1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:35 AM 16,324 active 1,443 known exploited

Catalog summary

16,324

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:35 AM 16,324 active 1,443 known exploited

Catalog summary

16,324

Active CVEs

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,901–2,950 of 16,324 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12510Medium
    AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
    CVSS 5.9
    Unknown/AI Enginegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-12492Critical
    Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
    CVSS 9.8
    Unknown/Happy Coders OTP Login for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-12395Medium
    WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter
    CVSS 6.5
    Unknown/WP Job Portalgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-11866Medium
    LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
    CVSS 5.4
    Unknown/Appointment Booking Plugingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-11371Medium
    BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
    CVSS 6.1
    Unknown/BetterDocsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  6. CVE-2026-15925Critical
    Improper TLS Hostname Verification in Snowflake Connector for Python
    CVSS 9.2
    Snowflake/Snowflake Connector for Pythongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-53366Unknown severity
    ipv4: account for fraggap on the paged allocation path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-15458Medium
    SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter
    CVSS 4.9
    cleverplugins/SEO Boostergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  9. CVE-2026-15013Critical
    SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
    CVSS 9.8
    cyberlord92/SAML Single Sign On – SSO Logingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-13042High
    RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content
    CVSS 7.2
    yo35/RPB Chessboardgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  11. CVE-2026-15445Medium
    SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
    CVSS 4.9
    cleverplugins/SEO Boostergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  12. CVE-2026-15306Medium
    Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter
    CVSS 6.1
    rextheme/Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplacesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  13. CVE-2026-21729High
    Loki detected_fields query limits results in unbounded memory allocation
    CVSS 7.5
    Grafana/Lokigeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  14. CVE-2026-15652Medium
    Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute
    CVSS 6.4
    shapedplugin/Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  15. CVE-2026-12941Medium
    MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter
    CVSS 6.5
    wcmp/MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutionsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  16. CVE-2026-14987Medium
    GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
    CVSS 6.4
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  17. CVE-2026-12409Medium
    Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action
    CVSS 4.3
    umarbajwa/Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pagesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  18. CVE-2026-12753High
    Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter
    CVSS 7.5
    themehunk/Advance Product Search- Voice & Ajax Search for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  19. CVE-2026-12434Medium
    List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute
    CVSS 4.3
    fernandobt/List category postsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  20. CVE-2026-15336Medium
    Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter
    CVSS 4.3
    catchplugins/Catch Themes Demo Importgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  21. CVE-2026-13005Medium
    MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting
    CVSS 4.4
    mxchat/MxChat – AI Chatbot & Content Generation for WordPressgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  22. CVE-2026-1609High
    Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users
    CVSS 8.1
    Keycloak/Keycloakgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-3842High
    Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  24. CVE-2026-15909Medium
    RafyMrX TOKO-ONLINE-ROTI add.php authorization
    CVSS 6.3
    RafyMrX/TOKO-ONLINE-ROTIgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  25. CVE-2026-23538High
    Feast: resource exhaustion via websocket endpoint
    CVSS 7.5
    Feast/Feast Feature Servergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  26. CVE-2021-27137High
    CISA ADP Vulnrichment
    CVSS 8.1 Known exploited
    DD-WRT/DD-WRTgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  27. CVE-2024-32385Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2024-32386High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  29. CVE-2024-32387Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  30. CVE-2024-32389Low
    CISA ADP Vulnrichment
    CVSS 3.5
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  31. CVE-2024-34268High
    CISA ADP Vulnrichment
    CVSS 7.1
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  32. CVE-2025-45868Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026View HOL analysis
  33. CVE-2025-45870Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026View HOL analysis
  34. CVE-2026-36425Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  35. CVE-2026-38158Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  36. CVE-2026-47081Low
    CISA ADP Vulnrichment
    CVSS 3.1
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-47082Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-47083Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  39. CVE-2026-47084Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-47085Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  41. CVE-2026-47086Low
    CISA ADP Vulnrichment
    CVSS 3.5
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-47087Low
    CISA ADP Vulnrichment
    CVSS 3.5
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  43. CVE-2026-47088Low
    CISA ADP Vulnrichment
    CVSS 3.1
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  44. CVE-2026-47089Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  45. CVE-2026-15907High
    H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
    CVSS 7.3
    H3C/SecPath F1000-C8300generic
    PublishedJul 15, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  46. CVE-2026-45313High
    Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape
    CVSS 7.7
    sandboxie-plus/Sandboxiegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  47. CVE-2026-15921Low
    nvm path traversal via a malicious mirror's LTS codename writes outside the alias directory
    CVSS 3.1
    nvm-sh/nvmgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-46339Critical
    9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
    CVSS 10.0
    decolua/9routergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  49. CVE-2026-33445High
    Memory management vulnerability in Secure Access servers
    CVSS 8.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-33444Medium
    Memory management vulnerability in Secure Access servers
    CVSS 6.9
    Absolute Secutity/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
Page 59 of 327
Previous5758596061Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,901–2,950 of 16,324 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12510Medium
    AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
    CVSS 5.9
    Unknown/AI Enginegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-12492Critical
    Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
    CVSS 9.8
    Unknown/Happy Coders OTP Login for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-12395Medium
    WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter
    CVSS 6.5
    Unknown/WP Job Portalgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-11866Medium
    LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
    CVSS 5.4
    Unknown/Appointment Booking Plugingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-11371Medium
    BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
    CVSS 6.1
    Unknown/BetterDocsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  6. CVE-2026-15925Critical
    Improper TLS Hostname Verification in Snowflake Connector for Python
    CVSS 9.2
    Snowflake/Snowflake Connector for Pythongeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-53366Unknown severity
    ipv4: account for fraggap on the paged allocation path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-15458Medium
    SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter
    CVSS 4.9
    cleverplugins/SEO Boostergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  9. CVE-2026-15013Critical
    SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
    CVSS 9.8
    cyberlord92/SAML Single Sign On – SSO Logingeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-13042High
    RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content
    CVSS 7.2
    yo35/RPB Chessboardgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  11. CVE-2026-15445Medium
    SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
    CVSS 4.9
    cleverplugins/SEO Boostergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  12. CVE-2026-15306Medium
    Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter
    CVSS 6.1
    rextheme/Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplacesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  13. CVE-2026-21729High
    Loki detected_fields query limits results in unbounded memory allocation
    CVSS 7.5
    Grafana/Lokigeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 29, 2026 Fix availableView HOL analysis
  14. CVE-2026-15652Medium
    Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute
    CVSS 6.4
    shapedplugin/Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  15. CVE-2026-12941Medium
    MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter
    CVSS 6.5
    wcmp/MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutionsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  16. CVE-2026-14987Medium
    GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
    CVSS 6.4
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  17. CVE-2026-12409Medium
    Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action
    CVSS 4.3
    umarbajwa/Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pagesgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  18. CVE-2026-12753High
    Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter
    CVSS 7.5
    themehunk/Advance Product Search- Voice & Ajax Search for WooCommercegeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 18, 2026View HOL analysis
  19. CVE-2026-12434Medium
    List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute
    CVSS 4.3
    fernandobt/List category postsgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  20. CVE-2026-15336Medium
    Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter
    CVSS 4.3
    catchplugins/Catch Themes Demo Importgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026View HOL analysis
  21. CVE-2026-13005Medium
    MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting
    CVSS 4.4
    mxchat/MxChat – AI Chatbot & Content Generation for WordPressgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  22. CVE-2026-1609High
    Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users
    CVSS 8.1
    Keycloak/Keycloakgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-3842High
    Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  24. CVE-2026-15909Medium
    RafyMrX TOKO-ONLINE-ROTI add.php authorization
    CVSS 6.3
    RafyMrX/TOKO-ONLINE-ROTIgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  25. CVE-2026-23538High
    Feast: resource exhaustion via websocket endpoint
    CVSS 7.5
    Feast/Feast Feature Servergeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  26. CVE-2021-27137High
    CISA ADP Vulnrichment
    CVSS 8.1 Known exploited
    DD-WRT/DD-WRTgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  27. CVE-2024-32385Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  28. CVE-2024-32386High
    CISA ADP Vulnrichment
    CVSS 7.3
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  29. CVE-2024-32387Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  30. CVE-2024-32389Low
    CISA ADP Vulnrichment
    CVSS 3.5
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  31. CVE-2024-34268High
    CISA ADP Vulnrichment
    CVSS 7.1
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  32. CVE-2025-45868Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026View HOL analysis
  33. CVE-2025-45870Unknown severity
    CISA ADP Vulnrichment
    Not scoredSource severity not reported
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 20, 2026View HOL analysis
  34. CVE-2026-36425Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  35. CVE-2026-38158Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 16, 2026First seen at HOL Jul 17, 2026Updated Jul 17, 2026View HOL analysis
  36. CVE-2026-47081Low
    CISA ADP Vulnrichment
    CVSS 3.1
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  37. CVE-2026-47082Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  38. CVE-2026-47083Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  39. CVE-2026-47084Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  40. CVE-2026-47085Medium
    CISA ADP Vulnrichment
    CVSS 4.0
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  41. CVE-2026-47086Low
    CISA ADP Vulnrichment
    CVSS 3.5
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  42. CVE-2026-47087Low
    CISA ADP Vulnrichment
    CVSS 3.5
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  43. CVE-2026-47088Low
    CISA ADP Vulnrichment
    CVSS 3.1
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  44. CVE-2026-47089Medium
    CISA ADP Vulnrichment
    CVSS 4.3
    cyrusimap/Cyrus IMAPgeneric
    PublishedJul 16, 2026First seen at HOL Jul 16, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  45. CVE-2026-15907High
    H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
    CVSS 7.3
    H3C/SecPath F1000-C8300generic
    PublishedJul 15, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026View HOL analysis
  46. CVE-2026-45313High
    Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape
    CVSS 7.7
    sandboxie-plus/Sandboxiegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  47. CVE-2026-15921Low
    nvm path traversal via a malicious mirror's LTS codename writes outside the alias directory
    CVSS 3.1
    nvm-sh/nvmgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-46339Critical
    9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
    CVSS 10.0
    decolua/9routergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  49. CVE-2026-33445High
    Memory management vulnerability in Secure Access servers
    CVSS 8.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  50. CVE-2026-33444Medium
    Memory management vulnerability in Secure Access servers
    CVSS 6.9
    Absolute Secutity/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
Page 59 of 327
Previous5758596061Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard