1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 2:15 PM 16,332 active 1,443 known exploited

Catalog summary

16,332

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 2:15 PM 16,332 active 1,443 known exploited

Catalog summary

16,332

Active CVEs

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,251–3,300 of 16,332 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-44768Medium
    Security misconfiguration in SAP CRM (WebClient UI)
    CVSS 4.1
    SAP_SE/SAP CRM (WebClient UI)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-44761Critical
    Insecure Sample Credentials in SAP Commerce Cloud
    CVSS 9.1
    SAP_SE/SAP Commerce Cloudgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-44760Medium
    Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)
    CVSS 4.7
    SAP_SE/SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  4. CVE-2026-44759Medium
    Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
    CVSS 6.1
    SAP_SE/SAP NetWeaver Enterprise Portalgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  5. CVE-2026-44753Low
    Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)
    CVSS 3.7
    SAP_SE/SAP HANA Extended Application Services classic model (User Self Service)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  6. CVE-2026-44752High
    Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)
    CVSS 8.2
    SAP_SE/SAP NetWeaver Application Server Java(Configuration Wizard)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  7. CVE-2026-44747Critical
    Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
    CVSS 9.9
    SAP_SE/SAP NetWeaver Application Server ABAPgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 29, 2026View HOL analysis
  8. CVE-2026-44745High
    Open Redirect vulnerability in SAP Approuter
    CVSS 8.1
    SAP_SE/SAP Approutergeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  9. CVE-2026-27690Critical
    HTTP Request Smuggling in SAP Approuter
    CVSS 9.1
    SAP_SE/SAP Approutergeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  10. CVE-2026-0487High
    DLL Hijacking vulnerability in SAProuter on Microsoft Windows
    CVSS 8.4
    SAP_SE/SAProuter on Microsoft Windowsgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 20, 2026View HOL analysis
  11. CVE-2026-15620Medium
    mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  12. CVE-2026-15619Medium
    mosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2025-56361High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2025-56362High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2025-56363High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2025-56364High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  17. CVE-2025-56365High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-36035Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-36214Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    osTicket/osTicketgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  20. CVE-2026-38450Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-15618Medium
    mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanism
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  22. CVE-2026-15607Medium
    tanstack db Alias Path select.ts select prototype pollution
    CVSS 4.3
    tanstack/dbgeneric
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-15605Low
    wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
    CVSS 3.1
    n/a/wandbgeneric
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  24. CVE-2026-58101High
    Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference
    CVSS 7.5
    JONASBN/Crypt::OpenSSL::X509generic
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-15598Medium
    antv layout object.js setNestedValue prototype pollution
    CVSS 6.3
    antv/layoutgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  26. CVE-2026-15597High
    SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  27. CVE-2026-58488Medium
    HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
    CVSS 6.9
    hedgedoc/hedgedocgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  28. CVE-2026-15680Unknown severity
    Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    Lorex/2K Indoor Wi-Fi Security Camerageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2026-15681Unknown severity
    AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
    Not scoredSource severity not reported
    AnyDesk/AnyDeskgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  30. CVE-2026-15682Unknown severity
    AnyDesk Support Information Link Following Denial-of-Service Vulnerability
    Not scoredSource severity not reported
    AnyDesk/AnyDeskgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  31. CVE-2026-15683Unknown severity
    Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability
    Not scoredSource severity not reported
    Lorex/2K Indoor Wi-Fi Security Camerageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  32. CVE-2026-15684Unknown severity
    Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability
    Not scoredSource severity not reported
    Glarysoft/Glary Utilitiesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  33. CVE-2026-15685Unknown severity
    Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
    Not scoredSource severity not reported
    Ollama/Ollamageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  34. CVE-2026-15596Medium
    SourceCodester Class and Exam Timetabling System subject.php cross site scripting
    CVSS 4.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-15595Medium
    SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting
    CVSS 4.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  36. CVE-2026-15594Low
    waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
    CVSS 3.7
    waooAI/waoowaoogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-12385Medium
    Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter
    CVSS 4.3
    nextendweb/Smart Slider 3generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  38. CVE-2026-12536Medium
    Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title
    CVSS 6.4
    themefusion/Avada (Fusion) Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  39. CVE-2026-14906Medium
    Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-6875Critical
    Sandbox Escape in ServiceNow AI Platform
    CVSS 9.5
    ServiceNow/ServiceNow AI Platformgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  41. CVE-2026-58228Medium
    Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
    CVSS 5.1
    phoenixframework/phoenix_live_viewgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-13221Critical
    Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
    CVSS 9.1
    SHAY/perlgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  43. CVE-2026-40553High
    Stack-based buffer overflow in gawk
    CVSS 7.5
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  44. CVE-2026-40469Critical
    Heap buffer overflow in gawk
    CVSS 9.1
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  45. CVE-2026-40468Critical
    Heap buffer overflow in gawk
    CVSS 9.1
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  46. CVE-2026-40467High
    Use after free in gawk
    CVSS 7.5
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  47. CVE-2026-15584High
    Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  48. CVE-2026-15559Medium
    CodeAstro Simple Online Leave Management System POST accept.php sql injection
    CVSS 6.3
    CodeAstro/Simple Online Leave Management Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-62147Medium
    Tempo-operator: tempo operator: query rbac bypass
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-15558Medium
    CodeAstro Simple Online Leave Management System deletemp.php sql injection
    CVSS 6.3
    CodeAstro/Simple Online Leave Management Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 66 of 327
Previous6465666768Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,251–3,300 of 16,332 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-44768Medium
    Security misconfiguration in SAP CRM (WebClient UI)
    CVSS 4.1
    SAP_SE/SAP CRM (WebClient UI)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-44761Critical
    Insecure Sample Credentials in SAP Commerce Cloud
    CVSS 9.1
    SAP_SE/SAP Commerce Cloudgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  3. CVE-2026-44760Medium
    Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)
    CVSS 4.7
    SAP_SE/SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  4. CVE-2026-44759Medium
    Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
    CVSS 6.1
    SAP_SE/SAP NetWeaver Enterprise Portalgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  5. CVE-2026-44753Low
    Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)
    CVSS 3.7
    SAP_SE/SAP HANA Extended Application Services classic model (User Self Service)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  6. CVE-2026-44752High
    Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)
    CVSS 8.2
    SAP_SE/SAP NetWeaver Application Server Java(Configuration Wizard)generic
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  7. CVE-2026-44747Critical
    Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
    CVSS 9.9
    SAP_SE/SAP NetWeaver Application Server ABAPgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 29, 2026View HOL analysis
  8. CVE-2026-44745High
    Open Redirect vulnerability in SAP Approuter
    CVSS 8.1
    SAP_SE/SAP Approutergeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  9. CVE-2026-27690Critical
    HTTP Request Smuggling in SAP Approuter
    CVSS 9.1
    SAP_SE/SAP Approutergeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  10. CVE-2026-0487High
    DLL Hijacking vulnerability in SAProuter on Microsoft Windows
    CVSS 8.4
    SAP_SE/SAProuter on Microsoft Windowsgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 20, 2026View HOL analysis
  11. CVE-2026-15620Medium
    mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  12. CVE-2026-15619Medium
    mosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 14, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  13. CVE-2025-56361High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  14. CVE-2025-56362High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  15. CVE-2025-56363High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2025-56364High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  17. CVE-2025-56365High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  18. CVE-2026-36035Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  19. CVE-2026-36214Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    osTicket/osTicketgeneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  20. CVE-2026-38450Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 14, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  21. CVE-2026-15618Medium
    mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanism
    CVSS 6.3
    mosaxiv/clawletgeneric
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  22. CVE-2026-15607Medium
    tanstack db Alias Path select.ts select prototype pollution
    CVSS 4.3
    tanstack/dbgeneric
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 15, 2026View HOL analysis
  23. CVE-2026-15605Low
    wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
    CVSS 3.1
    n/a/wandbgeneric
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026View HOL analysis
  24. CVE-2026-58101High
    Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference
    CVSS 7.5
    JONASBN/Crypt::OpenSSL::X509generic
    PublishedJul 13, 2026First seen at HOL Jul 14, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  25. CVE-2026-15598Medium
    antv layout object.js setNestedValue prototype pollution
    CVSS 6.3
    antv/layoutgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  26. CVE-2026-15597High
    SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  27. CVE-2026-58488Medium
    HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
    CVSS 6.9
    hedgedoc/hedgedocgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  28. CVE-2026-15680Unknown severity
    Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability
    Not scoredSource severity not reported
    Lorex/2K Indoor Wi-Fi Security Camerageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2026-15681Unknown severity
    AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
    Not scoredSource severity not reported
    AnyDesk/AnyDeskgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  30. CVE-2026-15682Unknown severity
    AnyDesk Support Information Link Following Denial-of-Service Vulnerability
    Not scoredSource severity not reported
    AnyDesk/AnyDeskgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  31. CVE-2026-15683Unknown severity
    Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability
    Not scoredSource severity not reported
    Lorex/2K Indoor Wi-Fi Security Camerageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  32. CVE-2026-15684Unknown severity
    Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability
    Not scoredSource severity not reported
    Glarysoft/Glary Utilitiesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  33. CVE-2026-15685Unknown severity
    Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
    Not scoredSource severity not reported
    Ollama/Ollamageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  34. CVE-2026-15596Medium
    SourceCodester Class and Exam Timetabling System subject.php cross site scripting
    CVSS 4.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  35. CVE-2026-15595Medium
    SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting
    CVSS 4.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  36. CVE-2026-15594Low
    waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
    CVSS 3.7
    waooAI/waoowaoogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-12385Medium
    Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter
    CVSS 4.3
    nextendweb/Smart Slider 3generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  38. CVE-2026-12536Medium
    Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title
    CVSS 6.4
    themefusion/Avada (Fusion) Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  39. CVE-2026-14906Medium
    Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-6875Critical
    Sandbox Escape in ServiceNow AI Platform
    CVSS 9.5
    ServiceNow/ServiceNow AI Platformgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  41. CVE-2026-58228Medium
    Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
    CVSS 5.1
    phoenixframework/phoenix_live_viewgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  42. CVE-2026-13221Critical
    Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
    CVSS 9.1
    SHAY/perlgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  43. CVE-2026-40553High
    Stack-based buffer overflow in gawk
    CVSS 7.5
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  44. CVE-2026-40469Critical
    Heap buffer overflow in gawk
    CVSS 9.1
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  45. CVE-2026-40468Critical
    Heap buffer overflow in gawk
    CVSS 9.1
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  46. CVE-2026-40467High
    Use after free in gawk
    CVSS 7.5
    GNU/gawkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  47. CVE-2026-15584High
    Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  48. CVE-2026-15559Medium
    CodeAstro Simple Online Leave Management System POST accept.php sql injection
    CVSS 6.3
    CodeAstro/Simple Online Leave Management Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-62147Medium
    Tempo-operator: tempo operator: query rbac bypass
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-15558Medium
    CodeAstro Simple Online Leave Management System deletemp.php sql injection
    CVSS 6.3
    CodeAstro/Simple Online Leave Management Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 66 of 327
Previous6465666768Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard