1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:30 AM 16,324 active 1,443 known exploited

Catalog summary

16,324

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:30 AM 16,324 active 1,443 known exploited

Catalog summary

16,324

Active CVEs

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,851–2,900 of 16,324 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-44632Critical
    Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
    CVSS 9.1
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  2. CVE-2026-44596Medium
    Yamcs: No Rate Limiting on Authentication Endpoint
    CVSS 6.5
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  3. CVE-2026-44595Medium
    Yamcs: Unauthorized user enumeration via IAM API endpoints
    CVSS 4.3
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  4. CVE-2026-45695Critical
    Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used
    CVSS 9.8
    github.com/kopia/kopia, kopia/kopiageneric · go
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-12379Medium
    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of Axivion
    CVSS 6.8
    Qt/Axiviongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  6. CVE-2026-14890Critical
    CVE-2026-14890
    CVSS 9.1
    SGLang/SGLanggeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  7. CVE-2026-14254High
    Improper Restriction of Excessive Authentication Attempts in Delphix Continuous Data
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  8. CVE-2026-5674High
    Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-35145Low
    HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.
    CVSS 3.1
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  10. CVE-2026-35143Low
    HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.
    CVSS 3.0
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  11. CVE-2026-35142Low
    HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.
    CVSS 2.6
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  12. CVE-2026-35141Low
    HCL DFXAnalytics is affected by a Login Replay Attack vulnerability
    CVSS 2.6
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  13. CVE-2026-35140Low
    HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
    CVSS 3.0
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  14. CVE-2024-58360Medium
    stoatchat before 0.7.8 Unrestricted Account Creation
    CVSS 6.5
    stoatchat/stoatchatgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026 Fix availableView HOL analysis
  15. CVE-2025-71388High
    stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions
    CVSS 7.6
    stoatchat/stoatchatgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  16. CVE-2025-71377High
    stoatchat before 20250210-1 Unrestricted Message History Fetch
    CVSS 8.7
    stoatchat/stoatchatgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  17. CVE-2026-12391Medium
    ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs
    CVSS 5.0
    Canonical/ubuntu-pro-client (ubuntu-advantage-tools)generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-11386Critical
    ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
    CVSS 9.0
    Canonical/ubuntu-pro-client (ubuntu-advantage-tools)generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-35147High
    HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.
    CVSS 8.2
    HCL Software/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  20. CVE-2026-35149High
    HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
    CVSS 8.2
    HCL Software/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  21. CVE-2026-35148Medium
    HCL DFXServer is affected by a Missing Access Control vulnerability
    CVSS 6.3
    HCL Software/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  22. CVE-2026-35146Medium
    HCL DFXServer is affected by an Unencrypted Communication vulnerability.
    CVSS 6.3
    HCLSoftware/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  23. CVE-2023-49899Critical
    Origin Validation Error in X-Rite MA-T6
    CVSS 9.8
    X-Rite/MA-T6generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026 Fix availableView HOL analysis
  24. CVE-2023-49900Critical
    Origin Validation Error in X-Rite MA-T6
    CVSS 9.8
    X-Rite/MA-T6generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  25. CVE-2026-22752Critical
    Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata
    CVSS 9.6
    Spring Security/Spring Authorization Servergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 21, 2026View HOL analysis
  26. CVE-2026-15324Medium
    SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter
    CVSS 4.4
    phppoet/SysBasics Customize My Account for WooCommerce – Live My Account Customizergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  27. CVE-2026-15103High
    WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter
    CVSS 8.8
    getwpfunnels/WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsellgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  28. CVE-2026-15727Medium
    WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter
    CVSS 4.9
    xylus/WP Bulk Deletegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  29. CVE-2026-15021Medium
    wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field
    CVSS 6.4
    tomdever/wpForo Forumgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  30. CVE-2026-15005High
    Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter
    CVSS 8.8
    timwhitlock/Loco Translategeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  31. CVE-2026-13741High
    Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter
    CVSS 8.8
    UnitedOver/Digits: WordPress Mobile Number Signup and Logingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-13755Medium
    Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute
    CVSS 6.4
    tickera/Tickera – Sell Tickets & Manage Eventsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  33. CVE-2026-15610Medium
    WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function
    CVSS 4.3
    quantumcloud/WPBot – AI ChatBot for Live Support, Lead Generation, AI Servicesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  34. CVE-2026-15106Medium
    WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter
    CVSS 5.3
    quantumcloud/WPBot – AI ChatBot for Live Support, Lead Generation, AI Servicesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  35. CVE-2026-15407Medium
    Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action
    CVSS 4.3
    themifyme/Themify Buildergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  36. CVE-2026-15651Medium
    WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter
    CVSS 4.9
    jgwhite33/WP TripAdvisor Review Slidergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  37. CVE-2026-15008High
    Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token
    CVSS 8.1
    uncannyowl/Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  38. CVE-2026-15022Medium
    Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array
    CVSS 6.5
    themeum/Tutor LMS – eLearning and online course solutiongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  39. CVE-2026-13754Medium
    Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter
    CVSS 6.5
    tickera/Tickera – Sell Tickets & Manage Eventsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  40. CVE-2026-13767Medium
    Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter
    CVSS 6.5
    expresstech/Quiz and Survey Master (QSM) – Quiz Maker & Survey Makergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  41. CVE-2026-15350Medium
    The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter
    CVSS 4.3
    kevp75/The Cache Purgergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  42. CVE-2026-15099Medium
    WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute
    CVSS 6.4
    wpdelicious/WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  43. CVE-2026-12979Medium
    FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
    CVSS 5.5
    Unknown/FunnelKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  44. CVE-2026-12978High
    FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form
    CVSS 7.1
    Unknown/FunnelKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-12907Low
    RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation
    CVSS 2.7
    Unknown/RTMKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  46. CVE-2026-12906Low
    RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure
    CVSS 2.7
    Unknown/RTMKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-12869Medium
    Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
    CVSS 6.1
    Unknown/Header Footer Builder for Elementorgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-12684Medium
    Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
    CVSS 6.5
    Unknown/Customer Reviews for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  49. CVE-2026-12585High
    Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
    CVSS 8.1
    Unknown/Abandoned Cart Lite for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-12525High
    Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
    CVSS 8.8
    Unknown/Redux Frameworkgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
Page 58 of 327
Previous5657585960Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,851–2,900 of 16,324 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-44632Critical
    Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
    CVSS 9.1
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  2. CVE-2026-44596Medium
    Yamcs: No Rate Limiting on Authentication Endpoint
    CVSS 6.5
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  3. CVE-2026-44595Medium
    Yamcs: Unauthorized user enumeration via IAM API endpoints
    CVSS 4.3
    yamcs/yamcsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  4. CVE-2026-45695Critical
    Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used
    CVSS 9.8
    github.com/kopia/kopia, kopia/kopiageneric · go
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-12379Medium
    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of Axivion
    CVSS 6.8
    Qt/Axiviongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  6. CVE-2026-14890Critical
    CVE-2026-14890
    CVSS 9.1
    SGLang/SGLanggeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  7. CVE-2026-14254High
    Improper Restriction of Excessive Authentication Attempts in Delphix Continuous Data
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  8. CVE-2026-5674High
    Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading
    CVSS 8.8
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-35145Low
    HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.
    CVSS 3.1
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  10. CVE-2026-35143Low
    HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.
    CVSS 3.0
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  11. CVE-2026-35142Low
    HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.
    CVSS 2.6
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  12. CVE-2026-35141Low
    HCL DFXAnalytics is affected by a Login Replay Attack vulnerability
    CVSS 2.6
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  13. CVE-2026-35140Low
    HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
    CVSS 3.0
    HCL Software/DFXAnalyticsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  14. CVE-2024-58360Medium
    stoatchat before 0.7.8 Unrestricted Account Creation
    CVSS 6.5
    stoatchat/stoatchatgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026 Fix availableView HOL analysis
  15. CVE-2025-71388High
    stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions
    CVSS 7.6
    stoatchat/stoatchatgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  16. CVE-2025-71377High
    stoatchat before 20250210-1 Unrestricted Message History Fetch
    CVSS 8.7
    stoatchat/stoatchatgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  17. CVE-2026-12391Medium
    ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs
    CVSS 5.0
    Canonical/ubuntu-pro-client (ubuntu-advantage-tools)generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-11386Critical
    ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
    CVSS 9.0
    Canonical/ubuntu-pro-client (ubuntu-advantage-tools)generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-35147High
    HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.
    CVSS 8.2
    HCL Software/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  20. CVE-2026-35149High
    HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
    CVSS 8.2
    HCL Software/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  21. CVE-2026-35148Medium
    HCL DFXServer is affected by a Missing Access Control vulnerability
    CVSS 6.3
    HCL Software/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  22. CVE-2026-35146Medium
    HCL DFXServer is affected by an Unencrypted Communication vulnerability.
    CVSS 6.3
    HCLSoftware/DFXServergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  23. CVE-2023-49899Critical
    Origin Validation Error in X-Rite MA-T6
    CVSS 9.8
    X-Rite/MA-T6generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026 Fix availableView HOL analysis
  24. CVE-2023-49900Critical
    Origin Validation Error in X-Rite MA-T6
    CVSS 9.8
    X-Rite/MA-T6generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  25. CVE-2026-22752Critical
    Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata
    CVSS 9.6
    Spring Security/Spring Authorization Servergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 21, 2026View HOL analysis
  26. CVE-2026-15324Medium
    SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter
    CVSS 4.4
    phppoet/SysBasics Customize My Account for WooCommerce – Live My Account Customizergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  27. CVE-2026-15103High
    WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter
    CVSS 8.8
    getwpfunnels/WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsellgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  28. CVE-2026-15727Medium
    WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter
    CVSS 4.9
    xylus/WP Bulk Deletegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  29. CVE-2026-15021Medium
    wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field
    CVSS 6.4
    tomdever/wpForo Forumgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  30. CVE-2026-15005High
    Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter
    CVSS 8.8
    timwhitlock/Loco Translategeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  31. CVE-2026-13741High
    Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter
    CVSS 8.8
    UnitedOver/Digits: WordPress Mobile Number Signup and Logingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  32. CVE-2026-13755Medium
    Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute
    CVSS 6.4
    tickera/Tickera – Sell Tickets & Manage Eventsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  33. CVE-2026-15610Medium
    WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function
    CVSS 4.3
    quantumcloud/WPBot – AI ChatBot for Live Support, Lead Generation, AI Servicesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  34. CVE-2026-15106Medium
    WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter
    CVSS 5.3
    quantumcloud/WPBot – AI ChatBot for Live Support, Lead Generation, AI Servicesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  35. CVE-2026-15407Medium
    Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action
    CVSS 4.3
    themifyme/Themify Buildergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  36. CVE-2026-15651Medium
    WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter
    CVSS 4.9
    jgwhite33/WP TripAdvisor Review Slidergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  37. CVE-2026-15008High
    Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token
    CVSS 8.1
    uncannyowl/Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  38. CVE-2026-15022Medium
    Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array
    CVSS 6.5
    themeum/Tutor LMS – eLearning and online course solutiongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  39. CVE-2026-13754Medium
    Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter
    CVSS 6.5
    tickera/Tickera – Sell Tickets & Manage Eventsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  40. CVE-2026-13767Medium
    Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter
    CVSS 6.5
    expresstech/Quiz and Survey Master (QSM) – Quiz Maker & Survey Makergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  41. CVE-2026-15350Medium
    The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter
    CVSS 4.3
    kevp75/The Cache Purgergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  42. CVE-2026-15099Medium
    WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute
    CVSS 6.4
    wpdelicious/WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)generic
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  43. CVE-2026-12979Medium
    FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
    CVSS 5.5
    Unknown/FunnelKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  44. CVE-2026-12978High
    FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form
    CVSS 7.1
    Unknown/FunnelKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  45. CVE-2026-12907Low
    RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation
    CVSS 2.7
    Unknown/RTMKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  46. CVE-2026-12906Low
    RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure
    CVSS 2.7
    Unknown/RTMKitgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-12869Medium
    Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
    CVSS 6.1
    Unknown/Header Footer Builder for Elementorgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-12684Medium
    Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
    CVSS 6.5
    Unknown/Customer Reviews for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  49. CVE-2026-12585High
    Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
    CVSS 8.1
    Unknown/Abandoned Cart Lite for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-12525High
    Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
    CVSS 8.8
    Unknown/Redux Frameworkgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
Page 58 of 327
Previous5657585960Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard