1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 5:55 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 5:55 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

8,392

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,051–1,100 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-6972Medium
    SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    sonalsinha21/SKT Skill Bargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  2. CVE-2026-7441Medium
    Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    alphawolf/Simple Yearly Archivegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-7444High
    Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery
    CVSS 8.1
    cornelraiu-1/Search Analytics for WPgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  4. CVE-2026-5651Medium
    Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter
    CVSS 4.9
    2wstechnologies/Askeet — Talk to Your WooCommerce Datageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  5. CVE-2026-7693High
    Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter
    CVSS 7.2
    inisev/Backup Migrationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  6. CVE-2026-18881High
    TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter
    CVSS 7.5
    realmag777/TableOn – WordPress Posts Table Filterablegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  7. CVE-2026-6147High
    LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
    CVSS 8.8
    lightsyncpro/LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstockgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  8. CVE-2026-15281Medium
    User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection
    CVSS 6.5
    gm_alex/User Access Managergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  9. CVE-2026-17505Medium
    TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting
    CVSS 6.1
    cozmoslabs/TranslatePress – Translate Multilingual sites with AI Translationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  10. CVE-2026-11454Medium
    Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  11. CVE-2026-5116Medium
    Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting
    CVSS 4.4
    sevenspark/DTX – Dynamic Text Extension for Contact Form 7generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  12. CVE-2026-17532Medium
    Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
    CVSS 6.1
    seraphinitesoft/Seraphinite Acceleratorgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  13. CVE-2026-6079High
    Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion
    CVSS 7.3
    ho3einie/Material Dashboardgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  14. CVE-2026-6627High
    WPFormify <= 1.1.1 - Missing Authorization
    CVSS 8.2
    saadiqbal/WPFormify – Stripe Payments with Form and Checkoutgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  15. CVE-2026-7726Medium
    Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action
    CVSS 6.5
    techeshta/Layouts for WPBakerygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-6639High
    AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenticated Sensitive Information Exposure
    CVSS 7.5
    wupsales/AI Copilot – Content Generatorgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-5581Critical
    Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion
    CVSS 9.1
    sh1zen/Multi Uploader for Gravity Formsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-5108Medium
    Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting
    CVSS 4.4
    superpwa/Super Progressive Web Appsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  19. CVE-2026-61483High
    Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
    CVSS 7.5
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-71201Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    OpenStack/Ironicgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-49004Critical
    PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product
    CVSS 10.0
    ZTE/NX799J (Red Magic 11 Air)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-17515Medium
    MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item
    CVSS 4.3
    Unknown/MLSImport: IDX Plugin & MLS Plugin for Real Estate Listingsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-16055High
    Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
    CVSS 7.5
    Unknown/Contest Gallerygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-16036High
    miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
    CVSS 7.5
    Unknown/miniOrange 2FAgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-15372High
    WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
    CVSS 7.5
    Unknown/WP 2FAgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-15360Critical
    Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
    CVSS 9.1
    Unknown/Ajax Load Moregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-15210Critical
    Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
    CVSS 9.1
    Unknown/OTP Login With Phone Number, OTP Verificationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-15230High
    YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
    CVSS 8.1
    Unknown/YayPricinggeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-14553High
    Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
    CVSS 8.1
    Unknown/zportalsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-15677Low
    GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
    CVSS 3.5
    Unknown/GeoDirectorygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-16993Low
    DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory
    CVSS 3.7
    Unknown/DHL Shipping Germany for WooCommercegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-16981Medium
    DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
    CVSS 5.3
    Unknown/DHL Shipping Germany for WooCommercegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-16968Medium
    GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
    CVSS 6.5
    Unknown/GeoDirectorygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-16942Medium
    WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
    CVSS 5.4
    Unknown/WP Custom HTML Pagegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-16940Critical
    Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
    CVSS 10.0
    Unknown/Custom Fieldsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-16746Low
    MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint
    CVSS 2.7
    Unknown/MultiVendorXgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-16736High
    User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
    CVSS 7.5
    Unknown/User Registration & Membershipgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-16613Medium
    GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
    CVSS 4.3
    Unknown/GDPR Cookie Compliancegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-16605High
    MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization
    CVSS 7.2
    Unknown/MultiVendorXgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-16604High
    Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute
    CVSS 7.5
    Unknown/Passstergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-16603High
    Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
    CVSS 7.5
    Unknown/Passstergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-16602High
    Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint
    CVSS 7.5
    Unknown/Passstergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-16583Medium
    Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
    CVSS 6.1
    Unknown/Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & Moregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-16573High
    Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
    CVSS 7.5
    Unknown/Bit Formgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-16561High
    Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
    CVSS 7.5
    Unknown/Sunshine Photo Cartgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-68080Medium
    Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-70375High
    HashBrown CMS: OS Command Injection via Git Deployer Branch Field
    CVSS 8.8
    HashBrownCMS/hashbrown-cmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-70374High
    HashBrown CMS: OS Command Injection in Media Upload Thumbnail Generation
    CVSS 8.8
    HashBrownCMS/hashbrown-cmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-67592High
    Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  50. CVE-2026-67555Medium
    Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
Page 22 of 326
Previous2021222324Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,392

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,051–1,100 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-6972Medium
    SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    sonalsinha21/SKT Skill Bargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  2. CVE-2026-7441Medium
    Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    alphawolf/Simple Yearly Archivegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-7444High
    Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery
    CVSS 8.1
    cornelraiu-1/Search Analytics for WPgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  4. CVE-2026-5651Medium
    Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter
    CVSS 4.9
    2wstechnologies/Askeet — Talk to Your WooCommerce Datageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  5. CVE-2026-7693High
    Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter
    CVSS 7.2
    inisev/Backup Migrationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  6. CVE-2026-18881High
    TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter
    CVSS 7.5
    realmag777/TableOn – WordPress Posts Table Filterablegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  7. CVE-2026-6147High
    LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
    CVSS 8.8
    lightsyncpro/LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstockgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  8. CVE-2026-15281Medium
    User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection
    CVSS 6.5
    gm_alex/User Access Managergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  9. CVE-2026-17505Medium
    TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting
    CVSS 6.1
    cozmoslabs/TranslatePress – Translate Multilingual sites with AI Translationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  10. CVE-2026-11454Medium
    Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  11. CVE-2026-5116Medium
    Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting
    CVSS 4.4
    sevenspark/DTX – Dynamic Text Extension for Contact Form 7generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  12. CVE-2026-17532Medium
    Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
    CVSS 6.1
    seraphinitesoft/Seraphinite Acceleratorgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  13. CVE-2026-6079High
    Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion
    CVSS 7.3
    ho3einie/Material Dashboardgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  14. CVE-2026-6627High
    WPFormify <= 1.1.1 - Missing Authorization
    CVSS 8.2
    saadiqbal/WPFormify – Stripe Payments with Form and Checkoutgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  15. CVE-2026-7726Medium
    Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action
    CVSS 6.5
    techeshta/Layouts for WPBakerygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-6639High
    AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenticated Sensitive Information Exposure
    CVSS 7.5
    wupsales/AI Copilot – Content Generatorgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-5581Critical
    Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion
    CVSS 9.1
    sh1zen/Multi Uploader for Gravity Formsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-5108Medium
    Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting
    CVSS 4.4
    superpwa/Super Progressive Web Appsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  19. CVE-2026-61483High
    Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
    CVSS 7.5
    Apache Software Foundation/Apache Lucygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-71201Medium
    CISA ADP Vulnrichment
    CVSS 5.0
    OpenStack/Ironicgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-49004Critical
    PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product
    CVSS 10.0
    ZTE/NX799J (Red Magic 11 Air)generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-17515Medium
    MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item
    CVSS 4.3
    Unknown/MLSImport: IDX Plugin & MLS Plugin for Real Estate Listingsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-16055High
    Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
    CVSS 7.5
    Unknown/Contest Gallerygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-16036High
    miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
    CVSS 7.5
    Unknown/miniOrange 2FAgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-15372High
    WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
    CVSS 7.5
    Unknown/WP 2FAgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-15360Critical
    Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
    CVSS 9.1
    Unknown/Ajax Load Moregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-15210Critical
    Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
    CVSS 9.1
    Unknown/OTP Login With Phone Number, OTP Verificationgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-15230High
    YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
    CVSS 8.1
    Unknown/YayPricinggeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-14553High
    Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
    CVSS 8.1
    Unknown/zportalsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2025-15677Low
    GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
    CVSS 3.5
    Unknown/GeoDirectorygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-16993Low
    DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory
    CVSS 3.7
    Unknown/DHL Shipping Germany for WooCommercegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-16981Medium
    DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
    CVSS 5.3
    Unknown/DHL Shipping Germany for WooCommercegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-16968Medium
    GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
    CVSS 6.5
    Unknown/GeoDirectorygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-16942Medium
    WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
    CVSS 5.4
    Unknown/WP Custom HTML Pagegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-16940Critical
    Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
    CVSS 10.0
    Unknown/Custom Fieldsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  36. CVE-2026-16746Low
    MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint
    CVSS 2.7
    Unknown/MultiVendorXgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-16736High
    User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
    CVSS 7.5
    Unknown/User Registration & Membershipgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-16613Medium
    GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
    CVSS 4.3
    Unknown/GDPR Cookie Compliancegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-16605High
    MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization
    CVSS 7.2
    Unknown/MultiVendorXgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-16604High
    Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute
    CVSS 7.5
    Unknown/Passstergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-16603High
    Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
    CVSS 7.5
    Unknown/Passstergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-16602High
    Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint
    CVSS 7.5
    Unknown/Passstergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-16583Medium
    Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
    CVSS 6.1
    Unknown/Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & Moregeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-16573High
    Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
    CVSS 7.5
    Unknown/Bit Formgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-16561High
    Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
    CVSS 7.5
    Unknown/Sunshine Photo Cartgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-68080Medium
    Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-70375High
    HashBrown CMS: OS Command Injection via Git Deployer Branch Field
    CVSS 8.8
    HashBrownCMS/hashbrown-cmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-70374High
    HashBrown CMS: OS Command Injection in Media Upload Thumbnail Generation
    CVSS 8.8
    HashBrownCMS/hashbrown-cmsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-67592High
    Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  50. CVE-2026-67555Medium
    Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
Page 22 of 326
Previous2021222324Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard