1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 3:15 PM 16,333 active 1,443 known exploited

Catalog summary

16,333

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 3:15 PM 16,333 active 1,443 known exploited

Catalog summary

16,333

Active CVEs

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,351–3,400 of 16,333 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57800High
    WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability
    CVSS 7.5
    Edge-Themes/Overworldgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-57799High
    WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability
    CVSS 7.5
    uxper/Nussgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-57797Medium
    WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability
    CVSS 4.3
    ThemeMove/EduMallgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-57798High
    WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerability
    CVSS 7.5
    SaurabhSharma/NewsPlus Shortcodesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-57796High
    WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability
    CVSS 7.5
    VLThemes/Leedogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-57795High
    WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability
    CVSS 7.5
    themelexus/Kitchorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-57794High
    WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability
    CVSS 7.5
    uxper/Golo Frameworkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-57793High
    WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability
    CVSS 7.5
    Elated-Themes/Flowgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-57792High
    WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Mikado-Themes/Dørgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-57791High
    WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability
    CVSS 7.5
    ThemeMove/Brookgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-57789High
    WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability
    CVSS 7.5
    jwsthemes/Aquageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-57790High
    WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability
    CVSS 7.5
    ThemeMove/Billeygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-57788High
    WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
    CVSS 7.5
    Edge-Themes/Aaltogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-57786High
    WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF) to Broken Authentication vulnerability
    CVSS 8.8
    purethemes/WorkScout-Coregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-57787High
    WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability
    CVSS 8.5
    CreativeWS/CWS SVGiconsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-57783Medium
    WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    merkulove/Speakergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-57782Medium
    WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability
    CVSS 5.3
    PressTigers/Universal Clocksgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-57781Medium
    WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability
    CVSS 5.3
    Sovlix/MeetingHubgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-57780Medium
    WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Plugin Envision/Envision Page Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-57779Medium
    WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability
    CVSS 5.3
    themebeez/Fascinategeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-57778Medium
    WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability
    CVSS 5.3
    wpdevart/Booking calendar, Appointment Booking Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-57776Medium
    WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability
    CVSS 5.3
    vowelweb/VW Weddinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-57774Medium
    WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability
    CVSS 5.3
    vowelweb/VW Food Cornergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-57773High
    WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Injection vulnerability
    CVSS 7.6
    Zorem/Advanced Shipment Tracking for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-57772High
    WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability
    CVSS 8.5
    WP Inventory/WP Inventory Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-57771High
    WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability
    CVSS 8.5
    Milan Petrovic/GD Rating Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-57770Critical
    WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability
    CVSS 9.8
    ThemeGoods/Grand Photographygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-57768High
    WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulnerability
    CVSS 8.2
    favethemes/Houzez Login Registergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-57745High
    WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    stmcan/RT-Theme 18 | Extensionsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-57744Critical
    WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulnerability
    CVSS 9.8
    stmcan/RT-Theme 18 | Extensionsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-57743High
    WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulnerability
    CVSS 8.1
    stmcan/RT-Theme 18 | Extensionsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-57741High
    WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    AcyMailing Newsletter Team/AcyMailing SMTP Newslettergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-57738Critical
    WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability
    CVSS 9.8
    axiomthemes/777generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-57739Critical
    WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability
    CVSS 9.3
    AcyMailing Newsletter Team/AcyMailing SMTP Newslettergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-57740High
    WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability
    CVSS 7.1
    AcyMailing Newsletter Team/AcyMailing SMTP Newslettergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-57734High
    WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tagDiv/tagDiv Composergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-57733High
    WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tagDiv/tagDiv Cloud Librarygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-57732High
    WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tagDiv/tagDiv Opt-In Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57729High
    WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
    CVSS 7.5
    UX-themes/Flatsomegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57724Critical
    WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability
    CVSS 9.8
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57725High
    WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57726Critical
    WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability
    CVSS 9.3
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57728High
    WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    UX-themes/Flatsomegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57727High
    WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability
    CVSS 7.5
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57719Critical
    WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability
    CVSS 10.0
    CodeRevolution/Aimogen Progeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-57718High
    WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.12 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Unlimited Elements/Unlimited Elements For Elementor (Free Widgets, Addons, Templates)generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-57715High
    WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPManageNinja/Fluent CRMgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-57714Critical
    WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability
    CVSS 9.3
    LatePoint/LatePointgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-57713High
    WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability
    CVSS 8.8
    Marcus (aka @msykes)/Events Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-57712High
    WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPZOOM/WPZOOM Portfoliogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 68 of 327
Previous6667686970Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,351–3,400 of 16,333 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57800High
    WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability
    CVSS 7.5
    Edge-Themes/Overworldgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-57799High
    WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability
    CVSS 7.5
    uxper/Nussgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-57797Medium
    WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability
    CVSS 4.3
    ThemeMove/EduMallgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-57798High
    WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerability
    CVSS 7.5
    SaurabhSharma/NewsPlus Shortcodesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-57796High
    WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability
    CVSS 7.5
    VLThemes/Leedogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-57795High
    WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability
    CVSS 7.5
    themelexus/Kitchorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-57794High
    WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability
    CVSS 7.5
    uxper/Golo Frameworkgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-57793High
    WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability
    CVSS 7.5
    Elated-Themes/Flowgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-57792High
    WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability
    CVSS 7.5
    Mikado-Themes/Dørgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-57791High
    WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability
    CVSS 7.5
    ThemeMove/Brookgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-57789High
    WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability
    CVSS 7.5
    jwsthemes/Aquageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-57790High
    WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability
    CVSS 7.5
    ThemeMove/Billeygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-57788High
    WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
    CVSS 7.5
    Edge-Themes/Aaltogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-57786High
    WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF) to Broken Authentication vulnerability
    CVSS 8.8
    purethemes/WorkScout-Coregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-57787High
    WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability
    CVSS 8.5
    CreativeWS/CWS SVGiconsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-57783Medium
    WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    merkulove/Speakergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-57782Medium
    WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability
    CVSS 5.3
    PressTigers/Universal Clocksgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-57781Medium
    WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability
    CVSS 5.3
    Sovlix/MeetingHubgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-57780Medium
    WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Plugin Envision/Envision Page Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-57779Medium
    WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability
    CVSS 5.3
    themebeez/Fascinategeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-57778Medium
    WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability
    CVSS 5.3
    wpdevart/Booking calendar, Appointment Booking Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-57776Medium
    WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability
    CVSS 5.3
    vowelweb/VW Weddinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-57774Medium
    WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability
    CVSS 5.3
    vowelweb/VW Food Cornergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-57773High
    WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Injection vulnerability
    CVSS 7.6
    Zorem/Advanced Shipment Tracking for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-57772High
    WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability
    CVSS 8.5
    WP Inventory/WP Inventory Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-57771High
    WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability
    CVSS 8.5
    Milan Petrovic/GD Rating Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-57770Critical
    WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability
    CVSS 9.8
    ThemeGoods/Grand Photographygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-57768High
    WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulnerability
    CVSS 8.2
    favethemes/Houzez Login Registergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-57745High
    WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    stmcan/RT-Theme 18 | Extensionsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-57744Critical
    WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulnerability
    CVSS 9.8
    stmcan/RT-Theme 18 | Extensionsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-57743High
    WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulnerability
    CVSS 8.1
    stmcan/RT-Theme 18 | Extensionsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-57741High
    WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    AcyMailing Newsletter Team/AcyMailing SMTP Newslettergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-57738Critical
    WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability
    CVSS 9.8
    axiomthemes/777generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-57739Critical
    WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability
    CVSS 9.3
    AcyMailing Newsletter Team/AcyMailing SMTP Newslettergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-57740High
    WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability
    CVSS 7.1
    AcyMailing Newsletter Team/AcyMailing SMTP Newslettergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-57734High
    WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tagDiv/tagDiv Composergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-57733High
    WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tagDiv/tagDiv Cloud Librarygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-57732High
    WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tagDiv/tagDiv Opt-In Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57729High
    WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
    CVSS 7.5
    UX-themes/Flatsomegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57724Critical
    WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability
    CVSS 9.8
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57725High
    WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57726Critical
    WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability
    CVSS 9.3
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57728High
    WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    UX-themes/Flatsomegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57727High
    WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability
    CVSS 7.5
    Themeum/Kirkigeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57719Critical
    WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability
    CVSS 10.0
    CodeRevolution/Aimogen Progeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-57718High
    WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.12 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Unlimited Elements/Unlimited Elements For Elementor (Free Widgets, Addons, Templates)generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-57715High
    WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPManageNinja/Fluent CRMgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-57714Critical
    WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability
    CVSS 9.3
    LatePoint/LatePointgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-57713High
    WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability
    CVSS 8.8
    Marcus (aka @msykes)/Events Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-57712High
    WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPZOOM/WPZOOM Portfoliogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 68 of 327
Previous6667686970Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard