1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 10:25 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 10:25 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 251–300 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-67622Critical
    Flowise 3.1.4 IDOR in OpenAI Assistants Integration
    CVSS 9.9
    FlowiseAI/Flowisegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-67434High
    PHP_CodeSniffer gitblame report command injection via crafted filename
    CVSS 7.3
    PHPCSStandards/PHP_CodeSniffer, squizlabs/php_codesniffercomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-67621High
    Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
    CVSS 7.6
    FlowiseAI/Flowisegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2026-48086Critical
    OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN
    CVSS 9.9
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-48085Critical
    OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap
    CVSS 9.8
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-70632High
    FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing
    CVSS 7.8
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-71498Medium
    node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
    CVSS 5.1
    re2, uhop/node-re2generic · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  8. CVE-2026-70631Medium
    FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder
    CVSS 5.5
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-47765High
    Frappe: Lack of Permissions in restore/bulk_restore
    CVSS 7.1
    frappe/frappegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-70630Medium
    FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder
    CVSS 5.5
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-70629Medium
    FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder
    CVSS 5.5
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-70628High
    FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File
    CVSS 7.8
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-71430Medium
    node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
    CVSS 6.2
    re2, uhop/node-re2generic · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-47194High
    Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain
    CVSS 8.6
    frappe/frappegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-48084High
    OpenReception doesn't rate limit passphrase login attempts
    CVSS 7.4
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-48083Medium
    OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits
    CVSS 6.5
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  17. CVE-2026-48082Low
    OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplification
    CVSS 3.7
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-48081High
    OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer
    CVSS 8.1
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-71497Medium
    jsoup: Cleaner may expose markup with custom raw-text elements
    CVSS 4.7
    jhy/jsoup, org.jsoup:jsoupgeneric · maven
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-47185Medium
    Frappe Has Broken Access Control in its Workspace Save API
    CVSS 5.1
    frappe/frappegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-62857High
    Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources
    CVSS 8.8
    fedify-dev/fedifygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  22. CVE-2026-48079High
    OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry
    CVSS 7.4
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-61632Medium
    PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
    CVSS 5.3
    facelessuser/pymdown-extensionsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-48078Medium
    OpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callers
    CVSS 5.3
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  25. CVE-2026-48077Medium
    OpenReception: GET appointment by ID returns full appointment record without authorization
    CVSS 5.3
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-19110Low
    DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
    CVSS 2.4
    n/a/DataGeargeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  27. CVE-2026-48076Medium
    OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channels
    CVSS 6.5
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-48075Medium
    OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injections
    CVSS 6.5
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-71488High
    league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
    CVSS 7.5
    league/commonmark, thephpleague/commonmarkcomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19177High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  31. CVE-2026-19176High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  32. CVE-2026-19175Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-19174High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-19173High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-19171Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-19167Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2026-19166Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-19165High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-19164Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-19163High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-19162High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-19161Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-19160Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-19159High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-19158High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  46. CVE-2026-19156High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  47. CVE-2026-19155High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-19153High
    CISA ADP Vulnrichment
    CVSS 8.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-19152High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  50. CVE-2026-19151High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 6 of 325
Previous45678Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 251–300 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-67622Critical
    Flowise 3.1.4 IDOR in OpenAI Assistants Integration
    CVSS 9.9
    FlowiseAI/Flowisegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-67434High
    PHP_CodeSniffer gitblame report command injection via crafted filename
    CVSS 7.3
    PHPCSStandards/PHP_CodeSniffer, squizlabs/php_codesniffercomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-67621High
    Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
    CVSS 7.6
    FlowiseAI/Flowisegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  4. CVE-2026-48086Critical
    OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN
    CVSS 9.9
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-48085Critical
    OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap
    CVSS 9.8
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-70632High
    FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing
    CVSS 7.8
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-71498Medium
    node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
    CVSS 5.1
    re2, uhop/node-re2generic · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  8. CVE-2026-70631Medium
    FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder
    CVSS 5.5
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-47765High
    Frappe: Lack of Permissions in restore/bulk_restore
    CVSS 7.1
    frappe/frappegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-70630Medium
    FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder
    CVSS 5.5
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-70629Medium
    FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder
    CVSS 5.5
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-70628High
    FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File
    CVSS 7.8
    FFmpeg/FFmpeggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-71430Medium
    node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
    CVSS 6.2
    re2, uhop/node-re2generic · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-47194High
    Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain
    CVSS 8.6
    frappe/frappegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-48084High
    OpenReception doesn't rate limit passphrase login attempts
    CVSS 7.4
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-48083Medium
    OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits
    CVSS 6.5
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  17. CVE-2026-48082Low
    OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplification
    CVSS 3.7
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  18. CVE-2026-48081High
    OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer
    CVSS 8.1
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-71497Medium
    jsoup: Cleaner may expose markup with custom raw-text elements
    CVSS 4.7
    jhy/jsoup, org.jsoup:jsoupgeneric · maven
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-47185Medium
    Frappe Has Broken Access Control in its Workspace Save API
    CVSS 5.1
    frappe/frappegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-62857High
    Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources
    CVSS 8.8
    fedify-dev/fedifygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  22. CVE-2026-48079High
    OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry
    CVSS 7.4
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-61632Medium
    PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
    CVSS 5.3
    facelessuser/pymdown-extensionsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-48078Medium
    OpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callers
    CVSS 5.3
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  25. CVE-2026-48077Medium
    OpenReception: GET appointment by ID returns full appointment record without authorization
    CVSS 5.3
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-19110Low
    DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
    CVSS 2.4
    n/a/DataGeargeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  27. CVE-2026-48076Medium
    OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channels
    CVSS 6.5
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  28. CVE-2026-48075Medium
    OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injections
    CVSS 6.5
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-71488High
    league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
    CVSS 7.5
    league/commonmark, thephpleague/commonmarkcomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19177High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  31. CVE-2026-19176High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  32. CVE-2026-19175Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-19174High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-19173High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  35. CVE-2026-19171Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  36. CVE-2026-19167Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2026-19166Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  38. CVE-2026-19165High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-19164Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-19163High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-19162High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-19161Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-19160Low
    CISA ADP Vulnrichment
    CVSS 3.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-19159High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-19158High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  46. CVE-2026-19156High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  47. CVE-2026-19155High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-19153High
    CISA ADP Vulnrichment
    CVSS 8.1
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-19152High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  50. CVE-2026-19151High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 6 of 325
Previous45678Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard