HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Gemini CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Plugins
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Oct 1, 2026, 5:57 AM 42,123 active 1,506 known exploited

Catalog summary

42,123

Active CVEs

21,789

Critical + high

1,506

Known exploited

19

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 11,551–11,600 of 42,123 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-75018Medium
    Custom Contact Forms <= 7.16 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters
    CVSS 4.3
    outlawgt/Custom Contact Formsgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  2. CVE-2026-85414Medium
    Gallery : FooGallery <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute
    CVSS 6.4
    fooplugins/Gallery : FooGallerygeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  3. CVE-2026-75586Medium
    Unlimited Elements For Elementor <= 2.0.17 - Reflected Cross-Site Scripting via 'formData[id]' Parameter
    CVSS 6.1
    unitecms/Unlimited Elements For Elementorgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  4. CVE-2026-4361Medium
    Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter
    CVSS 5.0
    Elegant Themes/Divigeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  5. CVE-2026-3853Medium
    Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter
    CVSS 6.4
    Elegant Themes/Divigeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  6. CVE-2026-15984High
    QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters
    CVSS 7.2
    Themovation/QuickCalgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  7. CVE-2026-18406High
    SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload
    CVSS 7.2
    brainstormforce/SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quizgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  8. CVE-2026-19887High
    Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback
    CVSS 8.8
    uscnanbu/Welcart e-Commercegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  9. CVE-2026-78438High
    W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator
    CVSS 7.2
    boldgrid/W3 Total Cachegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  10. CVE-2026-14975Medium
    WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter
    CVSS 6.5
    JoomUnited/WP File Downloadgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  11. CVE-2026-19769High
    Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key
    CVSS 7.2
    kstover/Ninja Forms – The Contact Form Builder That Grows With Yougeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  12. CVE-2026-16649High
    Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field Value
    CVSS 7.2
    Gravity Forms/Gravity Formsgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  13. CVE-2026-77830High
    Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder
    CVSS 7.2
    cleantalk/Spam protection, Honeypot, Anti-Spam by CleanTalkgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  14. CVE-2026-18843Medium
    Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter
    CVSS 6.1
    The Beaver Builder Team/Beaver Builder Plugin (Starter Version)generic
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  15. CVE-2026-84937Medium
    YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax
    CVSS 6.8
    Unknown/Video Player for YouTubegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  16. CVE-2026-84936Medium
    EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat
    CVSS 5.3
    Unknown/EmbedPressgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  17. CVE-2026-84935High
    HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings
    CVSS 8.0
    Unknown/HT Menugeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  18. CVE-2026-84934High
    JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override
    CVSS 8.0
    Unknown/JCH Optimizegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-84931Medium
    Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute
    CVSS 6.8
    Unknown/Joli Table Of Contentsgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  20. CVE-2026-84930Medium
    CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute
    CVSS 6.8
    Unknown/CatFolders Document Gallery & PDF Librarygeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  21. CVE-2026-84927Low
    EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification
    CVSS 2.7
    Unknown/EmbedPressgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  22. CVE-2026-84926Low
    EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route
    CVSS 2.7
    Unknown/EmbedPressgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  23. CVE-2026-84901Medium
    Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization
    CVSS 4.9
    Unknown/Eventingeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  24. CVE-2026-84899Medium
    VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class_suffix
    CVSS 6.8
    Unknown/VikWidgetsLoadergeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  25. CVE-2026-84898Medium
    Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta
    CVSS 6.6
    Unknown/Eventingeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-84896Medium
    King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget
    CVSS 6.8
    Unknown/King Addons for Elementorgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  27. CVE-2026-84745Low
    The Events Calendar &lt; 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API
    CVSS 2.7
    Unknown/The Events Calendargeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  28. CVE-2026-84225Low
    Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR
    CVSS 2.2
    Unknown/Kirkigeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-84221Medium
    Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID
    CVSS 6.8
    Unknown/Kirkigeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-84022Medium
    Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attributes
    CVSS 6.8
    Unknown/Bold Page Buildergeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-84021Medium
    Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL
    CVSS 6.8
    Unknown/Bold Page Buildergeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-83544Medium
    Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute
    CVSS 6.8
    Unknown/Greenshiftgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-83543Medium
    Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint
    CVSS 4.1
    Unknown/Greenshiftgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  34. CVE-2026-82846Medium
    Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields
    CVSS 6.8
    Unknown/Masteriyo LMSgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-82304High
    Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler
    CVSS 8.6
    Unknown/Music Storegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-81424Medium
    Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR
    CVSS 5.3
    Unknown/Accept Stripe Paymentsgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  37. CVE-2026-81423Medium
    Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler
    CVSS 4.3
    Unknown/Accept Stripe Paymentsgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-81404High
    IPGP Visitors Origin < 1.6 - Reflected XSS
    CVSS 7.1
    Unknown/IPGP Visitors Origingeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  39. CVE-2026-81348Low
    My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap
    CVSS 3.7
    Unknown/My Private Sitegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-78362Critical
    SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication
    CVSS 9.8
    Unknown/SEO Flow by LupsOnlinegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  41. CVE-2026-78150Low
    Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR
    CVSS 2.7
    Unknown/Smart Postgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-78149Medium
    Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id
    CVSS 5.3
    Unknown/Smart Postgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  43. CVE-2026-77826High
    RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation
    CVSS 8.8
    Unknown/RegistrationMagicgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  44. CVE-2026-19861Medium
    JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails
    CVSS 4.7
    Unknown/JetFormBuilder — Dynamic Blocks Form Buildergeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-19858High
    JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset
    CVSS 7.5
    Unknown/JetFormBuilder — Dynamic Blocks Form Buildergeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  46. CVE-2026-15247Medium
    Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion
    CVSS 5.4
    Unknown/Search Atlas SEOgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  47. CVE-2025-15694Low
    Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS
    CVSS 3.5
    Unknown/Joli Table Of Contentsgeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  48. CVE-2025-15693Low
    JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal
    CVSS 2.7
    Unknown/JCH Optimizegeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026 Fix availableView HOL analysis
  49. CVE-2026-77263High
    iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content
    CVSS 7.2
    iubenda/iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + moregeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
  50. CVE-2026-18404Medium
    Social Chat <= 8.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box
    CVSS 6.4
    quadlayers/Social Chat – Click To Chat App Buttongeneric
    PublishedSep 5, 2026First seen at HOL Sep 5, 2026Updated Sep 8, 2026View HOL analysis
Page 232 of 843
Previous230231232233234Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard