1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 10:25 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 10:25 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 301–350 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-19150High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-19148High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  3. CVE-2026-19147High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  4. CVE-2026-19146Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  5. CVE-2026-19145High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-19144High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-19143High
    CISA ADP Vulnrichment
    CVSS 8.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-19142High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-19141High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-19140High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-19139High
    CISA ADP Vulnrichment
    CVSS 7.4
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-19138High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-19168High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-19169High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-19172High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  16. CVE-2026-19170Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-19157Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-19154High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-19149Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-19137High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-18367Critical
    CISA ADP Vulnrichment
    CVSS 9.3
    Sophos/Sophos Endpoint for macOS, Sophos/Sophos Home for macOSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-71478Medium
    league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
    CVSS 6.1
    league/commonmark, thephpleague/commonmarkcomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-19108Medium
    MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
    CVSS 5.3
    MZ Automation/libiec61850generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  24. CVE-2026-71502Unknown severity
    Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-Transmute
    Not scoredSource severity not reported
    misp/cti-transmutegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-48074Low
    OpenReception: Staff deletion removes pending invites cross-tenant by email match
    CVSS 2.7
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-54717Medium
    Silverstripe: XSS in breadcrumbs in page list view
    CVSS 5.4
    silverstripe/cms, silverstripe/silverstripe-cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-67422High
    pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
    CVSS 7.5
    facelessuser/pymdown-extensions, pymdown-extensionsgeneric · pip · pypi
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-63637High
    Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriter
    CVSS 8.6
    dgraph-io/dgraphgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-45378High
    Decidim: Verification documents can be downloaded through reusable links
    CVSS 7.5
    decidim-verifications, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19071Medium
    itsourcecode Hospital Management System viewappointment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-45573Medium
    Decidim: Push subscriptions can be abused for server-side requests
    CVSS 6.4
    decidim-core, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-45572Medium
    Decidim: HTML content blocks allow stored script execution
    CVSS 4.8
    decidim-core, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-71476High
    Nx: Zip-Slip in the self-hosted remote cache
    CVSS 8.7
    @nx/azure-cache, @nx/gcs-cache +8generic · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  34. CVE-2026-71439Medium
    Mermaid radar diagrams are vulnerable to DoS
    CVSS 5.3
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-15734Critical
    WGDashboard Server-Side Template Injection vulnerability
    CVSS 9.8
    WGDashboard/WGDashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-15733Critical
    WGDashboard Remote Code Execution vulnerability
    CVSS 9.8
    WGDashboard/WGDashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-19070Medium
    itsourcecode Hospital Management System viewadmin.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2026-15732Critical
    WGDashboard Server-Side Request Forgery Vulnerability
    CVSS 9.8
    WGDashboard/WGDashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-71438Low
    Mermaid configuration APIs allow prototype pollution
    CVSS 2.4
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-50159Medium
    Mermaid allows CSS injection applying to sibling elements of the diagram
    CVSS 5.3
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-71437Medium
    Mermaid Architecture diagrams are vulnerable to prototype pollution
    CVSS 6.5
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-71436Medium
    Mermaid XY Charts are vulnerable to an infinite loop DoS
    CVSS 5.3
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-19069Medium
    itsourcecode Hospital Management System treatmentrecord.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  44. CVE-2026-71435Medium
    Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
    CVSS 6.1
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-70559High
    Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll
    CVSS 7.5
    DataLinkDC/Dinkygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  46. CVE-2026-71434Medium
    Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
    CVSS 5.3
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-45415Medium
    Decidim: CSV census record endpoints improper authorization
    CVSS 6.0
    decidim-verifications, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-70558Critical
    Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token
    CVSS 9.8
    DataLinkDC/Dinkygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  49. CVE-2026-64662Medium
    Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
    CVSS 6.5
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-64663Medium
    Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
    CVSS 6.5
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 7 of 325
Previous56789Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 301–350 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-19150High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-19148High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  3. CVE-2026-19147High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  4. CVE-2026-19146Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  5. CVE-2026-19145High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  6. CVE-2026-19144High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  7. CVE-2026-19143High
    CISA ADP Vulnrichment
    CVSS 8.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-19142High
    CISA ADP Vulnrichment
    CVSS 7.5
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  9. CVE-2026-19141High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-19140High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-19139High
    CISA ADP Vulnrichment
    CVSS 7.4
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  12. CVE-2026-19138High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-19168High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-19169High
    CISA ADP Vulnrichment
    CVSS 8.8
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-19172High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  16. CVE-2026-19170Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-19157Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-19154High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-19149Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-19137High
    CISA ADP Vulnrichment
    CVSS 8.3
    Google/Chromegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-18367Critical
    CISA ADP Vulnrichment
    CVSS 9.3
    Sophos/Sophos Endpoint for macOS, Sophos/Sophos Home for macOSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-71478Medium
    league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
    CVSS 6.1
    league/commonmark, thephpleague/commonmarkcomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-19108Medium
    MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
    CVSS 5.3
    MZ Automation/libiec61850generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  24. CVE-2026-71502Unknown severity
    Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-Transmute
    Not scoredSource severity not reported
    misp/cti-transmutegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  25. CVE-2026-48074Low
    OpenReception: Staff deletion removes pending invites cross-tenant by email match
    CVSS 2.7
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  26. CVE-2026-54717Medium
    Silverstripe: XSS in breadcrumbs in page list view
    CVSS 5.4
    silverstripe/cms, silverstripe/silverstripe-cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2026-67422High
    pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
    CVSS 7.5
    facelessuser/pymdown-extensions, pymdown-extensionsgeneric · pip · pypi
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2026-63637High
    Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriter
    CVSS 8.6
    dgraph-io/dgraphgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  29. CVE-2026-45378High
    Decidim: Verification documents can be downloaded through reusable links
    CVSS 7.5
    decidim-verifications, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19071Medium
    itsourcecode Hospital Management System viewappointment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-45573Medium
    Decidim: Push subscriptions can be abused for server-side requests
    CVSS 6.4
    decidim-core, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-45572Medium
    Decidim: HTML content blocks allow stored script execution
    CVSS 4.8
    decidim-core, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-71476High
    Nx: Zip-Slip in the self-hosted remote cache
    CVSS 8.7
    @nx/azure-cache, @nx/gcs-cache +8generic · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  34. CVE-2026-71439Medium
    Mermaid radar diagrams are vulnerable to DoS
    CVSS 5.3
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-15734Critical
    WGDashboard Server-Side Template Injection vulnerability
    CVSS 9.8
    WGDashboard/WGDashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-15733Critical
    WGDashboard Remote Code Execution vulnerability
    CVSS 9.8
    WGDashboard/WGDashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-19070Medium
    itsourcecode Hospital Management System viewadmin.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  38. CVE-2026-15732Critical
    WGDashboard Server-Side Request Forgery Vulnerability
    CVSS 9.8
    WGDashboard/WGDashboardgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-71438Low
    Mermaid configuration APIs allow prototype pollution
    CVSS 2.4
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-50159Medium
    Mermaid allows CSS injection applying to sibling elements of the diagram
    CVSS 5.3
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-71437Medium
    Mermaid Architecture diagrams are vulnerable to prototype pollution
    CVSS 6.5
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-71436Medium
    Mermaid XY Charts are vulnerable to an infinite loop DoS
    CVSS 5.3
    mermaid, mermaid-js/mermaidgeneric · npm
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-19069Medium
    itsourcecode Hospital Management System treatmentrecord.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  44. CVE-2026-71435Medium
    Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
    CVSS 6.1
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-70559High
    Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll
    CVSS 7.5
    DataLinkDC/Dinkygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  46. CVE-2026-71434Medium
    Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
    CVSS 5.3
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-45415Medium
    Decidim: CSV census record endpoints improper authorization
    CVSS 6.0
    decidim-verifications, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-70558Critical
    Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token
    CVSS 9.8
    DataLinkDC/Dinkygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  49. CVE-2026-64662Medium
    Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
    CVSS 6.5
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-64663Medium
    Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
    CVSS 6.5
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 7 of 325
Previous56789Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard