1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:45 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 9:45 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

8,421

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,501–1,550 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-21551High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  2. CVE-2026-21550High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  3. CVE-2026-21549High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  4. CVE-2026-21548High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  5. CVE-2026-18591Low
    Meesho Online Shopping App com.meesho.supply cleartext storage
    CVSS 2.1
    Meesho/Online Shopping Appgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  6. CVE-2026-28147Medium
    WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability
    CVSS 5.4
    Unlimited Elements/Unlimited Elements For Elementor (Free Widgets, Addons, Templates)generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  7. CVE-2026-12259Unknown severity
    Improper Input Validation in nltk/nltk
    Not scoredSource severity not reported
    nltk/nltk/nltkgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  8. CVE-2026-18590Medium
    Wavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injection
    CVSS 6.3
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-18589Critical
    Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow
    CVSS 9.8
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  10. CVE-2026-4793High
    CISA ADP Vulnrichment
    CVSS 7.3
    Synology/Synology Assistantgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  11. CVE-2026-16572High
    LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie
    CVSS 8.6
    Unknown/LogMyTripgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  12. CVE-2026-16565Medium
    Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
    CVSS 4.3
    Unknown/Dokan: AI Powered WooCommerce Multivendor Marketplace Solutiongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  13. CVE-2026-16564Medium
    Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
    CVSS 4.3
    Unknown/Dokan: AI Powered WooCommerce Multivendor Marketplace Solutiongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  14. CVE-2026-16563Medium
    Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
    CVSS 6.5
    Unknown/Academy LMSgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  15. CVE-2026-16539High
    SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
    CVSS 8.1
    Unknown/sm page duplicatorgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  16. CVE-2026-16300Critical
    Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset
    CVSS 9.8
    Unknown/ChamaWPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  17. CVE-2026-16297Medium
    Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import
    CVSS 4.1
    Unknown/Clearfy Cachegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  18. CVE-2026-16289Medium
    ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
    CVSS 4.3
    Unknown/ProfileGridgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  19. CVE-2026-16250Critical
    Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    Unknown/Personal QR Messagegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  20. CVE-2026-16060Critical
    Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload
    CVSS 9.8
    Unknown/Insert or Embed Articulate Content into WordPressgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  21. CVE-2026-15931Medium
    Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name
    CVSS 6.1
    Unknown/Simple Membershipgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  22. CVE-2026-15930Critical
    Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision
    CVSS 9.4
    Unknown/Simple Membershipgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  23. CVE-2026-15383Medium
    Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
    CVSS 6.1
    Unknown/Blog Floating Buttongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  24. CVE-2026-15260Medium
    Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
    CVSS 4.3
    Unknown/GEO my WPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  25. CVE-2026-15231Low
    TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
    CVSS 2.7
    Unknown/Tag, Category, and Taxonomy Managergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  26. CVE-2026-14557Critical
    SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
    CVSS 9.1
    Unknown/SoftMarket — Digital Marketplacegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  27. CVE-2026-13340Medium
    SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
    CVSS 6.1
    Unknown/SVG Supportgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  28. CVE-2026-12965Critical
    Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking
    CVSS 9.1
    Unknown/Super Store Finder WordPressgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-12872Critical
    Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    Unknown/Webinfosgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  30. CVE-2025-15673Medium
    Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
    CVSS 4.9
    Unknown/Import and export users and customersgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  31. CVE-2025-15672High
    Chama < 1.0.13 - Unauthenticated PHP Object Injection
    CVSS 8.1
    Unknown/ChamaWPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  32. CVE-2026-18588Critical
    Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow
    CVSS 9.8
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  33. CVE-2026-16534Critical
    Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
    CVSS 9.1
    Unknown/Import and export users and customersgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  34. CVE-2026-16532Critical
    Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form
    CVSS 9.1
    Unknown/Link Librarygeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  35. CVE-2026-16276Low
    Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search
    CVSS 2.7
    Unknown/Classified Listinggeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  36. CVE-2026-16274Low
    Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
    CVSS 2.7
    Unknown/Classified Listinggeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  37. CVE-2026-16057Medium
    Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
    CVSS 6.5
    Unknown/Contest Gallerygeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  38. CVE-2026-15254Medium
    Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode
    CVSS 6.5
    Unknown/Simply Schedule Appointmentsgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  39. CVE-2026-18587High
    Wavlink WL-NU516U1 Config Import os command injection
    CVSS 7.5
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  40. CVE-2026-18585Medium
    GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow
    CVSS 4.3
    GL.iNet/BE3600, GL.iNet/BE6500 +9generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-18584Medium
    GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization
    CVSS 5.4
    GL.iNet/E5800, GL.iNet/E750 +4generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  42. CVE-2026-18583Medium
    mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-bounds
    CVSS 5.3
    mz-automation/libiec61850generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  43. CVE-2026-13586Medium
    PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
    CVSS 5.3
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  44. CVE-2026-13506High
    Lazy ASN.1 sequence forcing resets nesting-depth guard
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  45. CVE-2026-12860High
    RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVA, Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  46. CVE-2026-12852High
    MLS wire decoder allocates attacker-declared opaque length before bounds check
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  47. CVE-2026-12817High
    OpenPGP AEAD decryption skips final tag on chunk-aligned data
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  48. CVE-2026-12816High
    IESEngine stream-mode MAC forgery via length-dependent KDF split
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVA, Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  49. CVE-2026-12803High
    KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVA, Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  50. CVE-2026-12802High
    CMS AuthEnvelopedData fails to enforce tag-length on decryption
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
Page 31 of 326
Previous2930313233Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,421

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,501–1,550 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-21551High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  2. CVE-2026-21550High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  3. CVE-2026-21549High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  4. CVE-2026-21548High
    CISA ADP Vulnrichment
    CVSS 7.5
    Unisoc (Shanghai) Technologies Co., Ltd./T8100/T9100/T8200/T8300generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  5. CVE-2026-18591Low
    Meesho Online Shopping App com.meesho.supply cleartext storage
    CVSS 2.1
    Meesho/Online Shopping Appgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  6. CVE-2026-28147Medium
    WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability
    CVSS 5.4
    Unlimited Elements/Unlimited Elements For Elementor (Free Widgets, Addons, Templates)generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  7. CVE-2026-12259Unknown severity
    Improper Input Validation in nltk/nltk
    Not scoredSource severity not reported
    nltk/nltk/nltkgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  8. CVE-2026-18590Medium
    Wavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injection
    CVSS 6.3
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-18589Critical
    Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow
    CVSS 9.8
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  10. CVE-2026-4793High
    CISA ADP Vulnrichment
    CVSS 7.3
    Synology/Synology Assistantgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  11. CVE-2026-16572High
    LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie
    CVSS 8.6
    Unknown/LogMyTripgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  12. CVE-2026-16565Medium
    Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
    CVSS 4.3
    Unknown/Dokan: AI Powered WooCommerce Multivendor Marketplace Solutiongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  13. CVE-2026-16564Medium
    Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
    CVSS 4.3
    Unknown/Dokan: AI Powered WooCommerce Multivendor Marketplace Solutiongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  14. CVE-2026-16563Medium
    Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
    CVSS 6.5
    Unknown/Academy LMSgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  15. CVE-2026-16539High
    SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
    CVSS 8.1
    Unknown/sm page duplicatorgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  16. CVE-2026-16300Critical
    Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset
    CVSS 9.8
    Unknown/ChamaWPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  17. CVE-2026-16297Medium
    Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import
    CVSS 4.1
    Unknown/Clearfy Cachegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  18. CVE-2026-16289Medium
    ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
    CVSS 4.3
    Unknown/ProfileGridgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  19. CVE-2026-16250Critical
    Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    Unknown/Personal QR Messagegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  20. CVE-2026-16060Critical
    Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload
    CVSS 9.8
    Unknown/Insert or Embed Articulate Content into WordPressgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  21. CVE-2026-15931Medium
    Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name
    CVSS 6.1
    Unknown/Simple Membershipgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  22. CVE-2026-15930Critical
    Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision
    CVSS 9.4
    Unknown/Simple Membershipgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  23. CVE-2026-15383Medium
    Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
    CVSS 6.1
    Unknown/Blog Floating Buttongeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  24. CVE-2026-15260Medium
    Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
    CVSS 4.3
    Unknown/GEO my WPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  25. CVE-2026-15231Low
    TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
    CVSS 2.7
    Unknown/Tag, Category, and Taxonomy Managergeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  26. CVE-2026-14557Critical
    SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
    CVSS 9.1
    Unknown/SoftMarket — Digital Marketplacegeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026View HOL analysis
  27. CVE-2026-13340Medium
    SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
    CVSS 6.1
    Unknown/SVG Supportgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  28. CVE-2026-12965Critical
    Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking
    CVSS 9.1
    Unknown/Super Store Finder WordPressgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-12872Critical
    Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    Unknown/Webinfosgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  30. CVE-2025-15673Medium
    Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
    CVSS 4.9
    Unknown/Import and export users and customersgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  31. CVE-2025-15672High
    Chama < 1.0.13 - Unauthenticated PHP Object Injection
    CVSS 8.1
    Unknown/ChamaWPgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  32. CVE-2026-18588Critical
    Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow
    CVSS 9.8
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  33. CVE-2026-16534Critical
    Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
    CVSS 9.1
    Unknown/Import and export users and customersgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  34. CVE-2026-16532Critical
    Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form
    CVSS 9.1
    Unknown/Link Librarygeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  35. CVE-2026-16276Low
    Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search
    CVSS 2.7
    Unknown/Classified Listinggeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  36. CVE-2026-16274Low
    Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
    CVSS 2.7
    Unknown/Classified Listinggeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  37. CVE-2026-16057Medium
    Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
    CVSS 6.5
    Unknown/Contest Gallerygeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  38. CVE-2026-15254Medium
    Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode
    CVSS 6.5
    Unknown/Simply Schedule Appointmentsgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  39. CVE-2026-18587High
    Wavlink WL-NU516U1 Config Import os command injection
    CVSS 7.5
    Wavlink/WL-NU516U1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  40. CVE-2026-18585Medium
    GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow
    CVSS 4.3
    GL.iNet/BE3600, GL.iNet/BE6500 +9generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-18584Medium
    GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization
    CVSS 5.4
    GL.iNet/E5800, GL.iNet/E750 +4generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  42. CVE-2026-18583Medium
    mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-bounds
    CVSS 5.3
    mz-automation/libiec61850generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  43. CVE-2026-13586Medium
    PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
    CVSS 5.3
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  44. CVE-2026-13506High
    Lazy ASN.1 sequence forcing resets nesting-depth guard
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  45. CVE-2026-12860High
    RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVA, Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  46. CVE-2026-12852High
    MLS wire decoder allocates attacker-declared opaque length before bounds check
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  47. CVE-2026-12817High
    OpenPGP AEAD decryption skips final tag on chunk-aligned data
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  48. CVE-2026-12816High
    IESEngine stream-mode MAC forgery via length-dependent KDF split
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVA, Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  49. CVE-2026-12803High
    KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-JAVA, Legion of the Bouncy Castle Inc./BC-LTS-JAVAgeneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  50. CVE-2026-12802High
    CMS AuthEnvelopedData fails to enforce tag-length on decryption
    CVSS 8.7
    Legion of the Bouncy Castle Inc./BC-FJA, Legion of the Bouncy Castle Inc./BC-JAVA +1generic
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
Page 31 of 326
Previous2930313233Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard