1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 4:00 PM 16,249 active 1,443 known exploited

Catalog summary

16,249

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 4:00 PM 16,249 active 1,443 known exploited

Catalog summary

16,249

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 851–900 of 16,249 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-70604High
    Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
    CVSS 7.4
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-13477Medium
    IBM QRadar SIEM is vulnerable to remote code execution by privileged users
    CVSS 4.7
    IBM/QRadargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-8400High
    Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
    CVSS 8.1
    IBM/WebSphere Application Server, IBM/WebSphere Application Server - Libertygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-12730Low
    Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers
    CVSS 3.8
    IBM/Business Automation Workflow containers and traditionalgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-70603Medium
    Electron: shell.openPath path validation bypass via embedded null byte
    CVSS 6.0
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  6. CVE-2026-70602Medium
    Electron: Extension tab APIs operate across session boundaries
    CVSS 6.6
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-12762Medium
    Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
    CVSS 5.3
    IBM/Cloud Pak For Business Automationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-70601High
    Electron: Context isolation bypass via Function.prototype.bind hijack
    CVSS 7.5
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-70600Low
    Electron: Cross-origin iframe can position native autofill popup
    CVSS 3.1
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  10. CVE-2026-9203High
    Server-side request forgery in Progress MarkLogic Server
    CVSS 8.5
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-9195Critical
    Cross-site scripting in Progress MarkLogic Server Query Console
    CVSS 9.3
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-9193Critical
    Privilege escalation in Progress MarkLogic Server Hadoop integration
    CVSS 9.9
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-70599Medium
    Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
    CVSS 5.9
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-9192Critical
    Authentication bypass in Progress MarkLogic Server ODBC App Server
    CVSS 9.8
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-9190Critical
    HTTP request smuggling in Progress MarkLogic Server
    CVSS 9.1
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  16. CVE-2026-8709Critical
    Privilege escalation in Progress MarkLogic Server REST document patch operation
    CVSS 9.9
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-7557Critical
    SAML authentication bypass in Progress MarkLogic Server
    CVSS 9.1
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-7329Critical
    Privilege escalation in Progress MarkLogic Server REST query interfaces
    CVSS 9.9
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-7327High
    Privilege escalation in Progress MarkLogic Server REST API document processing
    CVSS 8.1
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-7326High
    Cross-site request forgery in Progress MarkLogic Server Admin UI
    CVSS 7.5
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-70598Low
    Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
    CVSS 3.9
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-70597Medium
    Electron: Parent process code-sign check is spoofable
    CVSS 6.3
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-60053Critical
    Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
    CVSS 9.1
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-60023High
    Apache Answer: Unauthorized disclosure of deleted or pending answer content
    CVSS 7.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-50749Medium
    Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
    CVSS 6.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-48912Medium
    Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
    CVSS 6.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-15572High
    Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-48911High
    Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
    CVSS 7.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-48834High
    Apache Answer: Denial of service via crafted Accept-Language header parsing
    CVSS 7.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-16442High
    Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-53992Medium
    Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters
    CVSS 6.1
    ProjectSend/ProjectSendgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-49331Medium
    Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-39924Medium
    Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation
    CVSS 6.8
    Flarum/Flarum Frameworkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-70596Medium
    Ghost: Cross-Site Scripting in Feature Image Captions
    CVSS 4.3
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-15587Critical
    Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header
    CVSS 9.4
    Google Cloud/Google SecOps (Chronicle SOAR)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-39923High
    Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
    CVSS 8.1
    Flarum/Flarum Frameworkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-70595Medium
    Ghost: Server-Side Request Forgery Mitigation Issue
    CVSS 4.0
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  38. CVE-2026-12410High
    CCleaner local privilege escalation via link following on uninstall
    CVSS 7.8
    Gen Digital/CCleanergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-17613High
    CVE-2026-17613
    CVSS 7.5
    Penpot/Penpotgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-54876High
    Client-Side Memory Leak in OCSP Response Checking
    CVSS 7.5
    OpenSSL/OpenSSLgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-16100Medium
    Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-16071Medium
    Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-16102High
    Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-15573High
    Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-16443High
    Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-67623High
    Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
    CVSS 8.8
    mistralai/mistral-vibegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-15979High
    Content Egg <= 11.3.0 - Authenticated (Author+) Arbitrary File Deletion
    CVSS 8.1
    keywordrush/Content Egg – Affiliate Product Importer & Price Comparisongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-7529High
    wiseCampaign <= 1.1.16 - Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API
    CVSS 7.5
    wisemattic/wiseCampaign – WooCommerce Conversions Made Easygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-17506High
    Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    bensibley/Independent Analytics – WordPress Analytics Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2026-7456Medium
    Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action
    CVSS 6.5
    webocoders/Udimi Toolsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
Page 18 of 325
Previous1617181920Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 851–900 of 16,249 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-70604High
    Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
    CVSS 7.4
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-13477Medium
    IBM QRadar SIEM is vulnerable to remote code execution by privileged users
    CVSS 4.7
    IBM/QRadargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-8400High
    Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
    CVSS 8.1
    IBM/WebSphere Application Server, IBM/WebSphere Application Server - Libertygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-12730Low
    Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers
    CVSS 3.8
    IBM/Business Automation Workflow containers and traditionalgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-70603Medium
    Electron: shell.openPath path validation bypass via embedded null byte
    CVSS 6.0
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  6. CVE-2026-70602Medium
    Electron: Extension tab APIs operate across session boundaries
    CVSS 6.6
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-12762Medium
    Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
    CVSS 5.3
    IBM/Cloud Pak For Business Automationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-70601High
    Electron: Context isolation bypass via Function.prototype.bind hijack
    CVSS 7.5
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-70600Low
    Electron: Cross-origin iframe can position native autofill popup
    CVSS 3.1
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  10. CVE-2026-9203High
    Server-side request forgery in Progress MarkLogic Server
    CVSS 8.5
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-9195Critical
    Cross-site scripting in Progress MarkLogic Server Query Console
    CVSS 9.3
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-9193Critical
    Privilege escalation in Progress MarkLogic Server Hadoop integration
    CVSS 9.9
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-70599Medium
    Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
    CVSS 5.9
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-9192Critical
    Authentication bypass in Progress MarkLogic Server ODBC App Server
    CVSS 9.8
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-9190Critical
    HTTP request smuggling in Progress MarkLogic Server
    CVSS 9.1
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  16. CVE-2026-8709Critical
    Privilege escalation in Progress MarkLogic Server REST document patch operation
    CVSS 9.9
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-7557Critical
    SAML authentication bypass in Progress MarkLogic Server
    CVSS 9.1
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-7329Critical
    Privilege escalation in Progress MarkLogic Server REST query interfaces
    CVSS 9.9
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-7327High
    Privilege escalation in Progress MarkLogic Server REST API document processing
    CVSS 8.1
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-7326High
    Cross-site request forgery in Progress MarkLogic Server Admin UI
    CVSS 7.5
    Progress Software Corporation/MarkLogic Servergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-70598Low
    Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
    CVSS 3.9
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-70597Medium
    Electron: Parent process code-sign check is spoofable
    CVSS 6.3
    electron, electron/electrongeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-60053Critical
    Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
    CVSS 9.1
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-60023High
    Apache Answer: Unauthorized disclosure of deleted or pending answer content
    CVSS 7.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-50749Medium
    Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
    CVSS 6.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-48912Medium
    Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
    CVSS 6.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-15572High
    Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-48911High
    Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
    CVSS 7.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-48834High
    Apache Answer: Denial of service via crafted Accept-Language header parsing
    CVSS 7.5
    Apache Software Foundation/Apache Answergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-16442High
    Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-53992Medium
    Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters
    CVSS 6.1
    ProjectSend/ProjectSendgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-49331Medium
    Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-39924Medium
    Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation
    CVSS 6.8
    Flarum/Flarum Frameworkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-70596Medium
    Ghost: Cross-Site Scripting in Feature Image Captions
    CVSS 4.3
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-15587Critical
    Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header
    CVSS 9.4
    Google Cloud/Google SecOps (Chronicle SOAR)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-39923High
    Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
    CVSS 8.1
    Flarum/Flarum Frameworkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-70595Medium
    Ghost: Server-Side Request Forgery Mitigation Issue
    CVSS 4.0
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  38. CVE-2026-12410High
    CCleaner local privilege escalation via link following on uninstall
    CVSS 7.8
    Gen Digital/CCleanergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-17613High
    CVE-2026-17613
    CVSS 7.5
    Penpot/Penpotgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-54876High
    Client-Side Memory Leak in OCSP Response Checking
    CVSS 7.5
    OpenSSL/OpenSSLgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-16100Medium
    Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-16071Medium
    Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-16102High
    Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-15573High
    Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
    CVSS 8.1
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-16443High
    Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
    CVSS 7.4
    Affected software not mappedEcosystem not listed
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-67623High
    Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
    CVSS 8.8
    mistralai/mistral-vibegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  47. CVE-2026-15979High
    Content Egg <= 11.3.0 - Authenticated (Author+) Arbitrary File Deletion
    CVSS 8.1
    keywordrush/Content Egg – Affiliate Product Importer & Price Comparisongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-7529High
    wiseCampaign <= 1.1.16 - Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API
    CVSS 7.5
    wisemattic/wiseCampaign – WooCommerce Conversions Made Easygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-17506High
    Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    bensibley/Independent Analytics – WordPress Analytics Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2026-7456Medium
    Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action
    CVSS 6.5
    webocoders/Udimi Toolsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
Page 18 of 325
Previous1617181920Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard