HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Sep 30, 2026, 12:41 AM 41,396 active 1,505 known exploited

Catalog summary

41,396

Active CVEs

21,347

Critical + high

1,505

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 8,051–8,100 of 41,396 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-90535High
    Flowise before 3.1.4 Denial of Service via text-to-speech/abort
    CVSS 7.5
    FlowiseAI/Flowisegeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  2. CVE-2026-90534Medium
    Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method
    CVSS 6.5
    FlowiseAI/Flowisegeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  3. CVE-2026-90533Medium
    Flowise before 3.1.4 Broken Access Control via organizationuser
    CVSS 6.5
    FlowiseAI/Flowisegeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 15, 2026 Fix availableView HOL analysis
  4. CVE-2026-90474High
    MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass
    CVSS 7.6
    samanhappy/mcphubgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 24, 2026 Fix availableView HOL analysis
  5. CVE-2026-90473Medium
    msgpack-java through 0.9.12 Integer Overflow via MAP32
    CVSS 6.9
    msgpack/msgpack-javageneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 24, 2026View HOL analysis
  6. CVE-2026-90472Medium
    msgpack-java through 0.9.12 Stack Overflow via Nested Arrays
    CVSS 6.9
    msgpack/msgpack-javageneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 24, 2026View HOL analysis
  7. CVE-2026-89172Medium
    Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithms
    CVSS 5.6
    Microchip/AN1044, Microchip/AN953 +1generic
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 16, 2026View HOL analysis
  8. CVE-2026-11355Medium
    DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions
    CVSS 5.3
    designthemes/DT LMS – elearning, WordPress LMS Plugingeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  9. CVE-2026-77161Medium
    Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Authenticated (Subscriber+) SQL Injection via Parameter Name
    CVSS 6.5
    egoi/Smart Marketing SMS and Newsletters Formsgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  10. CVE-2026-78175High
    Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution
    CVSS 8.8
    themeum/Tutor LMS – eLearning and online course solutiongeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 15, 2026View HOL analysis
  11. CVE-2026-78159Critical
    The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation
    CVSS 9.8
    stellarwp/The Events Calendargeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  12. CVE-2026-78006Critical
    The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution
    CVSS 9.8
    stellarwp/The Events Calendargeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  13. CVE-2026-85198Medium
    MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path
    CVSS 6.5
    themeisle/MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEOgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  14. CVE-2026-17585Medium
    Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter
    CVSS 5.3
    wproyal/Royal Addons for Elementor – Addons and Templates Kit for Elementorgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  15. CVE-2026-85200High
    GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion
    CVSS 7.5
    ninjew/GEO my WPgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  16. CVE-2026-16482High
    rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection via 'compare' Parameter
    CVSS 7.5
    rtcamp/rtMedia for WordPress, BuddyPress and bbPressgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 15, 2026View HOL analysis
  17. CVE-2026-87919Medium
    Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode
    CVSS 4.9
    Unknown/Product XML Feed Manager for WooCommercegeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  18. CVE-2026-87918Medium
    WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions
    CVSS 5.3
    Unknown/WPBotgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  19. CVE-2026-87916Medium
    WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure
    CVSS 5.3
    Unknown/WPBotgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-87894Medium
    Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR
    CVSS 5.3
    Unknown/Rox Appointment Bookinggeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  21. CVE-2026-87892Medium
    Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass
    CVSS 5.3
    Unknown/Rox Appointment Bookinggeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  22. CVE-2026-87891Medium
    Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API
    CVSS 6.5
    Unknown/Rox Appointment Bookinggeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  23. CVE-2026-87888High
    YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route
    CVSS 8.0
    Unknown/YayPricinggeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  24. CVE-2026-87842High
    Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure
    CVSS 7.5
    Unknown/Zonifygeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-87797Medium
    Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note
    CVSS 4.3
    Unknown/Sprout Invoicesgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  26. CVE-2026-87759High
    Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation
    CVSS 8.8
    Unknown/Add User Autocompletegeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  27. CVE-2026-86790Medium
    WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode
    CVSS 6.8
    Unknown/WP Highlight Boxgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  28. CVE-2026-85681Critical
    WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Update
    CVSS 9.8
    Unknown/WP Componentgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  29. CVE-2026-84171Critical
    WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    Unknown/WP images upload on piclectgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  30. CVE-2026-84099High
    IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php
    CVSS 8.1
    Unknown/wpstorecartgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  31. CVE-2026-84047High
    Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action
    CVSS 8.6
    Unknown/Album Cover Findergeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  32. CVE-2026-84025Low
    BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR
    CVSS 2.2
    Unknown/BEARgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  33. CVE-2026-84024Medium
    BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF
    CVSS 4.3
    Unknown/BEARgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  34. CVE-2026-84023Medium
    BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF
    CVSS 6.5
    Unknown/BEARgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  35. CVE-2026-82851Low
    Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR
    CVSS 2.7
    Unknown/Masteriyo LMSgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  36. CVE-2026-82847Medium
    Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights
    CVSS 6.8
    Unknown/Masteriyo LMSgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  37. CVE-2026-82845Critical
    Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection
    CVSS 9.9
    Unknown/Masteriyo LMSgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-81742High
    BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation
    CVSS 8.8
    Unknown/BE REST Endpointsgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  39. CVE-2026-81429High
    Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF
    CVSS 7.1
    Unknown/Export & Import WPBakery Page Buildergeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  40. CVE-2026-81402Critical
    DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    Unknown/DS Ad Rotatorgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  41. CVE-2026-81090High
    Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF
    CVSS 7.2
    Unknown/Gpx2Graphicsgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  42. CVE-2026-80494High
    Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download
    CVSS 8.6
    Unknown/Yogeta WP Cloudgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  43. CVE-2026-80491High
    SAMO Forms <= 1.0.0 - Unauthenticated SQLi
    CVSS 8.6
    Unknown/SAMO Formsgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
  44. CVE-2026-78152Medium
    SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema
    CVSS 5.3
    Unknown/SureRank SEOgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  45. CVE-2026-77753Medium
    Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords
    CVSS 5.5
    Unknown/Temporary Login Without Passwordgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  46. CVE-2026-77752High
    Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation
    CVSS 7.2
    Unknown/Temporary Login Without Passwordgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  47. CVE-2026-77705High
    Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
    CVSS 7.2
    Unknown/Booking for Appointments and Events Calendargeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  48. CVE-2026-77689Medium
    Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass
    CVSS 5.3
    Unknown/Booking for Appointments and Events Calendargeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-77006Critical
    WebTotem Backups < 1.1.0 - Subscriber+ Arbitrary File Deletion via Path Traversal
    CVSS 9.6
    Unknown/WebTotem Backupsgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 23, 2026 Fix availableView HOL analysis
  50. CVE-2026-77005Critical
    Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal
    CVSS 9.6
    Unknown/CODE MONKEYS PROPOSALSgeneric
    PublishedSep 12, 2026First seen at HOL Sep 12, 2026Updated Sep 14, 2026View HOL analysis
Page 162 of 828
Previous160161162163164Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard