1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 11:10 AM 17,243 active 1,443 known exploited

Catalog summary

17,243

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 11, 2026, 11:10 AM 17,243 active 1,443 known exploited

Catalog summary

17,243

Active CVEs

8,703

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,701–7,750 of 17,243 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-47339High
    Apache APISIX: authz-casdoor incorrect session sharing
    CVSS 8.1
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  2. CVE-2026-44046Medium
    Apache APISIX: wolf-rbac plugin Identity Spoofing
    CVSS 5.8
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  3. CVE-2026-39999Critical
    Apache APISIX: JWT Algorithm Confusion allows authentication bypass
    CVSS 9.1
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  4. CVE-2026-48137Critical
    Untrusted pointer dereference in NI grpc-device sideband streaming API
    CVSS 9.1
    NI/InstrumentStudio, NI/grpc-devicegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 25, 2026View HOL analysis
  5. CVE-2026-39998High
    Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
    CVSS 8.8
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  6. CVE-2026-4026High
    FlexNet Manager Suite Privilege Escalation Vulnerability
    CVSS 8.7
    Flexera/FlexNet Manager Suitegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  7. CVE-2026-12706Medium
    Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  8. CVE-2026-41156High
    GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference
    CVSS 7.7
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  9. CVE-2026-34192High
    GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries
    CVSS 7.7
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  10. CVE-2026-11576High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse ThreadX - NetX Duogeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jul 2, 2026View HOL analysis
  11. CVE-2026-46461High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/Server Hardware Managergeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  12. CVE-2026-3640Medium
    STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint
    CVSS 5.3
    strablengineering/STRABL – A checkout solutiongeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  13. CVE-2026-54414Critical
    FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover
    CVSS 9.8
    error311/FileRisegeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  14. CVE-2025-7737High
    DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform
    CVSS 8.6
    Hitachi/Hitachi Virtual Storage Platform E390, E590, E790, E390H, E590H, E790H, Hitachi/Hitachi Virtual Storage Platform E990, E1090, E1090H +4generic
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  15. CVE-2026-12430Medium
    Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter
    CVSS 4.4
    creativethemeshq/Blocksy Companiongeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  16. CVE-2026-10034Medium
    WP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters)
    CVSS 5.3
    legalweb/WP DSGVO Tools (GDPR)generic
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2026-11989Medium
    Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
    CVSS 6.5
    bitpressadmin/Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automationgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  18. CVE-2026-4328Medium
    Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter
    CVSS 6.4
    addonspress/Advanced Importgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  19. CVE-2026-12157Medium
    BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute
    CVSS 6.4
    wpdevteam/BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbotgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  20. CVE-2026-1856Medium
    Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label
    CVSS 6.4
    creavi/Creavi Appointment Booking Calendargeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  21. CVE-2026-10779Medium
    Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters)
    CVSS 4.3
    techlabpro1/Classified Listing – AI-Powered Classified ads & Business Directorygeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  22. CVE-2026-11775Medium
    User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery
    CVSS 4.3
    adamsilverstein/User Admin Simplifiergeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2025-62821Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 30, 2026View HOL analysis
  24. CVE-2026-40624Critical
    AVer PTC cameras Files or Directories Accessible to External Parties
    CVSS 9.8
    AVer/PTC115, AVer/PTC115+ +2generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-12049Medium
    pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter
    CVSS 4.3
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  26. CVE-2026-12048Critical
    pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
    CVSS 9.3
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  27. CVE-2026-12047Low
    pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text
    CVSS 3.5
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  28. CVE-2026-12046Critical
    pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  29. CVE-2026-12045Critical
    pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  30. CVE-2026-12050Medium
    pgAdmin 4: SQL injection in named restore point endpoint
    CVSS 4.3
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  31. CVE-2026-12044High
    pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
    CVSS 8.8
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  32. CVE-2026-22674Medium
    Hashgraph Guardian Stored XSS via branding companyName field
    CVSS 4.8
    hashgraph/guardiangeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026View HOL analysis
  33. CVE-2026-46699High
    conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repository
    CVSS 7.6
    conda-forge/conda-smithygeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  34. CVE-2026-45696High
    OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)
    CVSS 8.3
    AcademySoftwareFoundation/openexrgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-44663Medium
    OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow
    CVSS 6.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  36. CVE-2025-15661Medium
    libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
    CVSS 6.5
    libssh2/libssh2generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026View HOL analysis
  37. CVE-2026-43994High
    Coturn: Stack buffer overflow in decode_oauth_token_gcm()
    CVSS 8.1
    coturn/coturngeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-25865High
    Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
    CVSS 7.8
    Yandex/Punto Switchergeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  39. CVE-2026-43915Medium
    Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username
    CVSS 5.4
    coturn/coturngeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  40. CVE-2026-47846Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Bitnami/bitnami/cassandrageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  41. CVE-2026-47847Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Bitnami/bitnami/mariadb-galera, Bitnami/bitnami/mariadb-galera Helm chartgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  42. CVE-2026-12390High
    Access of resource using incompatible type ('type confusion') in AzeoTech DAQFactory
    CVSS 8.4
    AzeoTech/DAQFactorygeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-47833Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Cloud Foundry Foundation/bpm-releasegeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  44. CVE-2026-11982Medium
    Stored XSS via missing XSS safety check in Admin2 Pages API partial validation
    CVSS 5.1
    Grav/grav-plugin-apigeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2025-32436High
    AutoGPT has a DoS vulnerability in AddAudioToVideoBlock
    CVSS 7.1
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  46. CVE-2026-11791Medium
    389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  47. CVE-2026-12527Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Shenzhen Liandian Communication Technology LTD/V380 IP Camera / AppFHE1_V1.0.6.0generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  48. CVE-2026-12539Medium
    Docker Sandboxes ICMP egress restriction bypass after daemon restart
    CVSS 5.7
    Docker/Docker Sandboxesgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  49. CVE-2026-12039Medium
    Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
    CVSS 5.7
    Docker/Docker Sandboxesgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  50. CVE-2026-42488High
    x86: mismatched mapcache metadata
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
Page 155 of 345
Previous153154155156157Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,703

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 7,701–7,750 of 17,243 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-47339High
    Apache APISIX: authz-casdoor incorrect session sharing
    CVSS 8.1
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  2. CVE-2026-44046Medium
    Apache APISIX: wolf-rbac plugin Identity Spoofing
    CVSS 5.8
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  3. CVE-2026-39999Critical
    Apache APISIX: JWT Algorithm Confusion allows authentication bypass
    CVSS 9.1
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  4. CVE-2026-48137Critical
    Untrusted pointer dereference in NI grpc-device sideband streaming API
    CVSS 9.1
    NI/InstrumentStudio, NI/grpc-devicegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 25, 2026View HOL analysis
  5. CVE-2026-39998High
    Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
    CVSS 8.8
    Apache Software Foundation/Apache APISIXgeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 23, 2026View HOL analysis
  6. CVE-2026-4026High
    FlexNet Manager Suite Privilege Escalation Vulnerability
    CVSS 8.7
    Flexera/FlexNet Manager Suitegeneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  7. CVE-2026-12706Medium
    Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 22, 2026View HOL analysis
  8. CVE-2026-41156High
    GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference
    CVSS 7.7
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  9. CVE-2026-34192High
    GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries
    CVSS 7.7
    Imagination Technologies/Graphics DDKgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  10. CVE-2026-11576High
    CISA ADP Vulnrichment
    CVSS 7.5
    Eclipse Foundation/Eclipse ThreadX - NetX Duogeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jul 2, 2026View HOL analysis
  11. CVE-2026-46461High
    CISA ADP Vulnrichment
    CVSS 7.8
    Dell/Server Hardware Managergeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026 Fix availableView HOL analysis
  12. CVE-2026-3640Medium
    STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint
    CVSS 5.3
    strablengineering/STRABL – A checkout solutiongeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  13. CVE-2026-54414Critical
    FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover
    CVSS 9.8
    error311/FileRisegeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Aug 10, 2026View HOL analysis
  14. CVE-2025-7737High
    DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform
    CVSS 8.6
    Hitachi/Hitachi Virtual Storage Platform E390, E590, E790, E390H, E590H, E790H, Hitachi/Hitachi Virtual Storage Platform E990, E1090, E1090H +4generic
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  15. CVE-2026-12430Medium
    Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter
    CVSS 4.4
    creativethemeshq/Blocksy Companiongeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  16. CVE-2026-10034Medium
    WP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters)
    CVSS 5.3
    legalweb/WP DSGVO Tools (GDPR)generic
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  17. CVE-2026-11989Medium
    Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
    CVSS 6.5
    bitpressadmin/Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automationgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  18. CVE-2026-4328Medium
    Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter
    CVSS 6.4
    addonspress/Advanced Importgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  19. CVE-2026-12157Medium
    BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute
    CVSS 6.4
    wpdevteam/BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbotgeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  20. CVE-2026-1856Medium
    Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label
    CVSS 6.4
    creavi/Creavi Appointment Booking Calendargeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  21. CVE-2026-10779Medium
    Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters)
    CVSS 4.3
    techlabpro1/Classified Listing – AI-Powered Classified ads & Business Directorygeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  22. CVE-2026-11775Medium
    User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery
    CVSS 4.3
    adamsilverstein/User Admin Simplifiergeneric
    PublishedJun 19, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  23. CVE-2025-62821Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJun 19, 2026First seen at HOL Jun 19, 2026Updated Jun 30, 2026View HOL analysis
  24. CVE-2026-40624Critical
    AVer PTC cameras Files or Directories Accessible to External Parties
    CVSS 9.8
    AVer/PTC115, AVer/PTC115+ +2generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  25. CVE-2026-12049Medium
    pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter
    CVSS 4.3
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  26. CVE-2026-12048Critical
    pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
    CVSS 9.3
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  27. CVE-2026-12047Low
    pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text
    CVSS 3.5
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  28. CVE-2026-12046Critical
    pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  29. CVE-2026-12045Critical
    pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  30. CVE-2026-12050Medium
    pgAdmin 4: SQL injection in named restore point endpoint
    CVSS 4.3
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 29, 2026 Fix availableView HOL analysis
  31. CVE-2026-12044High
    pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
    CVSS 8.8
    pgadmin.org/pgAdmin 4generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 1, 2026 Fix availableView HOL analysis
  32. CVE-2026-22674Medium
    Hashgraph Guardian Stored XSS via branding companyName field
    CVSS 4.8
    hashgraph/guardiangeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026View HOL analysis
  33. CVE-2026-46699High
    conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repository
    CVSS 7.6
    conda-forge/conda-smithygeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  34. CVE-2026-45696High
    OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)
    CVSS 8.3
    AcademySoftwareFoundation/openexrgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-44663Medium
    OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow
    CVSS 6.1
    AcademySoftwareFoundation/openexrgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  36. CVE-2025-15661Medium
    libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
    CVSS 6.5
    libssh2/libssh2generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 14, 2026View HOL analysis
  37. CVE-2026-43994High
    Coturn: Stack buffer overflow in decode_oauth_token_gcm()
    CVSS 8.1
    coturn/coturngeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  38. CVE-2026-25865High
    Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
    CVSS 7.8
    Yandex/Punto Switchergeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 23, 2026View HOL analysis
  39. CVE-2026-43915Medium
    Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username
    CVSS 5.4
    coturn/coturngeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 26, 2026View HOL analysis
  40. CVE-2026-47846Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Bitnami/bitnami/cassandrageneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  41. CVE-2026-47847Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Bitnami/bitnami/mariadb-galera, Bitnami/bitnami/mariadb-galera Helm chartgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  42. CVE-2026-12390High
    Access of resource using incompatible type ('type confusion') in AzeoTech DAQFactory
    CVSS 8.4
    AzeoTech/DAQFactorygeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-47833Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Cloud Foundry Foundation/bpm-releasegeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026 Fix availableView HOL analysis
  44. CVE-2026-11982Medium
    Stored XSS via missing XSS safety check in Admin2 Pages API partial validation
    CVSS 5.1
    Grav/grav-plugin-apigeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  45. CVE-2025-32436High
    AutoGPT has a DoS vulnerability in AddAudioToVideoBlock
    CVSS 7.1
    Significant-Gravitas/AutoGPTgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  46. CVE-2026-11791Medium
    389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
    CVSS 5.0
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026View HOL analysis
  47. CVE-2026-12527Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    Shenzhen Liandian Communication Technology LTD/V380 IP Camera / AppFHE1_V1.0.6.0generic
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
  48. CVE-2026-12539Medium
    Docker Sandboxes ICMP egress restriction bypass after daemon restart
    CVSS 5.7
    Docker/Docker Sandboxesgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  49. CVE-2026-12039Medium
    Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
    CVSS 5.7
    Docker/Docker Sandboxesgeneric
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 30, 2026 Fix availableView HOL analysis
  50. CVE-2026-42488High
    x86: mismatched mapcache metadata
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedJun 18, 2026First seen at HOL Jun 22, 2026Updated Jun 22, 2026View HOL analysis
Page 155 of 345
Previous153154155156157Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard