1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 7:35 AM 17,214 active 1,443 known exploited

Catalog summary

17,214

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 7:35 AM 17,214 active 1,443 known exploited

Catalog summary

17,214

Active CVEs

8,692

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,301–7,350 of 17,214 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-54904High
    concurrent-ruby: `AtomicReference#update` livelocks when the stored value is `Float::NAN`
    CVSS 8.2
    concurrent-ruby, ruby-concurrency/concurrent-rubygeneric · rubygems
    PublishedJun 24, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-13164High
    Unauthenticated self-registration in MailerUp allows access to stored email data
    CVSS 8.8
    Mailerup/Mailerupgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  3. CVE-2026-12986High
    CISA ADP Vulnrichment
    CVSS 7.3
    Payara/Payara Servergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  4. CVE-2026-11877High
    Missing Authorization Vulnerability in OpenText Access Manager
    CVSS 7.5
    OpenText/Access Managergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-11878High
    Reflected Cross-Site Scripting vulnerability in OpenText Access Manager
    CVSS 8.2
    OpenText/Access Managergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-12537Critical
    Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows
    CVSS 10.0
    @google/gemini-cli, Google Cloud/Gemini CLI +2generic · github actions · npm
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-35025High
    ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
    CVSS 8.1
    ProFTPD Project/ProFTPDgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 14, 2026View HOL analysis
  8. CVE-2026-42450High
    OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser
    CVSS 8.4
    AcademySoftwareFoundation/OpenColorIOgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  9. CVE-2026-13163Medium
    Lack of input validation in Mailerup input parameter leads to Open Redirect
    CVSS 5.3
    Mailerup/Mailerupgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  10. CVE-2026-12242High
    AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute
    CVSS 8.8
    adegans/AdRotate Banner Managergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  11. CVE-2026-13140Low
    Stored Cross-Site Scripting in Canarytokens.org
    CVSS 1.1
    Thinkst Applied Research/Canarytokensgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  12. CVE-2026-13150Medium
    SSRF in Pentestify PDF generation endpoint via Host header
    CVSS 6.9
    Pentestify/Pentestifygeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  13. CVE-2026-11968Medium
    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGit
    CVSS 5.5
    TortoiseGit team/TortoiseGitgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  14. CVE-2026-52943High
    net: skbuff: fix missing zerocopy reference in pskb_carve helpers
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-10745High
    CISA ADP Vulnrichment
    CVSS 7.9
    upKeeper Solutions/upKeeper Instant Privilege Accessgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  16. CVE-2026-52942High
    netfilter: nf_log: validate MAC header was set before dumping it
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-52935High
    xfrm: espintcp: do not reuse an in-progress partial send
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-52934High
    batman-adv: tvlv: reject oversized TVLV packets
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-52933High
    io_uring/poll: fix signed comparison in io_poll_get_ownership()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-52932High
    xfrm: ipcomp: Free destination pages on acomp errors
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-52931Critical
    batman-adv: tp_meter: avoid use of uninit sender vars
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-52929High
    sctp: stream: fully roll back denied add-stream state
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-52927High
    netfilter: ebtables: fix OOB read in compat_mtw_from_user
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-52924Critical
    sctp: purge outqueue on stale COOKIE-ECHO handling
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-52923High
    ipc: limit next_id allocation to the valid ID range
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-52922High
    batman-adv: dat: handle forward allocation error
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-52920High
    netfilter: xt_policy: fix strict mode inbound policy matching
    CVSS 8.3
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-52919High
    batman-adv: fix tp_meter counter underflow during shutdown
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-52918High
    Bluetooth: serialize accept_q access
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-52917High
    sctp: diag: reject stale associations in dump_one path
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-52915High
    netfilter: ip6t_hbh: reject oversized option lists
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-52914Critical
    batman-adv: fix fragment reassembly length accounting
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-52912High
    netfilter: nf_queue: hold bridge skb->dev while queued
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-10753Low
    Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update
    CVSS 2.7
    Unknown/Site Kit by Googlegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  35. CVE-2026-10749High
    Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData
    CVSS 7.2
    Unknown/Post Duplicatorgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  36. CVE-2026-10735High
    ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
    CVSS 7.5
    Unknown/Product Slider for WooCommerce Pro, Unknown/Real Testimonials Pro +1generic
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  37. CVE-2026-10531Medium
    AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortcode Attribute
    CVSS 5.4
    Unknown/AI Share & Summarizegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  38. CVE-2026-13006High
    Incomplete protection against CVE-2025-11226
    CVSS 7.0
    QOS.CH Sarl/Logback-coregeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-11997Medium
    Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update
    CVSS 4.3
    seo_tools/Bulk SEO Imagegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  40. CVE-2026-12416Critical
    Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
    CVSS 9.8
    pravel/Invoice Generatorgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  41. CVE-2026-12417Critical
    SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover
    CVSS 9.8
    pravel/SignUp & SignIngeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-12095High
    Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url' Parameter
    CVSS 7.2
    bytuncay/Kargo Takipgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  43. CVE-2026-10552Medium
    Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter
    CVSS 4.3
    jotis/Blue Captchageneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  44. CVE-2026-4297High
    Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary Options Update to Privilege Escalation via 'nc.setOption' XML-RPC Method
    CVSS 8.8
    newscred/Welcome Software Publishinggeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  45. CVE-2026-12094Medium
    Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter
    CVSS 5.3
    iamranit/Advanced Contact Form 7 – Compact DBgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  46. CVE-2026-10092High
    Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments
    CVSS 7.2
    nicashmu/Cincopa video and media plug-ingeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  47. CVE-2026-11370Medium
    WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter
    CVSS 6.4
    joomunited/WP Meta SEOgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  48. CVE-2026-10091High
    Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    cgarvey/Email JavaScript Cloakgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  49. CVE-2026-12100High
    URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Parameter
    CVSS 7.2
    abhisheksaha11/URL Previewgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  50. CVE-2026-12851Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
Page 147 of 345
Previous145146147148149Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,692

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,301–7,350 of 17,214 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-54904High
    concurrent-ruby: `AtomicReference#update` livelocks when the stored value is `Float::NAN`
    CVSS 8.2
    concurrent-ruby, ruby-concurrency/concurrent-rubygeneric · rubygems
    PublishedJun 24, 2026First seen at HOL Jun 19, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-13164High
    Unauthenticated self-registration in MailerUp allows access to stored email data
    CVSS 8.8
    Mailerup/Mailerupgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  3. CVE-2026-12986High
    CISA ADP Vulnrichment
    CVSS 7.3
    Payara/Payara Servergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  4. CVE-2026-11877High
    Missing Authorization Vulnerability in OpenText Access Manager
    CVSS 7.5
    OpenText/Access Managergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  5. CVE-2026-11878High
    Reflected Cross-Site Scripting vulnerability in OpenText Access Manager
    CVSS 8.2
    OpenText/Access Managergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  6. CVE-2026-12537Critical
    Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows
    CVSS 10.0
    @google/gemini-cli, Google Cloud/Gemini CLI +2generic · github actions · npm
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-35025High
    ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
    CVSS 8.1
    ProFTPD Project/ProFTPDgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 14, 2026View HOL analysis
  8. CVE-2026-42450High
    OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser
    CVSS 8.4
    AcademySoftwareFoundation/OpenColorIOgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  9. CVE-2026-13163Medium
    Lack of input validation in Mailerup input parameter leads to Open Redirect
    CVSS 5.3
    Mailerup/Mailerupgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  10. CVE-2026-12242High
    AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute
    CVSS 8.8
    adegans/AdRotate Banner Managergeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  11. CVE-2026-13140Low
    Stored Cross-Site Scripting in Canarytokens.org
    CVSS 1.1
    Thinkst Applied Research/Canarytokensgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  12. CVE-2026-13150Medium
    SSRF in Pentestify PDF generation endpoint via Host header
    CVSS 6.9
    Pentestify/Pentestifygeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  13. CVE-2026-11968Medium
    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGit
    CVSS 5.5
    TortoiseGit team/TortoiseGitgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  14. CVE-2026-52943High
    net: skbuff: fix missing zerocopy reference in pskb_carve helpers
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-10745High
    CISA ADP Vulnrichment
    CVSS 7.9
    upKeeper Solutions/upKeeper Instant Privilege Accessgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  16. CVE-2026-52942High
    netfilter: nf_log: validate MAC header was set before dumping it
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-52935High
    xfrm: espintcp: do not reuse an in-progress partial send
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-52934High
    batman-adv: tvlv: reject oversized TVLV packets
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-52933High
    io_uring/poll: fix signed comparison in io_poll_get_ownership()
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-52932High
    xfrm: ipcomp: Free destination pages on acomp errors
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-52931Critical
    batman-adv: tp_meter: avoid use of uninit sender vars
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-52929High
    sctp: stream: fully roll back denied add-stream state
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-52927High
    netfilter: ebtables: fix OOB read in compat_mtw_from_user
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-52924Critical
    sctp: purge outqueue on stale COOKIE-ECHO handling
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-52923High
    ipc: limit next_id allocation to the valid ID range
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 10, 2026 Fix availableView HOL analysis
  26. CVE-2026-52922High
    batman-adv: dat: handle forward allocation error
    CVSS 7.5
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-52920High
    netfilter: xt_policy: fix strict mode inbound policy matching
    CVSS 8.3
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-52919High
    batman-adv: fix tp_meter counter underflow during shutdown
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-52918High
    Bluetooth: serialize accept_q access
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-52917High
    sctp: diag: reject stale associations in dump_one path
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-52915High
    netfilter: ip6t_hbh: reject oversized option lists
    CVSS 7.1
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-52914Critical
    batman-adv: fix fragment reassembly length accounting
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-52912High
    netfilter: nf_queue: hold bridge skb->dev while queued
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-10753Low
    Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update
    CVSS 2.7
    Unknown/Site Kit by Googlegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  35. CVE-2026-10749High
    Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData
    CVSS 7.2
    Unknown/Post Duplicatorgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  36. CVE-2026-10735High
    ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
    CVSS 7.5
    Unknown/Product Slider for WooCommerce Pro, Unknown/Real Testimonials Pro +1generic
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  37. CVE-2026-10531Medium
    AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortcode Attribute
    CVSS 5.4
    Unknown/AI Share & Summarizegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026 Fix availableView HOL analysis
  38. CVE-2026-13006High
    Incomplete protection against CVE-2025-11226
    CVSS 7.0
    QOS.CH Sarl/Logback-coregeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jul 1, 2026View HOL analysis
  39. CVE-2026-11997Medium
    Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update
    CVSS 4.3
    seo_tools/Bulk SEO Imagegeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  40. CVE-2026-12416Critical
    Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
    CVSS 9.8
    pravel/Invoice Generatorgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  41. CVE-2026-12417Critical
    SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover
    CVSS 9.8
    pravel/SignUp & SignIngeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  42. CVE-2026-12095High
    Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url' Parameter
    CVSS 7.2
    bytuncay/Kargo Takipgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  43. CVE-2026-10552Medium
    Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter
    CVSS 4.3
    jotis/Blue Captchageneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  44. CVE-2026-4297High
    Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary Options Update to Privilege Escalation via 'nc.setOption' XML-RPC Method
    CVSS 8.8
    newscred/Welcome Software Publishinggeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  45. CVE-2026-12094Medium
    Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter
    CVSS 5.3
    iamranit/Advanced Contact Form 7 – Compact DBgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  46. CVE-2026-10092High
    Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments
    CVSS 7.2
    nicashmu/Cincopa video and media plug-ingeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  47. CVE-2026-11370Medium
    WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter
    CVSS 6.4
    joomunited/WP Meta SEOgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 29, 2026View HOL analysis
  48. CVE-2026-10091High
    Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    cgarvey/Email JavaScript Cloakgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  49. CVE-2026-12100High
    URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Parameter
    CVSS 7.2
    abhisheksaha11/URL Previewgeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
  50. CVE-2026-12851Critical
    GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
    CVSS 9.1
    GeoVision Inc./GV-I/O Box 4Egeneric
    PublishedJun 24, 2026First seen at HOL Jun 24, 2026Updated Jun 25, 2026View HOL analysis
Page 147 of 345
Previous145146147148149Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard