1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 10:43 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 10:43 PM 16,269 active 1,443 known exploited

Catalog summary

16,269

Active CVEs

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,601–1,650 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-67972High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-67973High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-67974High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-67975High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-67976High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  6. CVE-2026-67977High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  7. CVE-2026-67978High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  8. CVE-2026-3245High
    CISA ADP Vulnrichment
    CVSS 7.5
    Canon Production Printing/PRISMAproductiongeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-18577High
    Incomplete patch leads to administrative account takeover
    CVSS 8.2 Known exploited
    N-able/N-centralgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-10848High
    Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)
    CVSS 7.0
    zephyrproject/zephyrgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  11. CVE-2026-65321Critical
    PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
    CVSS 9.8
    laughingman7743/PyAthenageneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-10774Low
    PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS
    CVSS 2.4
    zephyrproject/zephyrgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  13. CVE-2026-68580High
    FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-71401Medium
    better-auth before 1.4.2 basePath Modification DoS
    CVSS 5.9
    better-auth/better-authgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  15. CVE-2025-71400High
    better-auth passkey before 1.4.0 IDOR via delete-passkey
    CVSS 7.1
    better-auth/passkeygeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  16. CVE-2025-71399High
    Better Auth before 1.4.5 Path Normalization Bypass via rou3
    CVSS 8.6
    better-auth/better-authgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  17. CVE-2026-12231Medium
    Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image'
    CVSS 6.4
    timstrifler/Exclusive Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  18. CVE-2026-15236High
    Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure
    CVSS 7.5
    Unknown/Gallery for Google Photosgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  19. CVE-2026-13389Medium
    WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
    CVSS 6.5
    Unknown/webtoffee-cookie-consentgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  20. CVE-2025-15675Medium
    Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
    CVSS 4.8
    Unknown/Charitablegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-16540High
    Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
    CVSS 7.5
    Unknown/Simply Schedule Appointmentsgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  22. CVE-2026-16064Medium
    Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
    CVSS 5.4
    Unknown/Event Booking Manager for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  23. CVE-2026-16063Medium
    Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content
    CVSS 5.4
    Unknown/Event Booking Manager for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  24. CVE-2026-16062Medium
    Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content
    CVSS 6.6
    Unknown/Event Booking Manager for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  25. CVE-2026-16292Medium
    Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF
    CVSS 5.4
    Unknown/Frontend File Manager Plugingeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  26. CVE-2026-16291Medium
    ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
    CVSS 4.3
    Unknown/ProfileGridgeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  27. CVE-2026-16285High
    WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
    CVSS 7.5
    Unknown/Product Attachment for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  28. CVE-2026-16273Medium
    Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
    CVSS 4.6
    Unknown/Narrative Publishergeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-16261High
    Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover
    CVSS 7.5
    Unknown/login-socialgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  30. CVE-2026-16042Medium
    LWS Optimize < 3.4 - Subscriber+ Cache Deletion
    CVSS 4.3
    Unknown/LWS Optimizegeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  31. CVE-2026-14817Medium
    Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes
    CVSS 6.8
    Unknown/Element Pack Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  32. CVE-2026-12586High
    Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
    CVSS 8.1
    Unknown/Lenxel WPgeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  33. CVE-2026-11872Medium
    Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item
    CVSS 4.3
    Unknown/Clever Mega Menu for Visual Composergeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-16256Critical
    Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation
    CVSS 9.8
    Unknown/POUCO Import Usersgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-15939Low
    Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API
    CVSS 2.7
    Unknown/Simple Restrictgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-15385Medium
    RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS
    CVSS 5.4
    Unknown/RT Mega Menugeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  37. CVE-2026-15248Medium
    Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
    CVSS 5.5
    Unknown/Meta Boxgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-15241High
    ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
    CVSS 7.5
    Unknown/AI ChatBot for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  39. CVE-2026-15206High
    SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile
    CVSS 7.5
    Unknown/SMS Alertgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  40. CVE-2026-15151High
    Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications
    CVSS 7.5
    Unknown/Five Star Restaurant Reservationsgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  41. CVE-2026-14938Medium
    FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR
    CVSS 4.3
    Unknown/FluentBoardsgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-14920High
    AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter
    CVSS 8.2
    Unknown/AcyMailinggeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  43. CVE-2026-14864Medium
    JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
    CVSS 5.4
    Unknown/JetEnginegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  44. CVE-2026-14841Medium
    King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
    CVSS 6.1
    Unknown/King Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  45. CVE-2026-18573Medium
    Keycloak-services: keycloak-services: client access-type policy condition bypass during client update
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  46. CVE-2026-18572Medium
    Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  47. CVE-2026-18571Medium
    Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  48. CVE-2026-18570Medium
    Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  49. CVE-2026-13339High
    CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter
    CVSS 7.5
    cubewp1211/CubeWP Frameworkgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  50. CVE-2026-18352High
    User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
    CVSS 7.5
    gm_alex/User Access Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
Page 33 of 326
Previous3132333435Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,601–1,650 of 16,269 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-67972High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-67973High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  3. CVE-2026-67974High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-67975High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  5. CVE-2026-67976High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  6. CVE-2026-67977High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  7. CVE-2026-67978High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedAug 3, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  8. CVE-2026-3245High
    CISA ADP Vulnrichment
    CVSS 7.5
    Canon Production Printing/PRISMAproductiongeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-18577High
    Incomplete patch leads to administrative account takeover
    CVSS 8.2 Known exploited
    N-able/N-centralgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-10848High
    Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)
    CVSS 7.0
    zephyrproject/zephyrgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  11. CVE-2026-65321Critical
    PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
    CVSS 9.8
    laughingman7743/PyAthenageneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-10774Low
    PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS
    CVSS 2.4
    zephyrproject/zephyrgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  13. CVE-2026-68580High
    FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel
    CVSS 7.5
    FreeRDP/FreeRDPgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2025-71401Medium
    better-auth before 1.4.2 basePath Modification DoS
    CVSS 5.9
    better-auth/better-authgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  15. CVE-2025-71400High
    better-auth passkey before 1.4.0 IDOR via delete-passkey
    CVSS 7.1
    better-auth/passkeygeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  16. CVE-2025-71399High
    Better Auth before 1.4.5 Path Normalization Bypass via rou3
    CVSS 8.6
    better-auth/better-authgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  17. CVE-2026-12231Medium
    Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image'
    CVSS 6.4
    timstrifler/Exclusive Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  18. CVE-2026-15236High
    Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure
    CVSS 7.5
    Unknown/Gallery for Google Photosgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  19. CVE-2026-13389Medium
    WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
    CVSS 6.5
    Unknown/webtoffee-cookie-consentgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  20. CVE-2025-15675Medium
    Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
    CVSS 4.8
    Unknown/Charitablegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-16540High
    Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
    CVSS 7.5
    Unknown/Simply Schedule Appointmentsgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  22. CVE-2026-16064Medium
    Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
    CVSS 5.4
    Unknown/Event Booking Manager for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  23. CVE-2026-16063Medium
    Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content
    CVSS 5.4
    Unknown/Event Booking Manager for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  24. CVE-2026-16062Medium
    Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content
    CVSS 6.6
    Unknown/Event Booking Manager for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  25. CVE-2026-16292Medium
    Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF
    CVSS 5.4
    Unknown/Frontend File Manager Plugingeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  26. CVE-2026-16291Medium
    ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
    CVSS 4.3
    Unknown/ProfileGridgeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  27. CVE-2026-16285High
    WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
    CVSS 7.5
    Unknown/Product Attachment for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  28. CVE-2026-16273Medium
    Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
    CVSS 4.6
    Unknown/Narrative Publishergeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-16261High
    Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover
    CVSS 7.5
    Unknown/login-socialgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  30. CVE-2026-16042Medium
    LWS Optimize < 3.4 - Subscriber+ Cache Deletion
    CVSS 4.3
    Unknown/LWS Optimizegeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  31. CVE-2026-14817Medium
    Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes
    CVSS 6.8
    Unknown/Element Pack Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  32. CVE-2026-12586High
    Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
    CVSS 8.1
    Unknown/Lenxel WPgeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  33. CVE-2026-11872Medium
    Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item
    CVSS 4.3
    Unknown/Clever Mega Menu for Visual Composergeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  34. CVE-2026-16256Critical
    Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation
    CVSS 9.8
    Unknown/POUCO Import Usersgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  35. CVE-2026-15939Low
    Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API
    CVSS 2.7
    Unknown/Simple Restrictgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-15385Medium
    RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS
    CVSS 5.4
    Unknown/RT Mega Menugeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  37. CVE-2026-15248Medium
    Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
    CVSS 5.5
    Unknown/Meta Boxgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-15241High
    ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
    CVSS 7.5
    Unknown/AI ChatBot for WooCommercegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  39. CVE-2026-15206High
    SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile
    CVSS 7.5
    Unknown/SMS Alertgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  40. CVE-2026-15151High
    Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications
    CVSS 7.5
    Unknown/Five Star Restaurant Reservationsgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  41. CVE-2026-14938Medium
    FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR
    CVSS 4.3
    Unknown/FluentBoardsgeneric
    PublishedAug 2, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-14920High
    AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter
    CVSS 8.2
    Unknown/AcyMailinggeneric
    PublishedAug 2, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  43. CVE-2026-14864Medium
    JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
    CVSS 5.4
    Unknown/JetEnginegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  44. CVE-2026-14841Medium
    King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
    CVSS 6.1
    Unknown/King Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  45. CVE-2026-18573Medium
    Keycloak-services: keycloak-services: client access-type policy condition bypass during client update
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  46. CVE-2026-18572Medium
    Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  47. CVE-2026-18571Medium
    Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  48. CVE-2026-18570Medium
    Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  49. CVE-2026-13339High
    CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter
    CVSS 7.5
    cubewp1211/CubeWP Frameworkgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  50. CVE-2026-18352High
    User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
    CVSS 7.5
    gm_alex/User Access Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
Page 33 of 326
Previous3132333435Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard