1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:40 PM 16,272 active 1,443 known exploited

Catalog summary

16,272

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:40 PM 16,272 active 1,443 known exploited

Catalog summary

16,272

Active CVEs

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,701–1,750 of 16,272 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15988High
    AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match
    CVSS 8.8
    tigroumeow/AI Engine – The Chatbot, AI Framework & MCP for WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  2. CVE-2025-14469Medium
    Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification
    CVSS 4.3
    mndpsingh287/Theme Editorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  3. CVE-2026-14840Medium
    YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
    CVSS 5.3
    Unknown/YOP Pollgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-14839High
    Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
    CVSS 7.5
    Unknown/Mapster WP Mapsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  5. CVE-2026-14823Low
    Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
    CVSS 2.2
    Unknown/Event Tickets and Registrationgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-14822Medium
    Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
    CVSS 5.3
    Unknown/Event Tickets and Registrationgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-14561Medium
    Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
    CVSS 6.5
    Unknown/Authora : Easy login with mobile numbergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  8. CVE-2026-14315Medium
    Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
    CVSS 6.5
    Unknown/Pixel Tag Manager for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  9. CVE-2026-14292Medium
    WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
    CVSS 5.4
    Unknown/Download Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  10. CVE-2026-14214Low
    Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
    CVSS 2.7
    Unknown/Booking for Appointments and Events Calendargeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-14195Low
    Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
    CVSS 2.7
    Unknown/Brizygeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-13729Medium
    Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
    CVSS 4.3
    Unknown/Podlove Podcast Publishergeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-13725High
    Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
    CVSS 7.1
    Unknown/Dynamic Pricing With Discount Rules for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-13604Medium
    Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
    CVSS 5.3
    Unknown/Pixelavogeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-13596Critical
    Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
    CVSS 9.1
    Unknown/Participants Databasegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  16. CVE-2026-13329Medium
    WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
    CVSS 6.5
    Unknown/Buckaroo Woocommerce Payments Plugingeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  17. CVE-2026-12696Medium
    wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
    CVSS 5.4
    Unknown/wpForo Forumgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  18. CVE-2026-11882Low
    Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes
    CVSS 3.7
    Unknown/Builderall for WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-10827Low
    Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes
    CVSS 3.5
    Unknown/Spectra Legacygeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-13157High
    Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
    CVSS 7.2
    Unknown/Theme Demo Importgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-13158High
    Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
    CVSS 7.2
    Unknown/Everest Toolkitgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-15234Medium
    Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
    CVSS 5.4
    Unknown/Codeless Page Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  23. CVE-2026-15262Medium
    Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column
    CVSS 5.4
    Unknown/Admin Columns for ACF Fieldsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  24. CVE-2026-15368High
    Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration
    CVSS 8.1
    Unknown/User Profile Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-15244High
    HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
    CVSS 7.2
    Unknown/HUSKYgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-14836High
    Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass
    CVSS 8.1
    Unknown/Login & Register Formsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-14596High
    DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
    CVSS 8.8
    Unknown/DynamicKit for Elementorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-14309High
    Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
    CVSS 8.1
    Unknown/Chat On Desk Order Notificationsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-14197Low
    Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
    CVSS 3.8
    Unknown/Fluent Supportgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-12966Medium
    Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
    CVSS 5.3
    Unknown/Direct Payments for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  31. CVE-2025-15669Medium
    Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
    CVSS 4.8
    Unknown/Bit Formgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  32. CVE-2026-15932Medium
    Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
    CVSS 5.3
    Unknown/Support Genixgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-3141Critical
    FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter
    CVSS 9.1
    wpwax/FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & Moregeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2026-15403Medium
    Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via 'field' Parameter
    CVSS 4.9
    dotonpaper/Pinpoint Booking System – Version 2generic
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-15006High
    Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Field
    CVSS 7.5
    bitpressadmin/Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automationgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  36. CVE-2026-13362Medium
    SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via _sp_form_code Post Meta
    CVSS 6.4
    sendpulse/SendPulse Email Marketing Newslettergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-15414High
    Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta
    CVSS 8.8
    wpswings/Subscriptions for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-34641High
    Premiere Pro | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Premieregeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-65981High
    Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover
    CVSS 7.1
    coturn/coturngeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18394High
    Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration
    CVSS 7.4
    AWS/Strands Agents Toolsgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  41. CVE-2026-18481High
    Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
    CVSS 7.3
    AWS/AWS Ops Wheelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  42. CVE-2026-58048Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-58047Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-17566Critical
    pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
    CVSS 9.9
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-17351Critical
    pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-17350Medium
    pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
    CVSS 5.4
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-17349Critical
    pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
    CVSS 9.6
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-17348Medium
    pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)
    CVSS 6.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-17347High
    pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
    CVSS 7.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-17346High
    pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
    CVSS 8.8
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 35 of 326
Previous3334353637Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,436

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 1,701–1,750 of 16,272 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15988High
    AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match
    CVSS 8.8
    tigroumeow/AI Engine – The Chatbot, AI Framework & MCP for WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  2. CVE-2025-14469Medium
    Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification
    CVSS 4.3
    mndpsingh287/Theme Editorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  3. CVE-2026-14840Medium
    YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
    CVSS 5.3
    Unknown/YOP Pollgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-14839High
    Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
    CVSS 7.5
    Unknown/Mapster WP Mapsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  5. CVE-2026-14823Low
    Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
    CVSS 2.2
    Unknown/Event Tickets and Registrationgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-14822Medium
    Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
    CVSS 5.3
    Unknown/Event Tickets and Registrationgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-14561Medium
    Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
    CVSS 6.5
    Unknown/Authora : Easy login with mobile numbergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  8. CVE-2026-14315Medium
    Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
    CVSS 6.5
    Unknown/Pixel Tag Manager for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  9. CVE-2026-14292Medium
    WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
    CVSS 5.4
    Unknown/Download Managergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  10. CVE-2026-14214Low
    Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
    CVSS 2.7
    Unknown/Booking for Appointments and Events Calendargeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-14195Low
    Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
    CVSS 2.7
    Unknown/Brizygeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-13729Medium
    Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
    CVSS 4.3
    Unknown/Podlove Podcast Publishergeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-13725High
    Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
    CVSS 7.1
    Unknown/Dynamic Pricing With Discount Rules for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-13604Medium
    Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
    CVSS 5.3
    Unknown/Pixelavogeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-13596Critical
    Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
    CVSS 9.1
    Unknown/Participants Databasegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  16. CVE-2026-13329Medium
    WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
    CVSS 6.5
    Unknown/Buckaroo Woocommerce Payments Plugingeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  17. CVE-2026-12696Medium
    wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
    CVSS 5.4
    Unknown/wpForo Forumgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  18. CVE-2026-11882Low
    Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes
    CVSS 3.7
    Unknown/Builderall for WordPressgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-10827Low
    Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes
    CVSS 3.5
    Unknown/Spectra Legacygeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-13157High
    Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
    CVSS 7.2
    Unknown/Theme Demo Importgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  21. CVE-2026-13158High
    Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
    CVSS 7.2
    Unknown/Everest Toolkitgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026View HOL analysis
  22. CVE-2026-15234Medium
    Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
    CVSS 5.4
    Unknown/Codeless Page Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  23. CVE-2026-15262Medium
    Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column
    CVSS 5.4
    Unknown/Admin Columns for ACF Fieldsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  24. CVE-2026-15368High
    Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration
    CVSS 8.1
    Unknown/User Profile Buildergeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-15244High
    HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
    CVSS 7.2
    Unknown/HUSKYgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-14836High
    Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass
    CVSS 8.1
    Unknown/Login & Register Formsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-14596High
    DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
    CVSS 8.8
    Unknown/DynamicKit for Elementorgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-14309High
    Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
    CVSS 8.1
    Unknown/Chat On Desk Order Notificationsgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-14197Low
    Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
    CVSS 3.8
    Unknown/Fluent Supportgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-12966Medium
    Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
    CVSS 5.3
    Unknown/Direct Payments for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  31. CVE-2025-15669Medium
    Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
    CVSS 4.8
    Unknown/Bit Formgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  32. CVE-2026-15932Medium
    Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
    CVSS 5.3
    Unknown/Support Genixgeneric
    PublishedAug 1, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-3141Critical
    FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter
    CVSS 9.1
    wpwax/FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & Moregeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  34. CVE-2026-15403Medium
    Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via 'field' Parameter
    CVSS 4.9
    dotonpaper/Pinpoint Booking System – Version 2generic
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  35. CVE-2026-15006High
    Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Field
    CVSS 7.5
    bitpressadmin/Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automationgeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  36. CVE-2026-13362Medium
    SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via _sp_form_code Post Meta
    CVSS 6.4
    sendpulse/SendPulse Email Marketing Newslettergeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  37. CVE-2026-15414High
    Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta
    CVSS 8.8
    wpswings/Subscriptions for WooCommercegeneric
    PublishedAug 1, 2026First seen at HOL Aug 3, 2026Updated Aug 3, 2026View HOL analysis
  38. CVE-2026-34641High
    Premiere Pro | Out-of-bounds Write (CWE-787)
    CVSS 7.8
    Adobe/Premieregeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-65981High
    Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover
    CVSS 7.1
    coturn/coturngeneric
    PublishedJul 31, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026View HOL analysis
  40. CVE-2026-18394High
    Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration
    CVSS 7.4
    AWS/Strands Agents Toolsgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  41. CVE-2026-18481High
    Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
    CVSS 7.3
    AWS/AWS Ops Wheelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 4, 2026View HOL analysis
  42. CVE-2026-58048Critical
    CISA ADP Vulnrichment
    CVSS 9.4
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-58047Medium
    CISA ADP Vulnrichment
    CVSS 5.6
    WebPros/WP Squared, WebPros/cPanelgeneric
    PublishedJul 31, 2026First seen at HOL Aug 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-17566Critical
    pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
    CVSS 9.9
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-17351Critical
    pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
    CVSS 9.0
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-17350Medium
    pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
    CVSS 5.4
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-17349Critical
    pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
    CVSS 9.6
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-17348Medium
    pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)
    CVSS 6.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-17347High
    pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
    CVSS 7.5
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-17346High
    pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
    CVSS 8.8
    pgadmin.org/pgAdmin 4generic
    PublishedJul 31, 2026First seen at HOL Aug 4, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 35 of 326
Previous3334353637Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard