1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:30 AM 16,232 active 1,443 known exploited

Catalog summary

16,232

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:30 AM 16,232 active 1,443 known exploited

Catalog summary

16,232

Active CVEs

8,389

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 101–150 of 16,232 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-70561Medium
    TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php
    CVSS 6.5
    TestLinkOpenSourceTRMS/TestLinkgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-66000Low
    Frappe: Unrestricted access to Document Follow APIs
    CVSS 2.3
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2025-58375High
    Frappe has potential SQL Injection due to missing validation
    CVSS 8.1
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2026-19230Low
    SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
    CVSS 3.5
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-44965Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-44964Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-47364Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-47363Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-47361Medium
    CISA ADP Vulnrichment
    CVSS 6.4
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-47362Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-64638High
    CISA ADP Vulnrichment
    CVSS 8.9
    Affected software not mappedEcosystem not listed
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-19229Medium
    SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
    CVSS 5.3
    SourceCodester/Online Clothing Storegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  13. CVE-2026-64637Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    WebPros/Pleskgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-64636High
    CISA ADP Vulnrichment
    CVSS 7.7
    WebPros/Pleskgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-19082High
    Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
    CVSS 7.5
    TONYC/Imagergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  16. CVE-2026-66058Medium
    Frappe: Unrestricted access to a Document Follow API
    CVSS 5.3
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-19213Medium
    WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
    CVSS 4.3
    n/a/WonderTradergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-56818Medium
    Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
    CVSS 6.5
    io.netty:netty-codec-redis, netty/nettygeneric · maven
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-66062Medium
    SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
    CVSS 5.3
    @sveltejs/kit, sveltejs/kitgeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-20348High
    ClamAV XAR File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-20345High
    ClamAV GPT File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-20339High
    ClamAV PESpin File Format Processing Integer Overflow Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-20347High
    ClamAV Mach-O File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-67585High
    Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
    CVSS 8.7
    DivvyPayHQ/absinthe_federationgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-20346High
    ClamAV PDF File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-20338High
    ClamAV ZIP File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  27. CVE-2026-20337High
    ClamAV ZIP File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-71557Medium
    go-git: Malicious reference names may modify files outside the reference storage
    CVSS 6.3
    github.com/go-git/go-git/v5, github.com/go-git/go-git/v6 +1generic · go
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2026-71556High
    go-git: Worktree operations may follow symlinks
    CVSS 7.1
    github.com/go-git/go-git/v5, github.com/go-git/go-git/v6 +1generic · go
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19212Medium
    WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
    CVSS 4.3
    n/a/WonderTradergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026View HOL analysis
  31. CVE-2026-68772High
    ZenML 0.94.6 Remote Code Execution via CloudpickleMaterializer
    CVSS 8.0
    ZenML/ZenMLgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026View HOL analysis
  32. CVE-2026-19211High
    SourceCodester Photo Share Website ajax.php signup sql injection
    CVSS 7.3
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  33. CVE-2026-14644High
    Nexus Repository 3 - Privilege Escalation
    CVSS 8.6
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  34. CVE-2026-17593High
    Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration
    CVSS 7.2
    Sonatype/Nexus Repositorygeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-17594High
    Nexus Repository 3 - Authorization Bypass in Repository Creation
    CVSS 8.2
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  36. CVE-2026-17595Medium
    Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass
    CVSS 5.3
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  37. CVE-2026-17596Medium
    Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name
    CVSS 6.3
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-17598Medium
    Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration
    CVSS 5.3
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-17599Medium
    Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
    CVSS 6.9
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-17600High
    Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation
    CVSS 8.7
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-17601High
    Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator
    CVSS 8.9
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-17603High
    Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API
    CVSS 8.7
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-17597Medium
    Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification
    CVSS 5.1
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-19210Medium
    SourceCodester Photo Share Website ajax.php save_upload unrestricted upload
    CVSS 6.3
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  45. CVE-2026-48093Medium
    Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embed
    CVSS 6.5
    dartiss/code-embedgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  46. CVE-2026-19209Low
    SourceCodester Photo Share Website index.php home cross site scripting
    CVSS 3.5
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  47. CVE-2026-66059Medium
    Frappe: Field-level permission bypass via Document Follow
    CVSS 5.3
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026View HOL analysis
  48. CVE-2026-62996Medium
    Smarty Security stream restriction bypass through stream: resource
    CVSS 6.9
    smarty-php/smarty, smarty/smartycomposer · generic · packagist
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-62992Medium
    Smarty: Symlink path traversal out of trusted directories
    CVSS 6.9
    smarty-php/smarty, smarty/smartycomposer · generic · packagist
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-19208Low
    WonderTrader TraderDD.cpp queryTrades behavioral workflow
    CVSS 3.7
    n/a/WonderTradergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
Page 3 of 325
Previous12345Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,389

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 101–150 of 16,232 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-70561Medium
    TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php
    CVSS 6.5
    TestLinkOpenSourceTRMS/TestLinkgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-66000Low
    Frappe: Unrestricted access to Document Follow APIs
    CVSS 2.3
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  3. CVE-2025-58375High
    Frappe has potential SQL Injection due to missing validation
    CVSS 8.1
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2026-19230Low
    SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
    CVSS 3.5
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-44965Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-44964Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-47364Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-47363Medium
    CISA ADP Vulnrichment
    CVSS 6.3
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-47361Medium
    CISA ADP Vulnrichment
    CVSS 6.4
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-47362Medium
    CISA ADP Vulnrichment
    CVSS 4.6
    Datadog/Android Appgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  11. CVE-2026-64638High
    CISA ADP Vulnrichment
    CVSS 8.9
    Affected software not mappedEcosystem not listed
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-19229Medium
    SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
    CVSS 5.3
    SourceCodester/Online Clothing Storegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  13. CVE-2026-64637Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    WebPros/Pleskgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-64636High
    CISA ADP Vulnrichment
    CVSS 7.7
    WebPros/Pleskgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-19082High
    Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags
    CVSS 7.5
    TONYC/Imagergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  16. CVE-2026-66058Medium
    Frappe: Unrestricted access to a Document Follow API
    CVSS 5.3
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-19213Medium
    WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
    CVSS 4.3
    n/a/WonderTradergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-56818Medium
    Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
    CVSS 6.5
    io.netty:netty-codec-redis, netty/nettygeneric · maven
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  19. CVE-2026-66062Medium
    SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
    CVSS 5.3
    @sveltejs/kit, sveltejs/kitgeneric · npm
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-20348High
    ClamAV XAR File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-20345High
    ClamAV GPT File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-20339High
    ClamAV PESpin File Format Processing Integer Overflow Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-20347High
    ClamAV Mach-O File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-67585High
    Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
    CVSS 8.7
    DivvyPayHQ/absinthe_federationgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-20346High
    ClamAV PDF File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-20338High
    ClamAV ZIP File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  27. CVE-2026-20337High
    ClamAV ZIP File Format Processing Memory Corruption Vulnerability
    CVSS 7.5
    Cisco/Cisco Secure Endpointgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-71557Medium
    go-git: Malicious reference names may modify files outside the reference storage
    CVSS 6.3
    github.com/go-git/go-git/v5, github.com/go-git/go-git/v6 +1generic · go
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2026-71556High
    go-git: Worktree operations may follow symlinks
    CVSS 7.1
    github.com/go-git/go-git/v5, github.com/go-git/go-git/v6 +1generic · go
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19212Medium
    WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
    CVSS 4.3
    n/a/WonderTradergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026View HOL analysis
  31. CVE-2026-68772High
    ZenML 0.94.6 Remote Code Execution via CloudpickleMaterializer
    CVSS 8.0
    ZenML/ZenMLgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026View HOL analysis
  32. CVE-2026-19211High
    SourceCodester Photo Share Website ajax.php signup sql injection
    CVSS 7.3
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  33. CVE-2026-14644High
    Nexus Repository 3 - Privilege Escalation
    CVSS 8.6
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  34. CVE-2026-17593High
    Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration
    CVSS 7.2
    Sonatype/Nexus Repositorygeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-17594High
    Nexus Repository 3 - Authorization Bypass in Repository Creation
    CVSS 8.2
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  36. CVE-2026-17595Medium
    Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass
    CVSS 5.3
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  37. CVE-2026-17596Medium
    Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name
    CVSS 6.3
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-17598Medium
    Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration
    CVSS 5.3
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-17599Medium
    Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
    CVSS 6.9
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-17600High
    Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation
    CVSS 8.7
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-17601High
    Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator
    CVSS 8.9
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-17603High
    Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API
    CVSS 8.7
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-17597Medium
    Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification
    CVSS 5.1
    Sonatype/Nexus Repository 3generic
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-19210Medium
    SourceCodester Photo Share Website ajax.php save_upload unrestricted upload
    CVSS 6.3
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  45. CVE-2026-48093Medium
    Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embed
    CVSS 6.5
    dartiss/code-embedgeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  46. CVE-2026-19209Low
    SourceCodester Photo Share Website index.php home cross site scripting
    CVSS 3.5
    SourceCodester/Photo Share Websitegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
  47. CVE-2026-66059Medium
    Frappe: Field-level permission bypass via Document Follow
    CVSS 5.3
    frappe/frappegeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 8, 2026View HOL analysis
  48. CVE-2026-62996Medium
    Smarty Security stream restriction bypass through stream: resource
    CVSS 6.9
    smarty-php/smarty, smarty/smartycomposer · generic · packagist
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-62992Medium
    Smarty: Symlink path traversal out of trusted directories
    CVSS 6.9
    smarty-php/smarty, smarty/smartycomposer · generic · packagist
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-19208Low
    WonderTrader TraderDD.cpp queryTrades behavioral workflow
    CVSS 3.7
    n/a/WonderTradergeneric
    PublishedAug 7, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026View HOL analysis
Page 3 of 325
Previous12345Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard