1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 10:20 AM 17,242 active 1,443 known exploited

Catalog summary

17,242

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 10:20 AM 17,242 active 1,443 known exploited

Catalog summary

17,242

Active CVEs

8,703

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,601–7,650 of 17,242 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12119Medium
    Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
    CVSS 6.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-11911High
    Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-11912High
    Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  4. CVE-2026-11551Critical
    Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
    CVSS 9.8
    wpmudev/Branda – White Label & Branding, Free Login Page Customizergeneric
    PublishedJun 19, 2026First seen at HOL Jun 20, 2026Updated Jun 23, 2026View HOL analysis
  5. CVE-2026-48129Medium
    Kestra task inputFiles accepts traversal filenames for worker file writes
    CVSS 6.5
    kestra-io/kestrageneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  6. CVE-2026-27878Medium
    Tempo TraceQL query with exemplar hint could result in unbounded memory usage
    CVSS 6.5
    Grafana/Enterprise Traces (GET), Grafana/Tempogeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  7. CVE-2026-12726Medium
    Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential
    CVSS 6.3
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  8. CVE-2026-12238Medium
    WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation
    CVSS 5.3
    wpgmaps/WP Go Maps – Google Map, OpenStreetMap, Leaflet Mapgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 24, 2026View HOL analysis
  9. CVE-2023-54357High
    Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
    CVSS 7.5
    Artio/Joomla! com_booking componentgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  10. CVE-2019-25762High
    Joomla! Component JoomProject 1.1.3.2 Information Disclosure
    CVSS 7.5
    Joomboost/JoomProjectgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  11. CVE-2019-25761High
    Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id
    CVSS 7.1
    Joomboost/JoomCRMgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  12. CVE-2019-25760Medium
    Joomla! Component Easy Shop 1.2.3 Local File Inclusion
    CVSS 6.2
    Joomtech/Easy Shopgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  13. CVE-2019-25759High
    Joomla! Component vBizz 1.0.7 SQL Injection
    CVSS 7.1
    Wdmtech/vBizzgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  14. CVE-2019-25758High
    Joomla! Component vBizz 1.0.7 Remote Code Execution
    CVSS 8.8
    Wdmtech/vBizzgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  15. CVE-2019-25757High
    Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter
    CVSS 7.1
    Wdmtech/vWishlistgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  16. CVE-2019-25756High
    Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard
    CVSS 8.2
    Wdmtech/vAccountgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2019-25755High
    Joomla vReview 1.9.11 SQL Injection via editReview
    CVSS 8.2
    Wdmtech/vReviewgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  18. CVE-2019-25754High
    Joomla vRestaurant 1.9.4 SQL Injection via menu-listing-layout
    CVSS 8.2
    Wdmtech/vRestaurantgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  19. CVE-2019-25753High
    Joomla! Component VMap 1.9.6 SQL Injection via loadmarker
    CVSS 8.2
    Wdmtech/VMapgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  20. CVE-2019-25752High
    Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection
    CVSS 8.2
    Cmsjunkie/J-BusinessDirectorygeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2019-25751High
    Joomla J-ClassifiedsManager 3.0.5 SQL Injection
    CVSS 8.2
    Cmsjunkie/ClassifiedsManagergeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2019-25750High
    Joomla J-MultipleHotelReservation 6.0.7 SQL Injection
    CVSS 8.2
    Cmsjunkie/MultipleHotelReservationgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2019-25749High
    Joomla J-CruisePortal 6.0.4 SQL Injection via cruises
    CVSS 7.1
    Cmsjunkie/J-CruisePortalgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2019-25748High
    Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels
    CVSS 8.2
    Cmsjunkie/JHotelReservationgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2017-20282High
    Joomla! Component jCart for OpenCart 2.0 SQL Injection
    CVSS 8.2
    Soft-Php/jCart for OpenCartgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  26. CVE-2017-20281High
    Joomla! Component Extra Search 2.2.8 SQL Injection
    CVSS 8.2
    Joomlaboat/Extra Searchgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  27. CVE-2017-20280High
    Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
    CVSS 8.2
    Myportfolio/Myportfoliogeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  28. CVE-2017-20279High
    Joomla Payage 2.05 SQL Injection via aid Parameter
    CVSS 8.2
    Extensions/Joomla Payagegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  29. CVE-2017-20278High
    Joomla JoomRecipe 1.0.3 SQL Injection via category parameter
    CVSS 8.2
    Joomboost/JoomRecipegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  30. CVE-2017-20277High
    Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
    CVSS 8.2
    Joomboost/Joomla JoomRecipegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  31. CVE-2017-20276High
    Joomla! Component SIMGenealogy 2.1.5 SQL Injection
    CVSS 8.2
    Simbunch/SIMGenealogygeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2017-20275High
    Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter
    CVSS 8.2
    Henryschorradt/Bridgegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  33. CVE-2017-20274High
    Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
    CVSS 8.2
    King-products/LMS King Professionalgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  34. CVE-2026-56211High
    Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  35. CVE-2026-56210High
    Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-56208High
    Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-56209Critical
    Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2017-20273High
    Joomla Event Registration Pro Calendar 4.1.3 SQL Injection
    CVSS 8.2
    Joomlashowroom/Event Registration Pro Calendargeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2017-20272High
    Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
    CVSS 8.2
    Faboba/Ultimate Property Listinggeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  40. CVE-2026-3195High
    Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-3196Medium
    Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  42. CVE-2017-20271High
    Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
    CVSS 8.2
    Nordmograph/StreetGuessr Gamegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  43. CVE-2017-20270High
    Joomla! Component Twitch Tv 1.1 SQL Injection
    CVSS 8.2
    Raindropsinfotech/Twitch Tvgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  44. CVE-2017-20269High
    Joomla! Component KissGallery 1.0.0 SQL Injection
    CVSS 8.2
    Terrywcarter/KissGallerygeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2017-20268High
    Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection
    CVSS 8.2
    Zcontent/Zap Calendar Litegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2017-20267High
    Joomla! Component Calendar Planner 1.0.1 SQL Injection
    CVSS 8.2
    Joomlathat/Calendar Plannergeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  47. CVE-2017-20266High
    Joomla SP Movie Database 1.3 SQL Injection via searchword
    CVSS 8.2
    Joomshaper/SP Movie Databasegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  48. CVE-2017-20265High
    Joomla! Component Flip Wall 8.0 SQL Injection
    CVSS 7.1
    Pulseextensions/Flip Wallgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  49. CVE-2026-12620Medium
    Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
    CVSS 6.5
    Microchip/GridTime 3000generic
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2017-20264High
    Joomla! Component Sponsor Wall 8.0 SQL Injection
    CVSS 7.1
    Pulseextensions/Sponsor Wallgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
Page 153 of 345
Previous151152153154155Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,703

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,601–7,650 of 17,242 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12119Medium
    Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
    CVSS 6.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  2. CVE-2026-11911High
    Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  3. CVE-2026-11912High
    Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
    CVSS 7.5
    eemitch/Simple File Listgeneric
    PublishedJun 20, 2026First seen at HOL Jun 20, 2026Updated Jun 22, 2026View HOL analysis
  4. CVE-2026-11551Critical
    Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
    CVSS 9.8
    wpmudev/Branda – White Label & Branding, Free Login Page Customizergeneric
    PublishedJun 19, 2026First seen at HOL Jun 20, 2026Updated Jun 23, 2026View HOL analysis
  5. CVE-2026-48129Medium
    Kestra task inputFiles accepts traversal filenames for worker file writes
    CVSS 6.5
    kestra-io/kestrageneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  6. CVE-2026-27878Medium
    Tempo TraceQL query with exemplar hint could result in unbounded memory usage
    CVSS 6.5
    Grafana/Enterprise Traces (GET), Grafana/Tempogeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 11, 2026 Fix availableView HOL analysis
  7. CVE-2026-12726Medium
    Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential
    CVSS 6.3
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  8. CVE-2026-12238Medium
    WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation
    CVSS 5.3
    wpgmaps/WP Go Maps – Google Map, OpenStreetMap, Leaflet Mapgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 24, 2026View HOL analysis
  9. CVE-2023-54357High
    Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
    CVSS 7.5
    Artio/Joomla! com_booking componentgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  10. CVE-2019-25762High
    Joomla! Component JoomProject 1.1.3.2 Information Disclosure
    CVSS 7.5
    Joomboost/JoomProjectgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  11. CVE-2019-25761High
    Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id
    CVSS 7.1
    Joomboost/JoomCRMgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  12. CVE-2019-25760Medium
    Joomla! Component Easy Shop 1.2.3 Local File Inclusion
    CVSS 6.2
    Joomtech/Easy Shopgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  13. CVE-2019-25759High
    Joomla! Component vBizz 1.0.7 SQL Injection
    CVSS 7.1
    Wdmtech/vBizzgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  14. CVE-2019-25758High
    Joomla! Component vBizz 1.0.7 Remote Code Execution
    CVSS 8.8
    Wdmtech/vBizzgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  15. CVE-2019-25757High
    Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter
    CVSS 7.1
    Wdmtech/vWishlistgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  16. CVE-2019-25756High
    Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard
    CVSS 8.2
    Wdmtech/vAccountgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2019-25755High
    Joomla vReview 1.9.11 SQL Injection via editReview
    CVSS 8.2
    Wdmtech/vReviewgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  18. CVE-2019-25754High
    Joomla vRestaurant 1.9.4 SQL Injection via menu-listing-layout
    CVSS 8.2
    Wdmtech/vRestaurantgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  19. CVE-2019-25753High
    Joomla! Component VMap 1.9.6 SQL Injection via loadmarker
    CVSS 8.2
    Wdmtech/VMapgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  20. CVE-2019-25752High
    Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection
    CVSS 8.2
    Cmsjunkie/J-BusinessDirectorygeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2019-25751High
    Joomla J-ClassifiedsManager 3.0.5 SQL Injection
    CVSS 8.2
    Cmsjunkie/ClassifiedsManagergeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2019-25750High
    Joomla J-MultipleHotelReservation 6.0.7 SQL Injection
    CVSS 8.2
    Cmsjunkie/MultipleHotelReservationgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2019-25749High
    Joomla J-CruisePortal 6.0.4 SQL Injection via cruises
    CVSS 7.1
    Cmsjunkie/J-CruisePortalgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  24. CVE-2019-25748High
    Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels
    CVSS 8.2
    Cmsjunkie/JHotelReservationgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2017-20282High
    Joomla! Component jCart for OpenCart 2.0 SQL Injection
    CVSS 8.2
    Soft-Php/jCart for OpenCartgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  26. CVE-2017-20281High
    Joomla! Component Extra Search 2.2.8 SQL Injection
    CVSS 8.2
    Joomlaboat/Extra Searchgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  27. CVE-2017-20280High
    Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
    CVSS 8.2
    Myportfolio/Myportfoliogeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  28. CVE-2017-20279High
    Joomla Payage 2.05 SQL Injection via aid Parameter
    CVSS 8.2
    Extensions/Joomla Payagegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  29. CVE-2017-20278High
    Joomla JoomRecipe 1.0.3 SQL Injection via category parameter
    CVSS 8.2
    Joomboost/JoomRecipegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  30. CVE-2017-20277High
    Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
    CVSS 8.2
    Joomboost/Joomla JoomRecipegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  31. CVE-2017-20276High
    Joomla! Component SIMGenealogy 2.1.5 SQL Injection
    CVSS 8.2
    Simbunch/SIMGenealogygeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  32. CVE-2017-20275High
    Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter
    CVSS 8.2
    Henryschorradt/Bridgegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  33. CVE-2017-20274High
    Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
    CVSS 8.2
    King-products/LMS King Professionalgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  34. CVE-2026-56211High
    Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  35. CVE-2026-56210High
    Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-56208High
    Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
    CVSS 8.6
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-56209Critical
    Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack
    CVSS 9.1
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2017-20273High
    Joomla Event Registration Pro Calendar 4.1.3 SQL Injection
    CVSS 8.2
    Joomlashowroom/Event Registration Pro Calendargeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2017-20272High
    Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
    CVSS 8.2
    Faboba/Ultimate Property Listinggeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  40. CVE-2026-3195High
    Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-3196Medium
    Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  42. CVE-2017-20271High
    Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
    CVSS 8.2
    Nordmograph/StreetGuessr Gamegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  43. CVE-2017-20270High
    Joomla! Component Twitch Tv 1.1 SQL Injection
    CVSS 8.2
    Raindropsinfotech/Twitch Tvgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  44. CVE-2017-20269High
    Joomla! Component KissGallery 1.0.0 SQL Injection
    CVSS 8.2
    Terrywcarter/KissGallerygeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2017-20268High
    Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection
    CVSS 8.2
    Zcontent/Zap Calendar Litegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2017-20267High
    Joomla! Component Calendar Planner 1.0.1 SQL Injection
    CVSS 8.2
    Joomlathat/Calendar Plannergeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  47. CVE-2017-20266High
    Joomla SP Movie Database 1.3 SQL Injection via searchword
    CVSS 8.2
    Joomshaper/SP Movie Databasegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  48. CVE-2017-20265High
    Joomla! Component Flip Wall 8.0 SQL Injection
    CVSS 7.1
    Pulseextensions/Flip Wallgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  49. CVE-2026-12620Medium
    Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
    CVSS 6.5
    Microchip/GridTime 3000generic
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2017-20264High
    Joomla! Component Sponsor Wall 8.0 SQL Injection
    CVSS 7.1
    Pulseextensions/Sponsor Wallgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
Page 153 of 345
Previous151152153154155Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard