1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:30 AM 17,239 active 1,443 known exploited

Catalog summary

17,239

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 9:30 AM 17,239 active 1,443 known exploited

Catalog summary

17,239

Active CVEs

8,700

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,551–7,600 of 17,239 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12814Medium
    Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
    CVSS 6.3
    Comfast/CF-WR631AX V3generic
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-12813Medium
    activepieces File URL file.ts handleUrlFile server-side request forgery
    CVSS 6.3
    n/a/activepiecesgeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-12812Low
    Radware Cyber Controller HTML Report Generation HTML injection
    CVSS 3.5
    Radware/Cyber Controllergeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  4. CVE-2026-12811Medium
    kortix-ai suna Auth Endpoint page.tsx router.push cross site scripting
    CVSS 4.3
    kortix-ai/sunageneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  5. CVE-2026-12810Medium
    Edimax BR-6478AC V2 POST Request mp command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  6. CVE-2026-12809Medium
    Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  7. CVE-2026-12808Medium
    Edimax BR-6478AC V2 POST Request stainfo command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  8. CVE-2026-12807Medium
    Edimax BR-6478AC V2 POST Request setWAN command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  9. CVE-2026-12806High
    Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow
    CVSS 8.8
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  10. CVE-2026-12805Medium
    OFFIS DCMTK ofxml.cc parseFile heap-based overflow
    CVSS 6.3
    OFFIS/DCMTKgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  11. CVE-2026-12804Medium
    lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect
    CVSS 4.3
    n/a/lemonldap-nggeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  12. CVE-2025-71378High
    picklescan - Remote Code Execution via Undetected cProfile.runctx in Pickle Files
    CVSS 8.1
    picklescan, picklescan/picklescangeneric · pypi
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  13. CVE-2025-71357High
    picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.ModifiedInterpreter.runcommand
    CVSS 8.1
    picklescan, picklescan/picklescangeneric · pypi
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  14. CVE-2025-71351High
    picklescan - Remote Code Execution via timeit.timeit() Detection Bypass
    CVSS 7.6
    picklescan/picklescangeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  15. CVE-2025-71348High
    picklescan - Arbitrary Code Execution via torch.utils._config_module.load_config Bypass
    CVSS 8.1
    picklescan, picklescan/picklescangeneric · pypi
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  16. CVE-2026-12799Medium
    BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
    CVSS 4.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  17. CVE-2026-12798Medium
    BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  18. CVE-2026-12797Medium
    BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  19. CVE-2026-12796Medium
    BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  20. CVE-2026-12795High
    BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
    CVSS 7.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  21. CVE-2026-12789Medium
    ILIAS Learning Management System Learning Progress Tracking class.ilTrQuery.php executeQueries sql injection
    CVSS 4.7
    ILIAS/Learning Management Systemgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-12788Medium
    zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
    CVSS 6.3
    zhilink 智互联(深圳)科技有限公司/ADP Application Developer Platform 应用开发者平台generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2026-12787Medium
    zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserialization
    CVSS 6.3
    zhilink 智互联(深圳)科技有限公司/ADP Application Developer Platform 应用开发者平台generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2026-12786High
    Ezbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
    CVSS 7.8
    Ezbsystems/UltraISO Premium Editiongeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-12784High
    IM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control
    CVSS 7.8
    IM-Magic/Partition Resizergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  26. CVE-2026-52911High
    ksmbd: scope conn->binding slowpath to bound sessions only
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-12782High
    EaseUS Partition Master Kernel Driver EUEDKEPM.sys access control
    CVSS 7.8
    EaseUS/Partition Mastergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  28. CVE-2026-12781High
    EaseUS Partition Master Kernel Driver epmntdrv.sys access control
    CVSS 7.8
    EaseUS/Partition Mastergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  29. CVE-2026-12780High
    AOMEI Backupper Kernel Driver amwrtdrv.sys access control
    CVSS 7.8
    AOMEI/Backuppergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  30. CVE-2026-12779High
    AOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control
    CVSS 7.8
    AOMEI/Dynamic Disk Managergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  31. CVE-2026-12778High
    AOMEI Partition Assistant Kernel Driver ampa10.sys access control
    CVSS 7.8
    AOMEI/Partition Assistantgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2026-12776Medium
    Montodel House-Rental-Management index.php houses sql injection
    CVSS 6.3
    Montodel/House-Rental-Managementgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  33. CVE-2026-12775High
    Montodel House-Rental-Management login.php sql injection
    CVSS 7.3
    Montodel/House-Rental-Managementgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  34. CVE-2026-12774Medium
    BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  35. CVE-2026-12773High
    BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
    CVSS 7.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-12772Medium
    BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  37. CVE-2026-12771Medium
    BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
    CVSS 5.0
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  38. CVE-2026-12770Medium
    BerriAI litellm Admin Key key_management_endpoints.py improper authorization
    CVSS 5.4
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  39. CVE-2026-56346Medium
    AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint
    CVSS 6.5
    AVideo/AVideogeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 8, 2026View HOL analysis
  40. CVE-2025-71379Medium
    vllm - Regular Expression Denial of Service in Multiple Components
    CVSS 4.3
    vllm, vllm/vllmgeneric · pypi
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2025-71331Medium
    Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
    CVSS 6.1
    Flowise/Flowisegeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  42. CVE-2024-58351Critical
    Flowise - Remote Code Execution via overrideConfig Parameter
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  43. CVE-2022-50972Critical
    WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
    CVSS 9.8
    WooCommerce/WooCommercegeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2020-37255High
    WordPress Time Capsule Plugin 1.21.16 Authentication Bypass
    CVSS 7.5
    Wptimecapsule/Time Capsule Plugingeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2019-25763Critical
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
    CVSS 9.8
    Ultimatebeaver/Ultimate Addons for Beaver Buildergeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-12673Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    liquidfiles/liquidfilesgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  47. CVE-2026-48939Critical
    Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
    CVSS 10.0 Known exploited
    icagenda.com/iCagenda extension for Joomlageneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-12119Medium
    Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
    CVSS 6.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  49. CVE-2026-11911High
    Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  50. CVE-2026-11912High
    Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
Page 152 of 345
Previous150151152153154Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,700

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,551–7,600 of 17,239 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12814Medium
    Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
    CVSS 6.3
    Comfast/CF-WR631AX V3generic
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-12813Medium
    activepieces File URL file.ts handleUrlFile server-side request forgery
    CVSS 6.3
    n/a/activepiecesgeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-12812Low
    Radware Cyber Controller HTML Report Generation HTML injection
    CVSS 3.5
    Radware/Cyber Controllergeneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  4. CVE-2026-12811Medium
    kortix-ai suna Auth Endpoint page.tsx router.push cross site scripting
    CVSS 4.3
    kortix-ai/sunageneric
    PublishedJun 21, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  5. CVE-2026-12810Medium
    Edimax BR-6478AC V2 POST Request mp command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  6. CVE-2026-12809Medium
    Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  7. CVE-2026-12808Medium
    Edimax BR-6478AC V2 POST Request stainfo command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  8. CVE-2026-12807Medium
    Edimax BR-6478AC V2 POST Request setWAN command injection
    CVSS 6.3
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  9. CVE-2026-12806High
    Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow
    CVSS 8.8
    Edimax/BR-6478AC V2generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  10. CVE-2026-12805Medium
    OFFIS DCMTK ofxml.cc parseFile heap-based overflow
    CVSS 6.3
    OFFIS/DCMTKgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  11. CVE-2026-12804Medium
    lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect
    CVSS 4.3
    n/a/lemonldap-nggeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  12. CVE-2025-71378High
    picklescan - Remote Code Execution via Undetected cProfile.runctx in Pickle Files
    CVSS 8.1
    picklescan, picklescan/picklescangeneric · pypi
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  13. CVE-2025-71357High
    picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.ModifiedInterpreter.runcommand
    CVSS 8.1
    picklescan, picklescan/picklescangeneric · pypi
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  14. CVE-2025-71351High
    picklescan - Remote Code Execution via timeit.timeit() Detection Bypass
    CVSS 7.6
    picklescan/picklescangeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  15. CVE-2025-71348High
    picklescan - Arbitrary Code Execution via torch.utils._config_module.load_config Bypass
    CVSS 8.1
    picklescan, picklescan/picklescangeneric · pypi
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 27, 2026 Fix availableView HOL analysis
  16. CVE-2026-12799Medium
    BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
    CVSS 4.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  17. CVE-2026-12798Medium
    BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  18. CVE-2026-12797Medium
    BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  19. CVE-2026-12796Medium
    BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  20. CVE-2026-12795High
    BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
    CVSS 7.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  21. CVE-2026-12789Medium
    ILIAS Learning Management System Learning Progress Tracking class.ilTrQuery.php executeQueries sql injection
    CVSS 4.7
    ILIAS/Learning Management Systemgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-12788Medium
    zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
    CVSS 6.3
    zhilink 智互联(深圳)科技有限公司/ADP Application Developer Platform 应用开发者平台generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2026-12787Medium
    zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserialization
    CVSS 6.3
    zhilink 智互联(深圳)科技有限公司/ADP Application Developer Platform 应用开发者平台generic
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2026-12786High
    Ezbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
    CVSS 7.8
    Ezbsystems/UltraISO Premium Editiongeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-12784High
    IM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control
    CVSS 7.8
    IM-Magic/Partition Resizergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  26. CVE-2026-52911High
    ksmbd: scope conn->binding slowpath to bound sessions only
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-12782High
    EaseUS Partition Master Kernel Driver EUEDKEPM.sys access control
    CVSS 7.8
    EaseUS/Partition Mastergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  28. CVE-2026-12781High
    EaseUS Partition Master Kernel Driver epmntdrv.sys access control
    CVSS 7.8
    EaseUS/Partition Mastergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  29. CVE-2026-12780High
    AOMEI Backupper Kernel Driver amwrtdrv.sys access control
    CVSS 7.8
    AOMEI/Backuppergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  30. CVE-2026-12779High
    AOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control
    CVSS 7.8
    AOMEI/Dynamic Disk Managergeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  31. CVE-2026-12778High
    AOMEI Partition Assistant Kernel Driver ampa10.sys access control
    CVSS 7.8
    AOMEI/Partition Assistantgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2026-12776Medium
    Montodel House-Rental-Management index.php houses sql injection
    CVSS 6.3
    Montodel/House-Rental-Managementgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 22, 2026View HOL analysis
  33. CVE-2026-12775High
    Montodel House-Rental-Management login.php sql injection
    CVSS 7.3
    Montodel/House-Rental-Managementgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 23, 2026View HOL analysis
  34. CVE-2026-12774Medium
    BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  35. CVE-2026-12773High
    BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
    CVSS 7.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-12772Medium
    BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration
    CVSS 6.3
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  37. CVE-2026-12771Medium
    BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
    CVSS 5.0
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  38. CVE-2026-12770Medium
    BerriAI litellm Admin Key key_management_endpoints.py improper authorization
    CVSS 5.4
    BerriAI/litellmgeneric
    PublishedJun 21, 2026First seen at HOL Jun 21, 2026Updated Jun 24, 2026View HOL analysis
  39. CVE-2026-56346Medium
    AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint
    CVSS 6.5
    AVideo/AVideogeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 8, 2026View HOL analysis
  40. CVE-2025-71379Medium
    vllm - Regular Expression Denial of Service in Multiple Components
    CVSS 4.3
    vllm, vllm/vllmgeneric · pypi
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2025-71331Medium
    Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
    CVSS 6.1
    Flowise/Flowisegeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 23, 2026 Fix availableView HOL analysis
  42. CVE-2024-58351Critical
    Flowise - Remote Code Execution via overrideConfig Parameter
    CVSS 9.8
    Flowise/Flowisegeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  43. CVE-2022-50972Critical
    WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
    CVSS 9.8
    WooCommerce/WooCommercegeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2020-37255High
    WordPress Time Capsule Plugin 1.21.16 Authentication Bypass
    CVSS 7.5
    Wptimecapsule/Time Capsule Plugingeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2019-25763Critical
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
    CVSS 9.8
    Ultimatebeaver/Ultimate Addons for Beaver Buildergeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-12673Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    liquidfiles/liquidfilesgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  47. CVE-2026-48939Critical
    Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
    CVSS 10.0 Known exploited
    icagenda.com/iCagenda extension for Joomlageneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-12119Medium
    Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
    CVSS 6.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  49. CVE-2026-11911High
    Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  50. CVE-2026-11912High
    Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
Page 152 of 345
Previous150151152153154Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard