1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 2:20 PM 16,332 active 1,443 known exploited

Catalog summary

16,332

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 2:20 PM 16,332 active 1,443 known exploited

Catalog summary

16,332

Active CVEs

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,301–3,350 of 16,332 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12257Critical
    Remote code execution in Mura Software’s CMS
    CVSS 9.3
    Mura Software/CMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-6541Medium
    Unscoped updates to other playbooks' metric configuration
    CVSS 4.3
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-9820Low
    Mattermost schemes teams endpoint exposes private team invite IDs
    CVSS 3.8
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-9824Medium
    Remote cluster metadata enumeration via /share-channel autocomplete
    CVSS 4.3
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-14934Critical
    Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise
    CVSS 9.4
    Google Cloud/BigQuery, Google Cloud/Colab Enterprise +1generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-4765Medium
    Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas
    CVSS 5.1
    RD Station Conversas/Tallos Chatgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-13014Critical
    Remote Code Execution vulnerability in "Suspicious" application
    CVSS 9.2
    Thales CERT/Suspiciousgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-14846Medium
    Incorrect neutralisation in the PrestaShop firmware
    CVSS 4.5
    PrestaShop/The firmwaregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-15557High
    waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authentication
    CVSS 7.3
    waooAI/waoowaoogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-22103Critical
    Command injection in NPC start web endpoint
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  11. CVE-2026-22098Critical
    Sensitive information is written to logs
    CVSS 9.2
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  12. CVE-2026-22097Critical
    Missing firmware validation allows remote code execution
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-22099High
    Missing authentication for Bluetooth communication
    CVSS 8.7
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  14. CVE-2026-22102Critical
    Arbitrary file overwrite through certificate update functionality
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  15. CVE-2026-22096Critical
    Missing authentication for webserver endpoints
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  16. CVE-2026-22100High
    Comnand injection in OCPP ReserveLogin message
    CVSS 8.6
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-22095Critical
    Command injection in diagnosis web endpoint
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-22093Critical
    Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app
    CVSS 9.5
    EVbee/EVbee Servicegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-41041Critical
    Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
    CVSS 9.1
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  20. CVE-2026-49876Medium
    Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs
    CVSS 6.5
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-15548High
    Shibby Tomato DNS List Rendering httpd sub_407220 stack-based overflow
    CVSS 8.8
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-61985Medium
    WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerability
    CVSS 5.3
    magepeopleteam/Car Rental Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-61977Medium
    WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Crocoblock/JetSearchgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-61983Medium
    WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability
    CVSS 5.3
    andy_moyle/Church Admingeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-61976Medium
    WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Crocoblock/JetBlocks For Elementorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-61975Medium
    WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Crocoblock/JetReviewsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-61971Low
    WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 2.7
    Cozmoslabs/User Profile Picturegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-61970Medium
    WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 4.9
    Themeisle/Auto Featured Image (Auto Post Thumbnail)generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-61968Medium
    WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability
    CVSS 5.4
    Saad Iqbal/myCredgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-61958Medium
    WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability
    CVSS 5.4
    Saad Iqbal/License Manager for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-61956High
    WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 7.1
    hamsalam/ووسلام &#8211; همگام سازی ووکامرس و باسلامgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-61955High
    WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability
    CVSS 7.6
    Hannan/گرویتی فرم فارسیgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-59523Medium
    WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
    CVSS 6.5
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-61952Medium
    WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 - Broken Access Control vulnerability
    CVSS 4.9
    Jose Vega/WooCommerce Bulk Edit Products – WP Sheet Editorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-59521High
    WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerability
    CVSS 7.2
    ShapedPlugin LLC/Real Testimonialsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-59518Critical
    WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability
    CVSS 9.8
    wpWax/Directoristgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-59516High
    WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Room 34 Creative Services, LLC/ICS Calendargeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-59515Critical
    WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability
    CVSS 9.3
    Sergey/AIWUgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57816High
    WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    FunnelKit/Funnel Builder by FunnelKitgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57815High
    WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
    CVSS 7.5
    WPMU DEV - Your All-in-One WordPress Platform/Forminatorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57814High
    WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPMU DEV - Your All-in-One WordPress Platform/Forminatorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57813Critical
    WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
    CVSS 9.8
    properfraction/MailOptingeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57812Medium
    WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
    CVSS 6.5
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57811Critical
    WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
    CVSS 10.0
    Realtyna/Realtyna Organic IDX plugingeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57810High
    WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection vulnerability
    CVSS 8.5
    Saad Iqbal/APIExperts Square for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-57805High
    WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/Tondageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-57803High
    WordPress Struktur Core plugin <= 2.5.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/Struktur Coregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-57802High
    WordPress Struktur theme <= 2.5.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/Strukturgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-57801High
    WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/SetSailgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-57800High
    WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability
    CVSS 7.5
    Edge-Themes/Overworldgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 67 of 327
Previous6566676869Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,301–3,350 of 16,332 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12257Critical
    Remote code execution in Mura Software’s CMS
    CVSS 9.3
    Mura Software/CMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-6541Medium
    Unscoped updates to other playbooks' metric configuration
    CVSS 4.3
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-9820Low
    Mattermost schemes teams endpoint exposes private team invite IDs
    CVSS 3.8
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-9824Medium
    Remote cluster metadata enumeration via /share-channel autocomplete
    CVSS 4.3
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-14934Critical
    Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise
    CVSS 9.4
    Google Cloud/BigQuery, Google Cloud/Colab Enterprise +1generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-4765Medium
    Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas
    CVSS 5.1
    RD Station Conversas/Tallos Chatgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-13014Critical
    Remote Code Execution vulnerability in "Suspicious" application
    CVSS 9.2
    Thales CERT/Suspiciousgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-14846Medium
    Incorrect neutralisation in the PrestaShop firmware
    CVSS 4.5
    PrestaShop/The firmwaregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-15557High
    waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authentication
    CVSS 7.3
    waooAI/waoowaoogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-22103Critical
    Command injection in NPC start web endpoint
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  11. CVE-2026-22098Critical
    Sensitive information is written to logs
    CVSS 9.2
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  12. CVE-2026-22097Critical
    Missing firmware validation allows remote code execution
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-22099High
    Missing authentication for Bluetooth communication
    CVSS 8.7
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  14. CVE-2026-22102Critical
    Arbitrary file overwrite through certificate update functionality
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  15. CVE-2026-22096Critical
    Missing authentication for webserver endpoints
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  16. CVE-2026-22100High
    Comnand injection in OCPP ReserveLogin message
    CVSS 8.6
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-22095Critical
    Command injection in diagnosis web endpoint
    CVSS 9.3
    EVbee/DC-80generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-22093Critical
    Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app
    CVSS 9.5
    EVbee/EVbee Servicegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-41041Critical
    Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
    CVSS 9.1
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  20. CVE-2026-49876Medium
    Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs
    CVSS 6.5
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-15548High
    Shibby Tomato DNS List Rendering httpd sub_407220 stack-based overflow
    CVSS 8.8
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-61985Medium
    WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerability
    CVSS 5.3
    magepeopleteam/Car Rental Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-61977Medium
    WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Crocoblock/JetSearchgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-61983Medium
    WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability
    CVSS 5.3
    andy_moyle/Church Admingeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-61976Medium
    WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Crocoblock/JetBlocks For Elementorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-61975Medium
    WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
    CVSS 5.3
    Crocoblock/JetReviewsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-61971Low
    WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 2.7
    Cozmoslabs/User Profile Picturegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-61970Medium
    WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 4.9
    Themeisle/Auto Featured Image (Auto Post Thumbnail)generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-61968Medium
    WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability
    CVSS 5.4
    Saad Iqbal/myCredgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-61958Medium
    WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability
    CVSS 5.4
    Saad Iqbal/License Manager for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-61956High
    WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability
    CVSS 7.1
    hamsalam/ووسلام &#8211; همگام سازی ووکامرس و باسلامgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-61955High
    WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability
    CVSS 7.6
    Hannan/گرویتی فرم فارسیgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-59523Medium
    WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
    CVSS 6.5
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-61952Medium
    WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 - Broken Access Control vulnerability
    CVSS 4.9
    Jose Vega/WooCommerce Bulk Edit Products – WP Sheet Editorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-59521High
    WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerability
    CVSS 7.2
    ShapedPlugin LLC/Real Testimonialsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-59518Critical
    WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability
    CVSS 9.8
    wpWax/Directoristgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-59516High
    WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Room 34 Creative Services, LLC/ICS Calendargeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-59515Critical
    WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability
    CVSS 9.3
    Sergey/AIWUgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57816High
    WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    FunnelKit/Funnel Builder by FunnelKitgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57815High
    WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
    CVSS 7.5
    WPMU DEV - Your All-in-One WordPress Platform/Forminatorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57814High
    WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPMU DEV - Your All-in-One WordPress Platform/Forminatorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57813Critical
    WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
    CVSS 9.8
    properfraction/MailOptingeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57812Medium
    WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
    CVSS 6.5
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57811Critical
    WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
    CVSS 10.0
    Realtyna/Realtyna Organic IDX plugingeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57810High
    WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection vulnerability
    CVSS 8.5
    Saad Iqbal/APIExperts Square for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-57805High
    WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/Tondageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-57803High
    WordPress Struktur Core plugin <= 2.5.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/Struktur Coregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-57802High
    WordPress Struktur theme <= 2.5.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/Strukturgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-57801High
    WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Select-Themes/SetSailgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-57800High
    WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability
    CVSS 7.5
    Edge-Themes/Overworldgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 67 of 327
Previous6566676869Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard