1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 5:23 PM 16,268 active 1,443 known exploited

Catalog summary

16,268

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 5:23 PM 16,268 active 1,443 known exploited

Catalog summary

16,268

Active CVEs

8,392

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,001–1,050 of 16,268 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64579Unknown severity
    xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-64578Unknown severity
    ksmbd: validate compound request size before reading StructureSize2
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  3. CVE-2026-64577Unknown severity
    gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  4. CVE-2026-64576Unknown severity
    nexthop: initialize extack in nh_res_bucket_migrate()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  5. CVE-2026-64575Unknown severity
    bpf: tcp: fix double sock release on batch realloc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-64574Unknown severity
    wifi: mac80211: tear down new links on vif update error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-64573Unknown severity
    Bluetooth: qca: fix NVM tag length underflow in TLV parser
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-64572Unknown severity
    ipv4: fib: free fib_alias with kfree_rcu() on insert error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-64571Unknown severity
    wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-64570Unknown severity
    wifi: mac80211: fix fils_discovery double free on alloc failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-64569Unknown severity
    mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-64568Unknown severity
    wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-64567Unknown severity
    btrfs: reject free space cache with more entries than pages
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-64566Unknown severity
    xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-55997High
    Long-lived Rancher registration token exposed in plaintext
    CVSS 8.8
    rancher/ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  16. CVE-2026-55998Medium
    Cluster Existence Oracle via Unauthenticated Import Endpoint
    CVSS 5.3
    SUSE/Ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-59675High
    Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service
    CVSS 7.5
    SUSE/Ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-55996Medium
    Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent
    CVSS 4.3
    SUSE/Ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-11920Medium
    JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter
    CVSS 4.9
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  20. CVE-2026-11977Medium
    WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
    CVSS 6.5
    afthemes/WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatarsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-7520High
    MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action
    CVSS 8.1
    mailmunch/Mailmunch Forms for Mailchimpgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-11969Medium
    WP TripAdvisor Review Slider <= 14.3 - Authenticated (Administrator+) SQL Injection
    CVSS 4.9
    jgwhite33/WP TripAdvisor Review Slidergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  23. CVE-2026-4431Critical
    Easy Post Submission <= 2.3.0 - Missing Authorization
    CVSS 9.1
    themeruby/Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPressgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-6020High
    ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
    CVSS 7.2
    devitemsllc/ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  25. CVE-2026-71215High
    art-template: Path Traversal in Sub-Template Resolution via include()/extend()
    CVSS 7.5
    art-template/art-templategeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  26. CVE-2026-71214Critical
    NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server
    CVSS 9.8
    NASA-AMMOS/plandev (sequencing-server)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  27. CVE-2026-71213Critical
    typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force
    CVSS 9.1
    typemill/typemillgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-71212Medium
    xidown: Argument Injection via Unterminated yt-dlp Command Line Construction
    CVSS 4.4
    indravoyager/xidowngeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-71211High
    mlflow: Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
    CVSS 7.1
    mlflow/mlflowgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  30. CVE-2026-71210Medium
    mealie: DNS-Rebinding TOCTOU in SSRF Guard Allows Internal Network and Cloud Metadata Access
    CVSS 5.3
    mealie-recipes/mealiegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  31. CVE-2026-71209High
    audiobookshelf: %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal
    CVSS 7.5
    advplyr/audiobookshelfgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-71208Medium
    KubeSphere: SSRF via Unvalidated Cluster CRD Connection Endpoint in Cluster Reconciliation
    CVSS 6.5
    kubesphere/KubeSpheregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-71207Critical
    Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass
    CVSS 9.8
    mrswapnilsahu/Stock-Inventory-Management-Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-71206High
    shiori: JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
    CVSS 8.3
    go-shiori/shiorigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-71205Medium
    changedetection.io: No Rate Limiting on /login Enables Unlimited Password Brute-Force
    CVSS 6.5
    dgtlmoon/changedetection.iogeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-71204Medium
    changedetection.io: Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
    CVSS 6.2
    dgtlmoon/changedetection.iogeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-71203Medium
    changedetection.io: Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
    CVSS 5.3
    dgtlmoon/changedetection.iogeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-71202High
    raster: Integer Underflow in crop() Offset Handling Causes Capacity-Overflow Panic
    CVSS 7.5
    kosinix/rastergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-70378High
    imagecli: Negative carve Ratio Bypasses Bounds Check and Crashes Process via Reachable Panic
    CVSS 7.5
    theotherphil/imagecligeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-70377High
    imagecli: Uncontrolled Memory Allocation via Unbounded scale Ratio Causes Denial of Service
    CVSS 7.5
    theotherphil/imagecligeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  41. CVE-2026-70376Critical
    Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE
    CVSS 9.6
    pluck-cms/Pluck CMSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-55747Medium
    PocketFlow: Path Traversal in pocketflow-coding-agent Cookbook Example File Tools
    CVSS 6.8
    The-Pocket/PocketFlow (pocketflow-coding-agent cookbook example)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  43. CVE-2026-55739High
    Crater: Missing Tenant-Ownership Check in CustomerPolicy Allows Cross-Company Customer Data Theft and Deletion
    CVSS 8.3
    crater-invoice/Cratergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-54418High
    Leantime: Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and Bypass
    CVSS 8.1
    Leantime/Leantimegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-54416High
    Pluck CMS: Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist
    CVSS 7.2
    pluck-cms/Pluck CMSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-61486Critical
    Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
    CVSS 9.8
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-61485High
    Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
    CVSS 7.5
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-61484Critical
    Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
    CVSS 9.8
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-12000High
    Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API
    CVSS 7.5
    cyberlord92/Page and Post Restrictiongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2026-7105Medium
    Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function
    CVSS 4.3
    xpro/Xpro Addons — 140+ Widgets for Elementorgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
Page 21 of 326
Previous1920212223Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,392

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,001–1,050 of 16,268 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64579Unknown severity
    xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-64578Unknown severity
    ksmbd: validate compound request size before reading StructureSize2
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  3. CVE-2026-64577Unknown severity
    gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  4. CVE-2026-64576Unknown severity
    nexthop: initialize extack in nh_res_bucket_migrate()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  5. CVE-2026-64575Unknown severity
    bpf: tcp: fix double sock release on batch realloc
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-64574Unknown severity
    wifi: mac80211: tear down new links on vif update error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-64573Unknown severity
    Bluetooth: qca: fix NVM tag length underflow in TLV parser
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-64572Unknown severity
    ipv4: fib: free fib_alias with kfree_rcu() on insert error path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-64571Unknown severity
    wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-64570Unknown severity
    wifi: mac80211: fix fils_discovery double free on alloc failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-64569Unknown severity
    mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-64568Unknown severity
    wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-64567Unknown severity
    btrfs: reject free space cache with more entries than pages
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  14. CVE-2026-64566Unknown severity
    xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  15. CVE-2026-55997High
    Long-lived Rancher registration token exposed in plaintext
    CVSS 8.8
    rancher/ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  16. CVE-2026-55998Medium
    Cluster Existence Oracle via Unauthenticated Import Endpoint
    CVSS 5.3
    SUSE/Ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-59675High
    Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service
    CVSS 7.5
    SUSE/Ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-55996Medium
    Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent
    CVSS 4.3
    SUSE/Ranchergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-11920Medium
    JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter
    CVSS 4.9
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  20. CVE-2026-11977Medium
    WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
    CVSS 6.5
    afthemes/WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatarsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-7520High
    MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action
    CVSS 8.1
    mailmunch/Mailmunch Forms for Mailchimpgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-11969Medium
    WP TripAdvisor Review Slider <= 14.3 - Authenticated (Administrator+) SQL Injection
    CVSS 4.9
    jgwhite33/WP TripAdvisor Review Slidergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  23. CVE-2026-4431Critical
    Easy Post Submission <= 2.3.0 - Missing Authorization
    CVSS 9.1
    themeruby/Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPressgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-6020High
    ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
    CVSS 7.2
    devitemsllc/ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugingeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  25. CVE-2026-71215High
    art-template: Path Traversal in Sub-Template Resolution via include()/extend()
    CVSS 7.5
    art-template/art-templategeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  26. CVE-2026-71214Critical
    NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server
    CVSS 9.8
    NASA-AMMOS/plandev (sequencing-server)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  27. CVE-2026-71213Critical
    typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force
    CVSS 9.1
    typemill/typemillgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-71212Medium
    xidown: Argument Injection via Unterminated yt-dlp Command Line Construction
    CVSS 4.4
    indravoyager/xidowngeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-71211High
    mlflow: Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
    CVSS 7.1
    mlflow/mlflowgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  30. CVE-2026-71210Medium
    mealie: DNS-Rebinding TOCTOU in SSRF Guard Allows Internal Network and Cloud Metadata Access
    CVSS 5.3
    mealie-recipes/mealiegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  31. CVE-2026-71209High
    audiobookshelf: %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal
    CVSS 7.5
    advplyr/audiobookshelfgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-71208Medium
    KubeSphere: SSRF via Unvalidated Cluster CRD Connection Endpoint in Cluster Reconciliation
    CVSS 6.5
    kubesphere/KubeSpheregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-71207Critical
    Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass
    CVSS 9.8
    mrswapnilsahu/Stock-Inventory-Management-Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-71206High
    shiori: JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
    CVSS 8.3
    go-shiori/shiorigeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-71205Medium
    changedetection.io: No Rate Limiting on /login Enables Unlimited Password Brute-Force
    CVSS 6.5
    dgtlmoon/changedetection.iogeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-71204Medium
    changedetection.io: Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
    CVSS 6.2
    dgtlmoon/changedetection.iogeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-71203Medium
    changedetection.io: Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
    CVSS 5.3
    dgtlmoon/changedetection.iogeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-71202High
    raster: Integer Underflow in crop() Offset Handling Causes Capacity-Overflow Panic
    CVSS 7.5
    kosinix/rastergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-70378High
    imagecli: Negative carve Ratio Bypasses Bounds Check and Crashes Process via Reachable Panic
    CVSS 7.5
    theotherphil/imagecligeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-70377High
    imagecli: Uncontrolled Memory Allocation via Unbounded scale Ratio Causes Denial of Service
    CVSS 7.5
    theotherphil/imagecligeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  41. CVE-2026-70376Critical
    Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE
    CVSS 9.6
    pluck-cms/Pluck CMSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-55747Medium
    PocketFlow: Path Traversal in pocketflow-coding-agent Cookbook Example File Tools
    CVSS 6.8
    The-Pocket/PocketFlow (pocketflow-coding-agent cookbook example)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  43. CVE-2026-55739High
    Crater: Missing Tenant-Ownership Check in CustomerPolicy Allows Cross-Company Customer Data Theft and Deletion
    CVSS 8.3
    crater-invoice/Cratergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-54418High
    Leantime: Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and Bypass
    CVSS 8.1
    Leantime/Leantimegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-54416High
    Pluck CMS: Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist
    CVSS 7.2
    pluck-cms/Pluck CMSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-61486Critical
    Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
    CVSS 9.8
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-61485High
    Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
    CVSS 7.5
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-61484Critical
    Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
    CVSS 9.8
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-12000High
    Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API
    CVSS 7.5
    cyberlord92/Page and Post Restrictiongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2026-7105Medium
    Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function
    CVSS 4.3
    xpro/Xpro Addons — 140+ Widgets for Elementorgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
Page 21 of 326
Previous1920212223Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard