1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 9:30 AM 16,321 active 1,443 known exploited

Catalog summary

16,321

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 9:30 AM 16,321 active 1,443 known exploited

Catalog summary

16,321

Active CVEs

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,751–2,800 of 16,321 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2024-23567Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  2. CVE-2024-23564Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    HCL Software/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  3. CVE-2026-16015Medium
    poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
    CVSS 6.3
    poco-ai/poco-clawgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  4. CVE-2026-13082Medium
    GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
    CVSS 5.3
    BURAK/GD::SecurityImagegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  5. CVE-2026-13410High
    Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
    CVSS 8.2
    GARU/Dancer::Plugin::Auth::Googlegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  6. CVE-2026-15943Medium
    Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  7. CVE-2026-16013Medium
    liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
    CVSS 5.3
    liftoff-sr/CIPstergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  8. CVE-2026-16009Medium
    itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  9. CVE-2026-16008Medium
    sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
    CVSS 6.3
    sagold/json-schema-librarygeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  10. CVE-2026-22104High
    Improper access control in Hashtopolis server chunk activity component
    CVSS 7.1
    hashtopolis/servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  11. CVE-2026-15380Medium
    Local privilege escalation in Symantec ITMS
    CVSS 5.1
    Broadcom/Symantec Management Suitegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  12. CVE-2026-15379Medium
    Arbitrary File Read as SYSTEM in Symantec ITMS
    CVSS 5.1
    Broadcom/Symantec IT Management Suitegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  13. CVE-2019-25764High
    CISA ADP Vulnrichment
    CVSS 7.3
    ASUS/AURA SYNCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  14. CVE-2026-15094Medium
    WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
    CVSS 6.1
    thimpress/WP Hotel Bookinggeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2026-15982Critical
    Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'
    CVSS 9.8
    CodeRevolution/Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkitgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-21770Medium
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking
    CVSS 6.5
    HCLSoftware/HCL Traveler for Microsoft Outlook (HTMO)generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  17. CVE-2026-41993Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    TXOne Networks/SafePortAgent, TXOne Networks/StellarProtectgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  18. CVE-2026-13765High
    LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
    CVSS 7.5
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  19. CVE-2026-14503Medium
    pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read
    CVSS 6.5
    ploudapp/pCloud WP Backupgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  20. CVE-2026-11324Medium
    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'
    CVSS 6.1
    evertec/WooCommerce Placetopay Gateway, evertec/WooCommerce Placetopay Gateway Belice +4generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  21. CVE-2026-15159Medium
    Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter
    CVSS 4.3
    SaturdayDrive/Ninja Forms - Excel Exportgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  22. CVE-2026-14956Critical
    Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter
    CVSS 9.8
    Bricksforge/Bricksforgegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  23. CVE-2026-2594Medium
    Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
    CVSS 6.4
    inc2734/Smart Custom Fieldsgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  24. CVE-2026-44251Medium
    Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message
    CVSS 6.5
    wazuh/wazuhgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  25. CVE-2025-51677Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  26. CVE-2025-51678Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  27. CVE-2025-60357High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2026-36669Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  29. CVE-2026-42168Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  30. CVE-2026-40106Medium
    Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)
    CVSS 4.7
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  31. CVE-2026-39359High
    Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name
    CVSS 7.5
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  32. CVE-2026-34150High
    Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing
    CVSS 7.5
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  33. CVE-2026-33754Medium
    Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)
    CVSS 6.5
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  34. CVE-2026-33434Medium
    Wazuh: Rate Limit Bypass via /events Endpoint
    CVSS 4.3
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 18, 2026View HOL analysis
  35. CVE-2026-44453High
    h2o is vulnerable to musl libc stack overflow
    CVSS 7.5
    h2o/h2ogeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-44452Medium
    h2o is vulnerable to heap overrun
    CVSS 5.9
    h2o/h2ogeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-44436High
    Quicly is vulnerable to connection state corruption
    CVSS 7.5
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  38. CVE-2026-44435High
    Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
    CVSS 7.5
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-44434Medium
    Quicly is vulnerable to stateless reset injection
    CVSS 5.3
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-44433Medium
    Quicly is vulnerable to memory exhaustion
    CVSS 5.3
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-15997Low
    Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded state
    CVSS 1.7
    Legion of the Bouncy Castle Inc./BC-LTSgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-43977High
    wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API
    CVSS 7.5
    wger-project/wgergeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  43. CVE-2026-43978High
    wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers
    CVSS 8.1
    wger-project/wgergeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  44. CVE-2026-44182Critical
    Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering
    CVSS 10.0
    jupyter-server/enterprise_gatewaygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-44181Critical
    Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
    CVSS 10.0
    jupyter-server/enterprise_gatewaygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-45368High
    Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
    CVSS 8.4
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 18, 2026View HOL analysis
  47. CVE-2026-45334Medium
    Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
    CVSS 5.3
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  48. CVE-2026-44175High
    Kirby: Cross-site scripting (XSS) from list field content in the site frontend
    CVSS 8.5
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  49. CVE-2026-44176Medium
    Kirby: `pages.access` permission is not checked during rendering of page drafts
    CVSS 6.0
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  50. CVE-2026-44177High
    Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup
    CVSS 8.8
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 56 of 327
Previous5455565758Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,751–2,800 of 16,321 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2024-23567Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    HCLSoftware/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  2. CVE-2024-23564Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    HCL Software/Aftermarket EPCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  3. CVE-2026-16015Medium
    poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
    CVSS 6.3
    poco-ai/poco-clawgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  4. CVE-2026-13082Medium
    GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
    CVSS 5.3
    BURAK/GD::SecurityImagegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  5. CVE-2026-13410High
    Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
    CVSS 8.2
    GARU/Dancer::Plugin::Auth::Googlegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  6. CVE-2026-15943Medium
    Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change
    CVSS 5.5
    Affected software not mappedEcosystem not listed
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  7. CVE-2026-16013Medium
    liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
    CVSS 5.3
    liftoff-sr/CIPstergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  8. CVE-2026-16009Medium
    itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  9. CVE-2026-16008Medium
    sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
    CVSS 6.3
    sagold/json-schema-librarygeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  10. CVE-2026-22104High
    Improper access control in Hashtopolis server chunk activity component
    CVSS 7.1
    hashtopolis/servergeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026 Fix availableView HOL analysis
  11. CVE-2026-15380Medium
    Local privilege escalation in Symantec ITMS
    CVSS 5.1
    Broadcom/Symantec Management Suitegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  12. CVE-2026-15379Medium
    Arbitrary File Read as SYSTEM in Symantec ITMS
    CVSS 5.1
    Broadcom/Symantec IT Management Suitegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  13. CVE-2019-25764High
    CISA ADP Vulnrichment
    CVSS 7.3
    ASUS/AURA SYNCgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  14. CVE-2026-15094Medium
    WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
    CVSS 6.1
    thimpress/WP Hotel Bookinggeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2026-15982Critical
    Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'
    CVSS 9.8
    CodeRevolution/Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkitgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-21770Medium
    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking
    CVSS 6.5
    HCLSoftware/HCL Traveler for Microsoft Outlook (HTMO)generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  17. CVE-2026-41993Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    TXOne Networks/SafePortAgent, TXOne Networks/StellarProtectgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 27, 2026 Fix availableView HOL analysis
  18. CVE-2026-13765High
    LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
    CVSS 7.5
    thimpress/LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  19. CVE-2026-14503Medium
    pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read
    CVSS 6.5
    ploudapp/pCloud WP Backupgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  20. CVE-2026-11324Medium
    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'
    CVSS 6.1
    evertec/WooCommerce Placetopay Gateway, evertec/WooCommerce Placetopay Gateway Belice +4generic
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  21. CVE-2026-15159Medium
    Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter
    CVSS 4.3
    SaturdayDrive/Ninja Forms - Excel Exportgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  22. CVE-2026-14956Critical
    Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter
    CVSS 9.8
    Bricksforge/Bricksforgegeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 21, 2026View HOL analysis
  23. CVE-2026-2594Medium
    Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
    CVSS 6.4
    inc2734/Smart Custom Fieldsgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  24. CVE-2026-44251Medium
    Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message
    CVSS 6.5
    wazuh/wazuhgeneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  25. CVE-2025-51677Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  26. CVE-2025-51678Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  27. CVE-2025-60357High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2026-36669Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  29. CVE-2026-42168Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 17, 2026First seen at HOL Jul 17, 2026Updated Jul 20, 2026View HOL analysis
  30. CVE-2026-40106Medium
    Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)
    CVSS 4.7
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  31. CVE-2026-39359High
    Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name
    CVSS 7.5
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  32. CVE-2026-34150High
    Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing
    CVSS 7.5
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  33. CVE-2026-33754Medium
    Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)
    CVSS 6.5
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  34. CVE-2026-33434Medium
    Wazuh: Rate Limit Bypass via /events Endpoint
    CVSS 4.3
    wazuh/wazuhgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 18, 2026View HOL analysis
  35. CVE-2026-44453High
    h2o is vulnerable to musl libc stack overflow
    CVSS 7.5
    h2o/h2ogeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-44452Medium
    h2o is vulnerable to heap overrun
    CVSS 5.9
    h2o/h2ogeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-44436High
    Quicly is vulnerable to connection state corruption
    CVSS 7.5
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  38. CVE-2026-44435High
    Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
    CVSS 7.5
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-44434Medium
    Quicly is vulnerable to stateless reset injection
    CVSS 5.3
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-44433Medium
    Quicly is vulnerable to memory exhaustion
    CVSS 5.3
    h2o/quiclygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-15997Low
    Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded state
    CVSS 1.7
    Legion of the Bouncy Castle Inc./BC-LTSgeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-43977High
    wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API
    CVSS 7.5
    wger-project/wgergeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  43. CVE-2026-43978High
    wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers
    CVSS 8.1
    wger-project/wgergeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  44. CVE-2026-44182Critical
    Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering
    CVSS 10.0
    jupyter-server/enterprise_gatewaygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 5, 2026View HOL analysis
  45. CVE-2026-44181Critical
    Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
    CVSS 10.0
    jupyter-server/enterprise_gatewaygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Aug 5, 2026View HOL analysis
  46. CVE-2026-45368High
    Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
    CVSS 8.4
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 18, 2026View HOL analysis
  47. CVE-2026-45334Medium
    Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
    CVSS 5.3
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  48. CVE-2026-44175High
    Kirby: Cross-site scripting (XSS) from list field content in the site frontend
    CVSS 8.5
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  49. CVE-2026-44176Medium
    Kirby: `pages.access` permission is not checked during rendering of page drafts
    CVSS 6.0
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  50. CVE-2026-44177High
    Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup
    CVSS 8.8
    getkirby/kirbygeneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
Page 56 of 327
Previous5455565758Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard