1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 6:10 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 6:10 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

8,418

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,101–1,150 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-68078Medium
    Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-66277Medium
    Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2026-67554Medium
    Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2026-68077Medium
    Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-66276Medium
    Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-67591Medium
    Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-67553Medium
    Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2026-68075Medium
    Apache Qpid Broker-J: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-66275Medium
    Apache Qpid Proton-J: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-67590High
    Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  11. CVE-2026-67552High
    Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-68073High
    Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-66274High
    Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-67589High
    Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-5062Medium
    PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter
    CVSS 4.9
    supercleanse/PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Linksgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-7753Medium
    Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure
    CVSS 6.5
    stylemix/Cost Calculator Buildergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-15941Medium
    Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection
    CVSS 6.5
    Relevanssi/Relevanssi Premium – A Better Search, comesio/Relevanssi – A Better Searchgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-67551High
    Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-68060High
    Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  20. CVE-2026-66273High
    Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-67588High
    Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-67465High
    Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-68074High
    Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-66257High
    Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-71192Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    OpenStack/Swiftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-71191Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    OpenStack/Swiftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2026-71190High
    CVE Program Container
    CVSS 8.7
    OpenStack/Swiftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  28. CVE-2026-18903Medium
    yeqifu warehouse FileController.java path traversal
    CVSS 4.3
    yeqifu/warehousegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-55707High
    CVE Program Container
    CVSS 7.1
    OpenStack/Neutrongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-18902High
    H3C NX15 esps repeaterproc command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  31. CVE-2026-66839High
    CISA ADP Vulnrichment
    CVSS 8.4
    Integrated Systems Technologies, Inc./NetKids iMarkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-66344Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Integrated Systems Technologies, Inc./NetKids iMarkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-9273Critical
    Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover
    CVSS 9.3
    stellarwp/Membership Plugin – Kadence Membershipsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-11421Medium
    ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17.4 - Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter
    CVSS 6.5
    wedevs/ERP: Complete HR, Accounting & CRM Suite Built for WooCommercegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-8790Medium
    Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Scripting
    CVSS 6.1
    antoineh/Football Poolgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-18322High
    Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator
    CVSS 8.8
    supsysticcom/Smart Popup by Supsysticgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-15918High
    VikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection
    CVSS 7.5
    e4jvikwp/VikAppointments Services Booking Calendargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-8761High
    Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation
    CVSS 8.8
    dokaninc/Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-16143High
    VikRentItems Flexible Rental Management System <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    e4jvikwp/VikRentItems Flexible Rental Management Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18901High
    H3C NX15 Web API esps service.add routine
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  41. CVE-2026-18900High
    H3C NX15 Backend RPC esps file.exec os command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-18898High
    UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow
    CVSS 8.8
    UTT/HiPER 1200GWgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  43. CVE-2026-18897High
    UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow
    CVSS 8.8
    UTT/HiPER 1250GWgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-18907High
    PathTravelsal Vulnerability in com.talpa.hibrowser
    CVSS 7.5
    TECNO Mobile/Hi Browsergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-18896Medium
    lavkush-maurya Student-Registration-System changepass.php sql injection
    CVSS 6.3
    lavkush-maurya/Student-Registration-Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-18895High
    UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow
    CVSS 8.8
    UTT/HiPER 1250GWgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-18859High
    ESAFENET CDG usbkey;logindojojs sql injection
    CVSS 7.3
    ESAFENET/CDGgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-18856Medium
    Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery
    CVSS 4.7
    Poesis/Rhymix CMSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-18854High
    Shandong Hoteam PDM Product Data Management System DataService GetStoredClassByFilter sql injection
    CVSS 7.3
    Shandong Hoteam/PDM Product Data Management Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2025-63822High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
Page 23 of 326
Previous2122232425Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,418

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,101–1,150 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-68078Medium
    Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-66277Medium
    Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2026-67554Medium
    Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2026-68077Medium
    Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-66276Medium
    Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-67591Medium
    Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-67553Medium
    Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2026-68075Medium
    Apache Qpid Broker-J: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-66275Medium
    Apache Qpid Proton-J: Incoming session flow control window can be exceeded
    CVSS 6.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-67590High
    Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  11. CVE-2026-67552High
    Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-68073High
    Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-66274High
    Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-67589High
    Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-5062Medium
    PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter
    CVSS 4.9
    supercleanse/PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Linksgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-7753Medium
    Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure
    CVSS 6.5
    stylemix/Cost Calculator Buildergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-15941Medium
    Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection
    CVSS 6.5
    Relevanssi/Relevanssi Premium – A Better Search, comesio/Relevanssi – A Better Searchgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-67551High
    Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-68060High
    Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  20. CVE-2026-66273High
    Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-67588High
    Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid ProtonJ2generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-67465High
    Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton Dotnetgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-68074High
    Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Broker-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-66257High
    Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
    CVSS 7.5
    Apache Software Foundation/Apache Qpid Proton-Jgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-71192Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    OpenStack/Swiftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-71191Medium
    CISA ADP Vulnrichment
    CVSS 6.0
    OpenStack/Swiftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  27. CVE-2026-71190High
    CVE Program Container
    CVSS 8.7
    OpenStack/Swiftgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  28. CVE-2026-18903Medium
    yeqifu warehouse FileController.java path traversal
    CVSS 4.3
    yeqifu/warehousegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-55707High
    CVE Program Container
    CVSS 7.1
    OpenStack/Neutrongeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-18902High
    H3C NX15 esps repeaterproc command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  31. CVE-2026-66839High
    CISA ADP Vulnrichment
    CVSS 8.4
    Integrated Systems Technologies, Inc./NetKids iMarkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  32. CVE-2026-66344Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    Integrated Systems Technologies, Inc./NetKids iMarkgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-9273Critical
    Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover
    CVSS 9.3
    stellarwp/Membership Plugin – Kadence Membershipsgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-11421Medium
    ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17.4 - Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter
    CVSS 6.5
    wedevs/ERP: Complete HR, Accounting & CRM Suite Built for WooCommercegeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-8790Medium
    Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Scripting
    CVSS 6.1
    antoineh/Football Poolgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-18322High
    Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator
    CVSS 8.8
    supsysticcom/Smart Popup by Supsysticgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  37. CVE-2026-15918High
    VikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection
    CVSS 7.5
    e4jvikwp/VikAppointments Services Booking Calendargeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  38. CVE-2026-8761High
    Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation
    CVSS 8.8
    dokaninc/Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsygeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-16143High
    VikRentItems Flexible Rental Management System <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting
    CVSS 7.2
    e4jvikwp/VikRentItems Flexible Rental Management Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18901High
    H3C NX15 Web API esps service.add routine
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  41. CVE-2026-18900High
    H3C NX15 Backend RPC esps file.exec os command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-18898High
    UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow
    CVSS 8.8
    UTT/HiPER 1200GWgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  43. CVE-2026-18897High
    UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow
    CVSS 8.8
    UTT/HiPER 1250GWgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  44. CVE-2026-18907High
    PathTravelsal Vulnerability in com.talpa.hibrowser
    CVSS 7.5
    TECNO Mobile/Hi Browsergeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-18896Medium
    lavkush-maurya Student-Registration-System changepass.php sql injection
    CVSS 6.3
    lavkush-maurya/Student-Registration-Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-18895High
    UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow
    CVSS 8.8
    UTT/HiPER 1250GWgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-18859High
    ESAFENET CDG usbkey;logindojojs sql injection
    CVSS 7.3
    ESAFENET/CDGgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-18856Medium
    Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery
    CVSS 4.7
    Poesis/Rhymix CMSgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-18854High
    Shandong Hoteam PDM Product Data Management System DataService GetStoredClassByFilter sql injection
    CVSS 7.3
    Shandong Hoteam/PDM Product Data Management Systemgeneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2025-63822High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
Page 23 of 326
Previous2122232425Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard