1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 4:25 PM 16,337 active 1,443 known exploited

Catalog summary

16,337

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 4:25 PM 16,337 active 1,443 known exploited

Catalog summary

16,337

Active CVEs

8,455

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,451–3,500 of 16,337 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57388High
    WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themefic/Hydra Bookinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-57387High
    WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    picu/picugeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-57382High
    WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Mitchell Bennis/Simple File Listgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-57383High
    WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    eyecix/JobSearchgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-57385High
    WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability
    CVSS 8.5
    appsbd/Viteposgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-57386High
    WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability
    CVSS 8.8
    Kodezen LLC/aBlocksgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-57381High
    WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Property Hive/PropertyHivegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-57379High
    WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPPOOL/FormyChatgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-57380High
    WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    hupe13/Extensions for Leaflet Mapgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-57378High
    WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability
    CVSS 7.5
    Phil Kurth/Advanced Formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-57364Medium
    WordPress Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type vulnerability
    CVSS 6.5
    WPDeveloper/Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; Moregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-57368High
    WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    NooTheme/Jobmonstergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-57375Medium
    WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability
    CVSS 6.5
    FluxBuilder/MStore APIgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-57372High
    WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 7.2
    denishua/WPJAM Basicgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-57363High
    WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    QuantumCloud/ChatBotgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-57371High
    WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability
    CVSS 8.8
    denishua/WPJAM Basicgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-57365Medium
    WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Hitesh Chandwani/reCAPTCHA (v2 &amp; v3) for Asgaros Forumgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-57376High
    WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Element Invader/ElementInvader Addons for Elementorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-57369High
    WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    themifyme/Themify Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-57377Medium
    WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability
    CVSS 6.5
    WPXPO/WowAddonsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-15547Medium
    Shibby Tomato CIFS Mount sub_2D048 os command injection
    CVSS 6.3
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-14453Critical
    A user with low privileges can inject SSTI templates that can lead to RCE in open-tickets
    CVSS 9.6
    Centreon/Infra Monitoringgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  23. CVE-2026-9597Medium
    Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
    CVSS 5.4
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-15546Medium
    Shibby Tomato start_jffs2 sub_2D568 os command injection
    CVSS 6.3
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-6850Medium
    Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost
    CVSS 6.5
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-10106Medium
    Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost
    CVSS 6.5
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-10085Medium
    Ordinary group/direct message member can enable group_constrained and remove all channel participants
    CVSS 5.4
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  28. CVE-2026-15574High
    Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-15545High
    Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write
    CVSS 8.8
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-9708Medium
    Incoming webhook user attribution via unvalidated webhook owner
    CVSS 4.9
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-10103Medium
    Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels
    CVSS 4.3
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  32. CVE-2026-15544High
    Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow
    CVSS 8.8
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-15543High
    Tenda CH22 CertListInfo formCertListInfo buffer overflow
    CVSS 8.8
    Tenda/CH22generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-14165High
    Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
    CVSS 7.5
    Dassault Systèmes/Tuleap Enterprise Editiongeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-15542High
    will-moss Isaiah Websocket Connection Authentication main.go improper authentication
    CVSS 7.3
    will-moss/Isaiahgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-15541High
    will-moss Isaiah Master Websocket server.go Server.Handle authorization
    CVSS 7.3
    will-moss/Isaiahgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-4769Critical
    Unauthenticated Access to Internal Diagnostic Interface
    CVSS 9.8
    WAGO/0765-110x/0100-0000, WAGO/0765-120x/0100-0000 +6generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-15540Medium
    SourceCodester Online Book Store System Administrative index.php php file inclusion
    CVSS 4.3
    SourceCodester/Online Book Store Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-15539Medium
    SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload
    CVSS 4.7
    SourceCodester/Online Book Store Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-15538Medium
    primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
    CVSS 6.3
    primefaces/primereactgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-12582High
    Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id
    CVSS 8.6
    Unknown/Library Management Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  42. CVE-2026-12397Medium
    WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
    CVSS 4.3
    Unknown/WP Job Portalgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  43. CVE-2026-12396Medium
    WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection
    CVSS 5.4
    Unknown/WP Job Portalgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  44. CVE-2026-12275High
    Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration
    CVSS 7.1
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  45. CVE-2026-12274Medium
    Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
    CVSS 6.5
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  46. CVE-2026-12273Medium
    Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
    CVSS 4.3
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  47. CVE-2026-12271Medium
    Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
    CVSS 5.4
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  48. CVE-2026-12081Medium
    Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field
    CVSS 5.0
    Unknown/Database for Contact Form 7, WPforms, Elementor formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  49. CVE-2026-11964Critical
    User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation
    CVSS 9.1
    Unknown/User Registration & Membershipgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  50. CVE-2026-11963High
    User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier Modification via IDOR
    CVSS 8.1
    Unknown/User Registration & Membershipgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
Page 70 of 327
Previous6869707172Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,455

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,451–3,500 of 16,337 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57388High
    WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themefic/Hydra Bookinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-57387High
    WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    picu/picugeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-57382High
    WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Mitchell Bennis/Simple File Listgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-57383High
    WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    eyecix/JobSearchgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-57385High
    WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability
    CVSS 8.5
    appsbd/Viteposgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-57386High
    WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability
    CVSS 8.8
    Kodezen LLC/aBlocksgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-57381High
    WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Property Hive/PropertyHivegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-57379High
    WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPPOOL/FormyChatgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-57380High
    WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    hupe13/Extensions for Leaflet Mapgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-57378High
    WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability
    CVSS 7.5
    Phil Kurth/Advanced Formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-57364Medium
    WordPress Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type vulnerability
    CVSS 6.5
    WPDeveloper/Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; Moregeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-57368High
    WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    NooTheme/Jobmonstergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-57375Medium
    WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability
    CVSS 6.5
    FluxBuilder/MStore APIgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-57372High
    WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 7.2
    denishua/WPJAM Basicgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-57363High
    WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    QuantumCloud/ChatBotgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-57371High
    WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability
    CVSS 8.8
    denishua/WPJAM Basicgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-57365Medium
    WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Hitesh Chandwani/reCAPTCHA (v2 &amp; v3) for Asgaros Forumgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-57376High
    WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Element Invader/ElementInvader Addons for Elementorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-57369High
    WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    themifyme/Themify Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-57377Medium
    WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability
    CVSS 6.5
    WPXPO/WowAddonsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-15547Medium
    Shibby Tomato CIFS Mount sub_2D048 os command injection
    CVSS 6.3
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-14453Critical
    A user with low privileges can inject SSTI templates that can lead to RCE in open-tickets
    CVSS 9.6
    Centreon/Infra Monitoringgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  23. CVE-2026-9597Medium
    Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
    CVSS 5.4
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-15546Medium
    Shibby Tomato start_jffs2 sub_2D568 os command injection
    CVSS 6.3
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-6850Medium
    Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost
    CVSS 6.5
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-10106Medium
    Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost
    CVSS 6.5
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-10085Medium
    Ordinary group/direct message member can enable group_constrained and remove all channel participants
    CVSS 5.4
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  28. CVE-2026-15574High
    Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default
    CVSS 7.5
    Affected software not mappedEcosystem not listed
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-15545High
    Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write
    CVSS 8.8
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-9708Medium
    Incoming webhook user attribution via unvalidated webhook owner
    CVSS 4.9
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-10103Medium
    Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels
    CVSS 4.3
    Mattermost/Mattermostgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 14, 2026View HOL analysis
  32. CVE-2026-15544High
    Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow
    CVSS 8.8
    Shibby/Tomatogeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-15543High
    Tenda CH22 CertListInfo formCertListInfo buffer overflow
    CVSS 8.8
    Tenda/CH22generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-14165High
    Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
    CVSS 7.5
    Dassault Systèmes/Tuleap Enterprise Editiongeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-15542High
    will-moss Isaiah Websocket Connection Authentication main.go improper authentication
    CVSS 7.3
    will-moss/Isaiahgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 15, 2026View HOL analysis
  36. CVE-2026-15541High
    will-moss Isaiah Master Websocket server.go Server.Handle authorization
    CVSS 7.3
    will-moss/Isaiahgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-4769Critical
    Unauthenticated Access to Internal Diagnostic Interface
    CVSS 9.8
    WAGO/0765-110x/0100-0000, WAGO/0765-120x/0100-0000 +6generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  38. CVE-2026-15540Medium
    SourceCodester Online Book Store System Administrative index.php php file inclusion
    CVSS 4.3
    SourceCodester/Online Book Store Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-15539Medium
    SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload
    CVSS 4.7
    SourceCodester/Online Book Store Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-15538Medium
    primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
    CVSS 6.3
    primefaces/primereactgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-12582High
    Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id
    CVSS 8.6
    Unknown/Library Management Systemgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  42. CVE-2026-12397Medium
    WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
    CVSS 4.3
    Unknown/WP Job Portalgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  43. CVE-2026-12396Medium
    WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection
    CVSS 5.4
    Unknown/WP Job Portalgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  44. CVE-2026-12275High
    Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration
    CVSS 7.1
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  45. CVE-2026-12274Medium
    Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
    CVSS 6.5
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  46. CVE-2026-12273Medium
    Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
    CVSS 4.3
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  47. CVE-2026-12271Medium
    Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
    CVSS 5.4
    Unknown/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  48. CVE-2026-12081Medium
    Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field
    CVSS 5.0
    Unknown/Database for Contact Form 7, WPforms, Elementor formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  49. CVE-2026-11964Critical
    User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation
    CVSS 9.1
    Unknown/User Registration & Membershipgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  50. CVE-2026-11963High
    User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier Modification via IDOR
    CVSS 8.1
    Unknown/User Registration & Membershipgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
Page 70 of 327
Previous6869707172Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard