 known exploited

Catalog summary

16,242

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 651–700 of 16,242 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64593Unknown severity
    btrfs: do not trim a device which is not writeable
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  2. CVE-2026-64592Unknown severity
    riscv: mm: Unconditionally sfence.vma for spurious fault
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  3. CVE-2026-64591Unknown severity
    iommu/vt-d: Avoid WARNING in sva unbind path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  4. CVE-2026-64590Unknown severity
    dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-64589Unknown severity
    i2c: core: fix NULL-deref on adapter registration failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  6. CVE-2026-64588Unknown severity
    fuse-uring: fix data races on ring->ready
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  7. CVE-2026-64587Unknown severity
    net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  8. CVE-2026-64586Unknown severity
    wifi: brcmfmac: drain bus_reset work on device removal
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  9. CVE-2026-64585Unknown severity
    can: esd_usb: kill anchored URBs before freeing netdevs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  10. CVE-2026-64584Unknown severity
    usb: gadget: f_midi: cancel pending IN work before freeing the midi object
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  11. CVE-2026-64583Unknown severity
    usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-19010High
    TinyAGI Message API Endpoint index.ts processMessage authorization
    CVSS 7.3
    n/a/TinyAGIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-18649High
    Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-19009High
    TinyAGI Message API Endpoint response.ts collectFiles file inclusion
    CVSS 7.3
    n/a/TinyAGIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-19008Medium
    mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
    CVSS 6.3
    mf-yang/openclaw-cngeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-19007Medium
    mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
    CVSS 6.3
    mf-yang/openclaw-cngeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-14204Medium
    Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF
    CVSS 6.5
    Unknown/Google Authenticatorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  18. CVE-2026-13703Medium
    SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure
    CVSS 5.4
    Unknown/SEO Redirection Plugingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-13154High
    Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
    CVSS 7.5
    Unknown/Gutenberg Essential Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-13153High
    Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint
    CVSS 7.5
    Unknown/Gutenberg Essential Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-12713Critical
    WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number
    CVSS 9.1
    Unknown/WPCargo Track & Tracegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  22. CVE-2025-15678Medium
    Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload
    CVSS 6.1
    Unknown/Nexter Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-16537Medium
    Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
    CVSS 5.4
    Unknown/Slick Slidergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-18395Medium
    Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
    CVSS 5.4
    Unknown/Child Pages Cardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  25. CVE-2026-16065Medium
    Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
    CVSS 6.5
    Unknown/Welcart e-Commercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-19006Medium
    mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
    CVSS 6.3
    mf-yang/openclaw-cngeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-14829High
    Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
    CVSS 8.2
    Unknown/Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumpsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-11588Medium
    EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation
    CVSS 6.1
    Unknown/EONSR AEO Agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-18050High
    Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads
    CVSS 7.5
    Unknown/Events Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-16954Medium
    AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens
    CVSS 6.5
    Unknown/AI Enginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2026-16734High
    Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation
    CVSS 7.5
    Unknown/Stripe Payment Forms by WP Full Paygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-16290Medium
    ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group
    CVSS 5.3
    Unknown/ProfileGridgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-16268High
    Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler
    CVSS 8.2
    Unknown/Newslettersgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-16054Critical
    Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle
    CVSS 9.1
    Unknown/Drag and Drop Multiple File Upload for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-14547Medium
    Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form
    CVSS 5.3
    Unknown/Estatik Real Estate Plugingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-14240Medium
    Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export
    CVSS 5.3
    Unknown/tourmastergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-14314Medium
    PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR
    CVSS 5.3
    Unknown/PeproDev WooCommerce Receipt Uploadergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-14313Medium
    PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering via IDOR
    CVSS 5.3
    Unknown/PeproDev WooCommerce Receipt Uploadergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-19005Medium
    nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges management
    CVSS 6.3
    nanocoai/NanoClawgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-18967Medium
    Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-18510High
    TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content
    CVSS 7.2
    cozmoslabs/TranslatePress – Translate Multilingual sites with AI Translationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-18400Medium
    Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting
    CVSS 6.4
    metaslider/Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slidergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-19000High
    JeecgBoot Anonymous Chat Attachment send server-side request forgery
    CVSS 7.3
    n/a/JeecgBootgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-18998Medium
    cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization
    CVSS 6.3
    cosmicstack-labs/mercury-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-18997Medium
    cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
    CVSS 6.3
    cosmicstack-labs/mercury-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-15459High
    WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint
    CVSS 8.1
    wpmudev/WPMU DEV Dashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-18996Medium
    cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment
    CVSS 6.3
    cosmicstack-labs/mercury-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-18995Medium
    netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure
    CVSS 4.3
    netease-youdao/LobsterAIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-18909Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    ELAN Microelectronics Corp./ELAN Smart-Padgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-18993Medium
    NousResearch hermes-agent Memory Toolset model_tools.py access control
    CVSS 6.3
    NousResearch/hermes-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 14 of 325
Previous1213141516Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 651–700 of 16,242 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64593Unknown severity
    btrfs: do not trim a device which is not writeable
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  2. CVE-2026-64592Unknown severity
    riscv: mm: Unconditionally sfence.vma for spurious fault
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  3. CVE-2026-64591Unknown severity
    iommu/vt-d: Avoid WARNING in sva unbind path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  4. CVE-2026-64590Unknown severity
    dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-64589Unknown severity
    i2c: core: fix NULL-deref on adapter registration failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  6. CVE-2026-64588Unknown severity
    fuse-uring: fix data races on ring->ready
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  7. CVE-2026-64587Unknown severity
    net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  8. CVE-2026-64586Unknown severity
    wifi: brcmfmac: drain bus_reset work on device removal
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  9. CVE-2026-64585Unknown severity
    can: esd_usb: kill anchored URBs before freeing netdevs
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  10. CVE-2026-64584Unknown severity
    usb: gadget: f_midi: cancel pending IN work before freeing the midi object
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  11. CVE-2026-64583Unknown severity
    usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-19010High
    TinyAGI Message API Endpoint index.ts processMessage authorization
    CVSS 7.3
    n/a/TinyAGIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-18649High
    Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-19009High
    TinyAGI Message API Endpoint response.ts collectFiles file inclusion
    CVSS 7.3
    n/a/TinyAGIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-19008Medium
    mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
    CVSS 6.3
    mf-yang/openclaw-cngeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-19007Medium
    mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
    CVSS 6.3
    mf-yang/openclaw-cngeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-14204Medium
    Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF
    CVSS 6.5
    Unknown/Google Authenticatorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  18. CVE-2026-13703Medium
    SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure
    CVSS 5.4
    Unknown/SEO Redirection Plugingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-13154High
    Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
    CVSS 7.5
    Unknown/Gutenberg Essential Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-13153High
    Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint
    CVSS 7.5
    Unknown/Gutenberg Essential Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-12713Critical
    WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number
    CVSS 9.1
    Unknown/WPCargo Track & Tracegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  22. CVE-2025-15678Medium
    Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload
    CVSS 6.1
    Unknown/Nexter Blocksgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-16537Medium
    Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
    CVSS 5.4
    Unknown/Slick Slidergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-18395Medium
    Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
    CVSS 5.4
    Unknown/Child Pages Cardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  25. CVE-2026-16065Medium
    Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
    CVSS 6.5
    Unknown/Welcart e-Commercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-19006Medium
    mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
    CVSS 6.3
    mf-yang/openclaw-cngeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-14829High
    Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
    CVSS 8.2
    Unknown/Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumpsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-11588Medium
    EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation
    CVSS 6.1
    Unknown/EONSR AEO Agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-18050High
    Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads
    CVSS 7.5
    Unknown/Events Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-16954Medium
    AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens
    CVSS 6.5
    Unknown/AI Enginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  31. CVE-2026-16734High
    Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation
    CVSS 7.5
    Unknown/Stripe Payment Forms by WP Full Paygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-16290Medium
    ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group
    CVSS 5.3
    Unknown/ProfileGridgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-16268High
    Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler
    CVSS 8.2
    Unknown/Newslettersgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-16054Critical
    Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle
    CVSS 9.1
    Unknown/Drag and Drop Multiple File Upload for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  35. CVE-2026-14547Medium
    Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form
    CVSS 5.3
    Unknown/Estatik Real Estate Plugingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-14240Medium
    Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export
    CVSS 5.3
    Unknown/tourmastergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-14314Medium
    PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR
    CVSS 5.3
    Unknown/PeproDev WooCommerce Receipt Uploadergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-14313Medium
    PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering via IDOR
    CVSS 5.3
    Unknown/PeproDev WooCommerce Receipt Uploadergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-19005Medium
    nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges management
    CVSS 6.3
    nanocoai/NanoClawgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-18967Medium
    Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow
    CVSS 6.4
    Affected software not mappedEcosystem not listed
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-18510High
    TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content
    CVSS 7.2
    cozmoslabs/TranslatePress – Translate Multilingual sites with AI Translationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-18400Medium
    Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting
    CVSS 6.4
    metaslider/Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slidergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-19000High
    JeecgBoot Anonymous Chat Attachment send server-side request forgery
    CVSS 7.3
    n/a/JeecgBootgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-18998Medium
    cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization
    CVSS 6.3
    cosmicstack-labs/mercury-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-18997Medium
    cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
    CVSS 6.3
    cosmicstack-labs/mercury-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-15459High
    WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint
    CVSS 8.1
    wpmudev/WPMU DEV Dashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-18996Medium
    cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment
    CVSS 6.3
    cosmicstack-labs/mercury-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-18995Medium
    netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure
    CVSS 4.3
    netease-youdao/LobsterAIgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-18909Medium
    CISA ADP Vulnrichment
    CVSS 4.7
    ELAN Microelectronics Corp./ELAN Smart-Padgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-18993Medium
    NousResearch hermes-agent Memory Toolset model_tools.py access control
    CVSS 6.3
    NousResearch/hermes-agentgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 14 of 325
Previous1213141516Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard