1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 6:40 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 6:40 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

8,418

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,151–1,200 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-63823Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2025-70962High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-52466Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-67863High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-67864High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-67865High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-67866High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-67867High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-67869High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-67870Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-67871High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-67872High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-67873Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-46334High
    OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning
    CVSS 8.7
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  15. CVE-2026-18853Medium
    ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
    CVSS 5.3
    ZomboDroid/Meme Generator Appgeneric
    PublishedAug 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-45809High
    OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI
    CVSS 8.7
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-45705Medium
    OpenSIPS: OOB Read in Multipart Body Boundary Parsing
    CVSS 5.3
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-18852Low
    epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition
    CVSS 3.3
    epsilla-cloud/vectordbgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  19. CVE-2026-18103Medium
    Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapi
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-45537Critical
    OpenSIPS: Global Buffer Overflow in construct_uri
    CVSS 9.1
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-18819Medium
    RackTables cross-site request forgery
    CVSS 4.3
    n/a/RackTablesgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-18818Medium
    Ehco1996 django-sspanel Support Ticket views.py TicketDetailView authorization
    CVSS 6.3
    Ehco1996/django-sspanelgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  23. CVE-2026-18817Low
    Baserow Inactive Non-Staff User serializers.py BaserowImpersonateAuthTokenSerializer improper authorization
    CVSS 2.2
    n/a/Baserowgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-45103High
    OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow
    CVSS 7.5
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  25. CVE-2026-70594Medium
    Ghost: Session Fixation in Ghost Admin
    CVSS 6.7
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-70593Medium
    Ghost: Theme Upload Path Traversal
    CVSS 6.6
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-18816Medium
    Baserow 2FA Verify Endpoint views.py verify improper authentication
    CVSS 5.0
    n/a/Baserowgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-45100Critical
    OpenSIPS: Buffer Overflow in Base64 Encode Transformation
    CVSS 9.1
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-70592Medium
    Ghost: Database Backup Path Traversal
    CVSS 5.5
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-70591Medium
    Ghost: Server-Side Request Forgery in Image Fetching
    CVSS 4.1
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-70590Medium
    Ghost: Blind Password Hash Disclosure in Ghost Admin API
    CVSS 4.8
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-45084High
    OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state
    CVSS 8.7
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-70619High
    Odysseus Missing Admin Authorization via Embedding Endpoint Routes
    CVSS 8.8
    odysseus-dev/odysseusgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-70620Medium
    Odysseus SSRF via Embedding Endpoint Configuration
    CVSS 6.8
    odysseus-dev/odysseusgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-18814High
    H3C NX15 esps reload.reload_config command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-70589Medium
    Ghost: Archived Offers can be Redeemed
    CVSS 4.8
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-70588Medium
    Ghost: Cross-Site Scripting in Universal Import
    CVSS 5.0
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-18813High
    H3C NX15 esps delete command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-70494High
    Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
    CVSS 8.1
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-70493Medium
    Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
    CVSS 6.5
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-13227High
    ERPNext v16.25.0 - Improper authorization in Prospect opportunities API
    CVSS 7.1
    Frappe/ERPNextgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-70492High
    Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
    CVSS 8.7
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-70491Medium
    Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
    CVSS 6.5
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-66902Critical
    Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
    CVSS 9.8
    CJCOLLIER/Google::Authgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-66901High
    Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
    CVSS 7.5
    CJCOLLIER/Google::Authgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-45538Critical
    OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy
    CVSS 9.8
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-70490Medium
    Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
    CVSS 6.3
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-70489Medium
    Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
    CVSS 6.5
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-54020Medium
    Open WebUI: DNS Rebinding SSRF Bypass
    CVSS 6.3
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-70488Medium
    Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
    CVSS 4.3
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 24 of 326
Previous2223242526Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,418

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,151–1,200 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2025-63823Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2025-70962High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-52466Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-67863High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-67864High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-67865High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-67866High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-67867High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-67869High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-67870Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-67871High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-67872High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-67873Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 5, 2026First seen at HOL Aug 5, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-46334High
    OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning
    CVSS 8.7
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  15. CVE-2026-18853Medium
    ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
    CVSS 5.3
    ZomboDroid/Meme Generator Appgeneric
    PublishedAug 4, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  16. CVE-2026-45809High
    OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI
    CVSS 8.7
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  17. CVE-2026-45705Medium
    OpenSIPS: OOB Read in Multipart Body Boundary Parsing
    CVSS 5.3
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  18. CVE-2026-18852Low
    epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition
    CVSS 3.3
    epsilla-cloud/vectordbgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  19. CVE-2026-18103Medium
    Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapi
    CVSS 4.9
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-45537Critical
    OpenSIPS: Global Buffer Overflow in construct_uri
    CVSS 9.1
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-18819Medium
    RackTables cross-site request forgery
    CVSS 4.3
    n/a/RackTablesgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-18818Medium
    Ehco1996 django-sspanel Support Ticket views.py TicketDetailView authorization
    CVSS 6.3
    Ehco1996/django-sspanelgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  23. CVE-2026-18817Low
    Baserow Inactive Non-Staff User serializers.py BaserowImpersonateAuthTokenSerializer improper authorization
    CVSS 2.2
    n/a/Baserowgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  24. CVE-2026-45103High
    OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow
    CVSS 7.5
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  25. CVE-2026-70594Medium
    Ghost: Session Fixation in Ghost Admin
    CVSS 6.7
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-70593Medium
    Ghost: Theme Upload Path Traversal
    CVSS 6.6
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-18816Medium
    Baserow 2FA Verify Endpoint views.py verify improper authentication
    CVSS 5.0
    n/a/Baserowgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  28. CVE-2026-45100Critical
    OpenSIPS: Buffer Overflow in Base64 Encode Transformation
    CVSS 9.1
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  29. CVE-2026-70592Medium
    Ghost: Database Backup Path Traversal
    CVSS 5.5
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-70591Medium
    Ghost: Server-Side Request Forgery in Image Fetching
    CVSS 4.1
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-70590Medium
    Ghost: Blind Password Hash Disclosure in Ghost Admin API
    CVSS 4.8
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-45084High
    OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state
    CVSS 8.7
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  33. CVE-2026-70619High
    Odysseus Missing Admin Authorization via Embedding Endpoint Routes
    CVSS 8.8
    odysseus-dev/odysseusgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-70620Medium
    Odysseus SSRF via Embedding Endpoint Configuration
    CVSS 6.8
    odysseus-dev/odysseusgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-18814High
    H3C NX15 esps reload.reload_config command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  36. CVE-2026-70589Medium
    Ghost: Archived Offers can be Redeemed
    CVSS 4.8
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-70588Medium
    Ghost: Cross-Site Scripting in Universal Import
    CVSS 5.0
    TryGhost/Ghost, ghostgeneric · npm
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-18813High
    H3C NX15 esps delete command injection
    CVSS 7.2
    H3C/NX15generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  39. CVE-2026-70494High
    Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
    CVSS 8.1
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-70493Medium
    Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
    CVSS 6.5
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-13227High
    ERPNext v16.25.0 - Improper authorization in Prospect opportunities API
    CVSS 7.1
    Frappe/ERPNextgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-70492High
    Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
    CVSS 8.7
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-70491Medium
    Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
    CVSS 6.5
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-66902Critical
    Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call
    CVSS 9.8
    CJCOLLIER/Google::Authgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-66901High
    Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
    CVSS 7.5
    CJCOLLIER/Google::Authgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-45538Critical
    OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy
    CVSS 9.8
    OpenSIPS/opensipsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-70490Medium
    Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
    CVSS 6.3
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-70489Medium
    Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
    CVSS 6.5
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-54020Medium
    Open WebUI: DNS Rebinding SSRF Bypass
    CVSS 6.3
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-70488Medium
    Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
    CVSS 4.3
    open-webui, open-webui/open-webuigeneric · pip
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 24 of 326
Previous2223242526Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard