1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:43 PM 16,277 active 1,443 known exploited

Catalog summary

16,277

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:43 PM 16,277 active 1,443 known exploited

Catalog summary

16,277

Active CVEs

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,651–1,700 of 16,277 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14864Medium
    JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
    CVSS 5.4
    Unknown/JetEnginegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  2. CVE-2026-14841Medium
    King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
    CVSS 6.1
    Unknown/King Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  3. CVE-2026-18573Medium
    Keycloak-services: keycloak-services: client access-type policy condition bypass during client update
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  4. CVE-2026-18572Medium
    Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-18571Medium
    Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-18570Medium
    Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-13339High
    CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter
    CVSS 7.5
    cubewp1211/CubeWP Frameworkgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  8. CVE-2026-18352High
    User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
    CVSS 7.5
    gm_alex/User Access Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-18556High
    Unauthenticated administrative account takeover
    CVSS 8.2 Known exploited
    N-able/N-centralgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-67326High
    GitPython before 3.1.50 Newline Injection via config_writer section
    CVSS 7.0
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-67324Critical
    GitPython 3.1.50 Authentication Bypass via Joined Short Options
    CVSS 9.8
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-67323High
    GitPython before 3.1.51 Command Injection via unguarded Git options
    CVSS 8.4
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-71403High
    better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass
    CVSS 7.1
    better-auth/better-authgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  14. CVE-2026-67289Critical
    FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
    CVSS 9.8
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-71404Medium
    better-auth before 1.1.16 Reflected XSS via error parameter
    CVSS 5.1
    better-auth/better-authgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  16. CVE-2026-66402Critical
    FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass
    CVSS 9.8
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-67325High
    GitPython before 3.1.51 Command Injection via option prefix abbreviation
    CVSS 8.8
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-67293Medium
    FreeRDP before 3.29.0 Improper Certificate Hostname Validation
    CVSS 4.2
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-67305Critical
    FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr
    CVSS 9.4
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2025-71402Low
    better-auth before 1.4.0 Session Revocation via Forged Cookie
    CVSS 2.0
    better-auth/better-authgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-10773Medium
    Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)
    CVSS 5.4
    zephyrproject/zephyrgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-2411Medium
    Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-18536High
    Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
    CVSS 7.5
    RRWO/Data::Entropygeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-16635High
    Pronamic Pay <= 10.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms 'Update user role' Field
    CVSS 8.8
    pronamic/Pronamic Paygeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  25. CVE-2026-18344Medium
    Responsive Thumbnail Slider < 1.1.53 - Reflected Cross-Site Scripting via 'id' Parameter
    CVSS 6.1
    nik00726/Responsive Thumbnail Slidergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  26. CVE-2026-15644Medium
    Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute
    CVSS 6.4
    codesupplyco/Powerkit – Supercharge your WordPress Sitegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2025-14073Medium
    WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure
    CVSS 5.3
    woocommerce/WooCommerce PayPal Paymentsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  28. CVE-2026-17555Medium
    WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export_data' Parameter
    CVSS 4.9
    wpvividplugins/WPvivid — Backup, Migration & Staginggeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-17571Medium
    Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'
    CVSS 6.1
    wpmanageninja/Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  30. CVE-2026-15964Critical
    Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
    CVSS 9.8
    britcoder/Single Sign On For TNGgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  31. CVE-2026-15649Medium
    Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    codesupplyco/Powerkit – Supercharge your WordPress Sitegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-16091Medium
    GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gamipress_rank' Shortcode
    CVSS 6.4
    rubengc/GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  33. CVE-2026-17580Medium
    Advanced Views <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via 'view-refresh' and 'card-refresh' REST Endpoints
    CVSS 6.5
    wplakeorg/Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…generic
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2026-15950Medium
    Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute
    CVSS 6.4
    cozythemes/Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templatesgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-18059Medium
    PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key Validation
    CVSS 5.3
    pixelyoursite/PixelYourSite Pro – Your smart PIXEL (TAG) Manager, pixelyoursite/PixelYourSite – Your smart PIXEL (TAG) & API Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  36. CVE-2026-15052High
    MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 - Unauthenticated Stored Cross-Site Scripting via Form Field Values
    CVSS 7.2
    umarbajwa/MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-15450High
    NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter
    CVSS 8.1
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-17605Medium
    Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field
    CVSS 6.6
    stiofansisland/Payment forms, Buy now buttons, and Invoicing System | GetPaidgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  39. CVE-2026-15951Medium
    Icegram Mailer <= 1.0.12 - Authenticated (Administrator+) SQL Injection via 'fields' Parameter
    CVSS 4.9
    icegram/Icegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  40. CVE-2026-16144High
    Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter
    CVSS 8.1
    wpchill/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-15018Medium
    Database Collation Fix <= 1.2.10 - Unauthenticated SQL Injection via 'force-collation-algorithm' Parameter
    CVSS 5.3
    davejesch/Database Collation Fixgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  42. CVE-2026-16614Medium
    GSheetConnector <= 5.2.1 - Authenticated (Administrator+) SQL Injection via 's' Parameter
    CVSS 4.9
    westerndeal/GSheetConnector – CF7 Google Sheets Connectorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  43. CVE-2026-11995Medium
    Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action()
    CVSS 5.3
    saadiqbal/Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  44. CVE-2026-16685Medium
    Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  45. CVE-2026-16090Medium
    GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via gamipress_achievement Shortcode
    CVSS 6.4
    rubengc/GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  46. CVE-2026-18062Medium
    Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content
    CVSS 6.4
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  47. CVE-2026-18435Medium
    Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute
    CVSS 6.4
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  48. CVE-2026-15645Medium
    Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nav' Shortcode Attribute
    CVSS 6.4
    codesupplyco/Powerkit – Supercharge your WordPress Sitegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  49. CVE-2026-15662Medium
    Advanced Woo Labels <= 2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_color' Parameter
    CVSS 6.4
    mihail-barinov/Advanced Woo Labels – Product Labels & Badges for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  50. CVE-2026-15601Medium
    Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)
    CVSS 4.9
    themeum/Kirki – Freeform Page Builder, Website Builder & Customizergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
Page 34 of 326
Previous3233343536Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,651–1,700 of 16,277 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14864Medium
    JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
    CVSS 5.4
    Unknown/JetEnginegeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  2. CVE-2026-14841Medium
    King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
    CVSS 6.1
    Unknown/King Addons for Elementorgeneric
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  3. CVE-2026-18573Medium
    Keycloak-services: keycloak-services: client access-type policy condition bypass during client update
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  4. CVE-2026-18572Medium
    Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-18571Medium
    Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation
    CVSS 6.6
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-18570Medium
    Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed
    CVSS 5.4
    Affected software not mappedEcosystem not listed
    PublishedAug 2, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-13339High
    CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter
    CVSS 7.5
    cubewp1211/CubeWP Frameworkgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  8. CVE-2026-18352High
    User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
    CVSS 7.5
    gm_alex/User Access Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  9. CVE-2026-18556High
    Unauthenticated administrative account takeover
    CVSS 8.2 Known exploited
    N-able/N-centralgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-67326High
    GitPython before 3.1.50 Newline Injection via config_writer section
    CVSS 7.0
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-67324Critical
    GitPython 3.1.50 Authentication Bypass via Joined Short Options
    CVSS 9.8
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-67323High
    GitPython before 3.1.51 Command Injection via unguarded Git options
    CVSS 8.4
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2025-71403High
    better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass
    CVSS 7.1
    better-auth/better-authgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  14. CVE-2026-67289Critical
    FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
    CVSS 9.8
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2025-71404Medium
    better-auth before 1.1.16 Reflected XSS via error parameter
    CVSS 5.1
    better-auth/better-authgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  16. CVE-2026-66402Critical
    FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass
    CVSS 9.8
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-67325High
    GitPython before 3.1.51 Command Injection via option prefix abbreviation
    CVSS 8.8
    gitpython-developers/GitPythongeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-67293Medium
    FreeRDP before 3.29.0 Improper Certificate Hostname Validation
    CVSS 4.2
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-67305Critical
    FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr
    CVSS 9.4
    FreeRDP/FreeRDPgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2025-71402Low
    better-auth before 1.4.0 Session Revocation via Forged Cookie
    CVSS 2.0
    better-auth/better-authgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  21. CVE-2026-10773Medium
    Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)
    CVSS 5.4
    zephyrproject/zephyrgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-2411Medium
    Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values
    CVSS 6.5
    zephyrproject/zephyrgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-18536High
    Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
    CVSS 7.5
    RRWO/Data::Entropygeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-16635High
    Pronamic Pay <= 10.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms 'Update user role' Field
    CVSS 8.8
    pronamic/Pronamic Paygeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  25. CVE-2026-18344Medium
    Responsive Thumbnail Slider < 1.1.53 - Reflected Cross-Site Scripting via 'id' Parameter
    CVSS 6.1
    nik00726/Responsive Thumbnail Slidergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  26. CVE-2026-15644Medium
    Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute
    CVSS 6.4
    codesupplyco/Powerkit – Supercharge your WordPress Sitegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  27. CVE-2025-14073Medium
    WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure
    CVSS 5.3
    woocommerce/WooCommerce PayPal Paymentsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  28. CVE-2026-17555Medium
    WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export_data' Parameter
    CVSS 4.9
    wpvividplugins/WPvivid — Backup, Migration & Staginggeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  29. CVE-2026-17571Medium
    Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'
    CVSS 6.1
    wpmanageninja/Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  30. CVE-2026-15964Critical
    Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
    CVSS 9.8
    britcoder/Single Sign On For TNGgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  31. CVE-2026-15649Medium
    Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    codesupplyco/Powerkit – Supercharge your WordPress Sitegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  32. CVE-2026-16091Medium
    GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gamipress_rank' Shortcode
    CVSS 6.4
    rubengc/GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  33. CVE-2026-17580Medium
    Advanced Views <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via 'view-refresh' and 'card-refresh' REST Endpoints
    CVSS 6.5
    wplakeorg/Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…generic
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2026-15950Medium
    Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute
    CVSS 6.4
    cozythemes/Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templatesgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-18059Medium
    PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key Validation
    CVSS 5.3
    pixelyoursite/PixelYourSite Pro – Your smart PIXEL (TAG) Manager, pixelyoursite/PixelYourSite – Your smart PIXEL (TAG) & API Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  36. CVE-2026-15052High
    MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 - Unauthenticated Stored Cross-Site Scripting via Form Field Values
    CVSS 7.2
    umarbajwa/MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-15450High
    NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter
    CVSS 8.1
    webaways/NEX-Forms – Ultimate Forms Plugin for WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-17605Medium
    Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field
    CVSS 6.6
    stiofansisland/Payment forms, Buy now buttons, and Invoicing System | GetPaidgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  39. CVE-2026-15951Medium
    Icegram Mailer <= 1.0.12 - Authenticated (Administrator+) SQL Injection via 'fields' Parameter
    CVSS 4.9
    icegram/Icegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  40. CVE-2026-16144High
    Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter
    CVSS 8.1
    wpchill/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  41. CVE-2026-15018Medium
    Database Collation Fix <= 1.2.10 - Unauthenticated SQL Injection via 'force-collation-algorithm' Parameter
    CVSS 5.3
    davejesch/Database Collation Fixgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  42. CVE-2026-16614Medium
    GSheetConnector <= 5.2.1 - Authenticated (Administrator+) SQL Injection via 's' Parameter
    CVSS 4.9
    westerndeal/GSheetConnector – CF7 Google Sheets Connectorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  43. CVE-2026-11995Medium
    Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action()
    CVSS 5.3
    saadiqbal/Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  44. CVE-2026-16685Medium
    Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  45. CVE-2026-16090Medium
    GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via gamipress_achievement Shortcode
    CVSS 6.4
    rubengc/GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  46. CVE-2026-18062Medium
    Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content
    CVSS 6.4
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  47. CVE-2026-18435Medium
    Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute
    CVSS 6.4
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  48. CVE-2026-15645Medium
    Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nav' Shortcode Attribute
    CVSS 6.4
    codesupplyco/Powerkit – Supercharge your WordPress Sitegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  49. CVE-2026-15662Medium
    Advanced Woo Labels <= 2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_color' Parameter
    CVSS 6.4
    mihail-barinov/Advanced Woo Labels – Product Labels & Badges for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  50. CVE-2026-15601Medium
    Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)
    CVSS 4.9
    themeum/Kirki – Freeform Page Builder, Website Builder & Customizergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
Page 34 of 326
Previous3233343536Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard