1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 8:45 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 8:45 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

8,421

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,351–1,400 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64564Critical
    sctp: don't free the ASCONF's own transport in DEL-IP processing
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  2. CVE-2026-64563High
    rhashtable: clear stale iter->p on table restart
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  3. CVE-2026-64562High
    KVM: nVMX: Hide shadow VMCS right after VMCLEAR
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  4. CVE-2026-64561High
    KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  5. CVE-2026-16548Medium
    Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
    CVSS 5.4
    Unknown/Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chatgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  6. CVE-2026-16547Medium
    REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
    CVSS 5.9
    Unknown/REST API Loggeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  7. CVE-2026-16546Medium
    Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
    CVSS 4.3
    Unknown/Wired Impact Volunteer Managementgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  8. CVE-2026-16296Medium
    Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler
    CVSS 4.7
    Unknown/Clearfy Cachegeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  9. CVE-2026-16295Medium
    Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher
    CVSS 4.3
    Unknown/Clearfy Cachegeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  10. CVE-2026-16293Medium
    Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL
    CVSS 6.8
    Unknown/PowerPress Podcasting plugin by Blubrrygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  11. CVE-2026-16070Low
    Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
    CVSS 2.7
    Unknown/Brizygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  12. CVE-2026-16069Medium
    Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
    CVSS 6.8
    Unknown/Brizygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  13. CVE-2026-16068Low
    Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
    CVSS 3.5
    Unknown/Brizygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  14. CVE-2026-16056Medium
    Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts
    CVSS 4.3
    Unknown/Contest Gallerygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  15. CVE-2026-16035Medium
    miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
    CVSS 4.3
    Unknown/miniOrange 2FAgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  16. CVE-2026-15958Critical
    Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
    CVSS 9.3
    Unknown/Easy Integration for Dropboxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  17. CVE-2026-15233Medium
    Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
    CVSS 4.8
    Unknown/Nested Pagesgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  18. CVE-2026-14939Medium
    Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import
    CVSS 6.8
    Unknown/Visualizergeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  19. CVE-2026-14872Medium
    Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter
    CVSS 6.8
    Unknown/Database for Contact Form 7, WPforms, Elementor formsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  20. CVE-2026-14848Medium
    Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout
    CVSS 5.4
    Unknown/Paid Membership Subscriptionsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  21. CVE-2026-14824Medium
    Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question
    CVSS 4.8
    Unknown/Quiz and Survey Master (QSM)generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  22. CVE-2026-14816Medium
    The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam
    CVSS 6.5
    Unknown/The GDPR Framework By Data443generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  23. CVE-2026-12698Medium
    wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment
    CVSS 4.3
    Unknown/wpForo Forumgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  24. CVE-2026-11366Low
    MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
    CVSS 3.7
    Unknown/MonsterInsightsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  25. CVE-2026-10526Medium
    EmbedPress < 4.6.1 - Unauthenticated Blind SSRF
    CVSS 5.8
    Unknown/EmbedPressgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  26. CVE-2026-16536Medium
    Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id
    CVSS 5.3
    Unknown/Simple Google Calendar Outlook Events Widgetgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  27. CVE-2026-16623High
    Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)
    CVSS 8.0
    Unknown/Create Block Themegeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  28. CVE-2026-16618Critical
    ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution
    CVSS 9.8
    Unknown/Improve SEOgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  29. CVE-2026-18739Low
    Popt-devel: popt-static: off-by-one in poptstuffargs
    CVSS 2.5
    rpm-software-management/poptgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-18569Low
    Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-16881High
    CISA ADP Vulnrichment
    CVSS 8.7
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  32. CVE-2026-42169High
    Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c)
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-18723Medium
    diaowen DWSurvey Survey Status up-survey-status.do improper authorization
    CVSS 6.3
    diaowen/DWSurveygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  34. CVE-2026-18722Medium
    diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization
    CVSS 6.3
    diaowen/DWSurveygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  35. CVE-2026-18721Medium
    kalcaddle kodbox SSO API Login apiLogin redirect
    CVSS 4.3
    kalcaddle/kodboxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  36. CVE-2026-14818High
    CISA ADP Vulnrichment
    CVSS 7.2
    Zyxel/ATP series firmware, Zyxel/USG FLEX 50(W) series firmware +2generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  37. CVE-2026-17614Medium
    Wildfly-core: path traversal on wildfly domain controller
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-8508Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Zyxel/WAX650S firmwaregeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  39. CVE-2026-6837High
    CISA ADP Vulnrichment
    CVSS 7.2
    Zyxel/WAX650S firmwaregeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18720Medium
    kalcaddle kodbox msgWarning Plugin action improper authorization
    CVSS 5.3
    kalcaddle/kodboxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  41. CVE-2026-18719Medium
    cemtan sar2html Search sar2html.py sql injection
    CVSS 6.3
    cemtan/sar2htmlgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-11835Medium
    Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Address (TOCTOU)
    CVSS 5.6
    Caliptra/Core ROMgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  43. CVE-2026-11836Low
    Production Debug-Unlock Token Verification Missing Device Binding
    CVSS 1.8
    Caliptra/Core Firmware, Caliptra/Core ROMgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  44. CVE-2026-18686Critical
    GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
    CVSS 9.8
    GL.iNet/GL-MT3000generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  45. CVE-2025-29296Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-51144Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-51400High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-51401High
    CISA ADP Vulnrichment
    CVSS 7.7
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-52370Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2026-67855High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
Page 28 of 326
Previous2627282930Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,421

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,351–1,400 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64564Critical
    sctp: don't free the ASCONF's own transport in DEL-IP processing
    CVSS 9.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  2. CVE-2026-64563High
    rhashtable: clear stale iter->p on table restart
    CVSS 7.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  3. CVE-2026-64562High
    KVM: nVMX: Hide shadow VMCS right after VMCLEAR
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  4. CVE-2026-64561High
    KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  5. CVE-2026-16548Medium
    Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
    CVSS 5.4
    Unknown/Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chatgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  6. CVE-2026-16547Medium
    REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
    CVSS 5.9
    Unknown/REST API Loggeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  7. CVE-2026-16546Medium
    Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
    CVSS 4.3
    Unknown/Wired Impact Volunteer Managementgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  8. CVE-2026-16296Medium
    Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler
    CVSS 4.7
    Unknown/Clearfy Cachegeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  9. CVE-2026-16295Medium
    Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher
    CVSS 4.3
    Unknown/Clearfy Cachegeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  10. CVE-2026-16293Medium
    Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL
    CVSS 6.8
    Unknown/PowerPress Podcasting plugin by Blubrrygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  11. CVE-2026-16070Low
    Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
    CVSS 2.7
    Unknown/Brizygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  12. CVE-2026-16069Medium
    Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
    CVSS 6.8
    Unknown/Brizygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  13. CVE-2026-16068Low
    Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
    CVSS 3.5
    Unknown/Brizygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  14. CVE-2026-16056Medium
    Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts
    CVSS 4.3
    Unknown/Contest Gallerygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  15. CVE-2026-16035Medium
    miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
    CVSS 4.3
    Unknown/miniOrange 2FAgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  16. CVE-2026-15958Critical
    Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
    CVSS 9.3
    Unknown/Easy Integration for Dropboxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  17. CVE-2026-15233Medium
    Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
    CVSS 4.8
    Unknown/Nested Pagesgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  18. CVE-2026-14939Medium
    Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import
    CVSS 6.8
    Unknown/Visualizergeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  19. CVE-2026-14872Medium
    Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter
    CVSS 6.8
    Unknown/Database for Contact Form 7, WPforms, Elementor formsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  20. CVE-2026-14848Medium
    Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout
    CVSS 5.4
    Unknown/Paid Membership Subscriptionsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  21. CVE-2026-14824Medium
    Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question
    CVSS 4.8
    Unknown/Quiz and Survey Master (QSM)generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  22. CVE-2026-14816Medium
    The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam
    CVSS 6.5
    Unknown/The GDPR Framework By Data443generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  23. CVE-2026-12698Medium
    wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment
    CVSS 4.3
    Unknown/wpForo Forumgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  24. CVE-2026-11366Low
    MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
    CVSS 3.7
    Unknown/MonsterInsightsgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  25. CVE-2026-10526Medium
    EmbedPress < 4.6.1 - Unauthenticated Blind SSRF
    CVSS 5.8
    Unknown/EmbedPressgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  26. CVE-2026-16536Medium
    Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id
    CVSS 5.3
    Unknown/Simple Google Calendar Outlook Events Widgetgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  27. CVE-2026-16623High
    Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)
    CVSS 8.0
    Unknown/Create Block Themegeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  28. CVE-2026-16618Critical
    ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution
    CVSS 9.8
    Unknown/Improve SEOgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  29. CVE-2026-18739Low
    Popt-devel: popt-static: off-by-one in poptstuffargs
    CVSS 2.5
    rpm-software-management/poptgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  30. CVE-2026-18569Low
    Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-16881High
    CISA ADP Vulnrichment
    CVSS 8.7
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  32. CVE-2026-42169High
    Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c)
    CVSS 7.3
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-18723Medium
    diaowen DWSurvey Survey Status up-survey-status.do improper authorization
    CVSS 6.3
    diaowen/DWSurveygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  34. CVE-2026-18722Medium
    diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization
    CVSS 6.3
    diaowen/DWSurveygeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  35. CVE-2026-18721Medium
    kalcaddle kodbox SSO API Login apiLogin redirect
    CVSS 4.3
    kalcaddle/kodboxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  36. CVE-2026-14818High
    CISA ADP Vulnrichment
    CVSS 7.2
    Zyxel/ATP series firmware, Zyxel/USG FLEX 50(W) series firmware +2generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  37. CVE-2026-17614Medium
    Wildfly-core: path traversal on wildfly domain controller
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-8508Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Zyxel/WAX650S firmwaregeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  39. CVE-2026-6837High
    CISA ADP Vulnrichment
    CVSS 7.2
    Zyxel/WAX650S firmwaregeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18720Medium
    kalcaddle kodbox msgWarning Plugin action improper authorization
    CVSS 5.3
    kalcaddle/kodboxgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  41. CVE-2026-18719Medium
    cemtan sar2html Search sar2html.py sql injection
    CVSS 6.3
    cemtan/sar2htmlgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  42. CVE-2026-11835Medium
    Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Address (TOCTOU)
    CVSS 5.6
    Caliptra/Core ROMgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  43. CVE-2026-11836Low
    Production Debug-Unlock Token Verification Missing Device Binding
    CVSS 1.8
    Caliptra/Core Firmware, Caliptra/Core ROMgeneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  44. CVE-2026-18686Critical
    GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
    CVSS 9.8
    GL.iNet/GL-MT3000generic
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  45. CVE-2025-29296Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-51144Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  47. CVE-2026-51400High
    CISA ADP Vulnrichment
    CVSS 8.4
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  48. CVE-2026-51401High
    CISA ADP Vulnrichment
    CVSS 7.7
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  49. CVE-2026-52370Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
  50. CVE-2026-67855High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 4, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026View HOL analysis
Page 28 of 326
Previous2627282930Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard