1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 6:05 PM 16,344 active 1,443 known exploited

Catalog summary

16,344

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 6:05 PM 16,344 active 1,443 known exploited

Catalog summary

16,344

Active CVEs

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,651–3,700 of 16,344 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-8678Medium
    MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions
    CVSS 4.3
    richardperdaan/MyParcelgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-13756High
    WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter
    CVSS 8.8
    WP Grid Builder/WP Grid Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-11426Medium
    UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter
    CVSS 6.5
    WebFactory/Under Construction Page (Pro)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-14480Critical
    OpenPLC v3 External Control of File Name or Path
    CVSS 9.9
    OpenPLC/OpenPLCgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-44383High
    Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration
    CVSS 7.5
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-42952High
    Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication Attempts
    CVSS 7.5
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-20744Critical
    Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control
    CVSS 9.8
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-11913Critical
    Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
    CVSS 9.8
    Drupal/Mother May Igeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-11914Medium
    Composer - Critical - Unsupported - SA-CONTRIB-2026-046
    CVSS 5.9
    Drupal/Composergeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-11915Medium
    Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047
    CVSS 5.9
    Drupal/Brute force attack protectiongeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-15087Medium
    Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078
    CVSS 5.9
    Drupal/Clean RESTfulgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-15086Medium
    Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077
    CVSS 5.9
    Drupal/Raw Formatter [Meta Tag Formatter]generic
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-15089Critical
    Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079
    CVSS 9.1
    Drupal/Commerce guest registrationgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-55808Medium
    Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
    CVSS 5.4
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  15. CVE-2026-55807Low
    Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
    CVSS 3.1
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  16. CVE-2026-55806Medium
    Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
    CVSS 5.9
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-55804Medium
    Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
    CVSS 5.9
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-55803Medium
    Drupal core - Critical - PHP object injection - SA-CORE-2026-005
    CVSS 5.9
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-15085Medium
    AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076
    CVSS 5.4
    Drupal/AI SEO/GEO Analyzergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-15084Medium
    UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075
    CVSS 5.4
    Drupal/UI Patterns (SDC in Drupal UI)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-15083Medium
    ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
    CVSS 4.2
    Drupal/ECA: Event - Condition - Actiongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  22. CVE-2026-15082Medium
    Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073
    CVSS 5.4
    Drupal/Siteimprove Analyticsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-15081High
    Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072
    CVSS 7.4
    Drupal/Location Selectorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-15080Medium
    Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071
    CVSS 4.3
    Drupal/Ray Enterprise Translationgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-15079Medium
    Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070
    CVSS 5.4
    Drupal/Login Disablegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-58591Medium
    Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069
    CVSS 5.4
    Drupal/Colorboxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-58590Medium
    FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
    CVSS 5.4
    Drupal/FlowDropgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  28. CVE-2026-58589Medium
    FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
    CVSS 5.4
    Drupal/FlowDropgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  29. CVE-2026-58588Medium
    Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066
    CVSS 6.1
    Drupal/Drupal Canvasgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  30. CVE-2026-58587Medium
    Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065
    CVSS 6.1
    Drupal/Drupal Canvasgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  31. CVE-2026-13244High
    Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064
    CVSS 8.1
    Drupal/Tealium iQ Tag Managementgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-13243Critical
    Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063
    CVSS 9.8
    Drupal/Salesforce Suitegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-13242Medium
    Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
    CVSS 6.5
    Drupal/Geolocation Fieldgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-13241Critical
    Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
    CVSS 9.8
    Drupal/Paragraphsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  35. CVE-2026-13240Critical
    Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
    CVSS 9.8
    Drupal/Paragraphsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  36. CVE-2026-13239Critical
    WissKI - Critical - Access bypass - SA-CONTRIB-2026-059
    CVSS 9.8
    Drupal/WissKIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-13238Critical
    Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058
    CVSS 9.1
    Drupal/Commerce Realex / Global Paymentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  38. CVE-2026-13237Critical
    AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057
    CVSS 9.1
    Drupal/AI Agentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  39. CVE-2026-13236Critical
    AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056
    CVSS 9.8
    Drupal/AI Agentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  40. CVE-2026-13235Critical
    AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055
    CVSS 9.8
    Drupal/AI (Artificial Intelligence)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-13234Medium
    AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054
    CVSS 6.1
    Drupal/AI (Artificial Intelligence)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  42. CVE-2026-13233Critical
    OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053
    CVSS 9.1
    Drupal/OpenAI Providergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  43. CVE-2026-13232Critical
    Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052
    CVSS 9.8
    Drupal/Advanced Content Feedback (aka admin_feedback)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  44. CVE-2026-13231Medium
    Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051
    CVSS 6.1
    Drupal/Advanced Content Feedback (aka admin_feedback)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-55810Critical
    Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
    CVSS 9.8
    Drupal/Plotly.js Graphinggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  46. CVE-2026-55809Critical
    Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049
    CVSS 9.8
    Drupal/Flag attendance fieldgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  47. CVE-2026-55187Medium
    Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms (follow-up to CVE-2026-27808)
    CVSS 5.8
    axllent/mailpit, github.com/axllent/mailpitgeneric · go
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  48. CVE-2026-12535Critical
    Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
    CVSS 9.8
    Drupal/Formatter Fieldgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-11909Critical
    Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044
    CVSS 9.8
    Drupal/Examples for Developersgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  50. CVE-2026-11908Medium
    Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043
    CVSS 5.4
    Drupal/Tagifygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
Page 74 of 327
Previous7273747576Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,651–3,700 of 16,344 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-8678Medium
    MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions
    CVSS 4.3
    richardperdaan/MyParcelgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-13756High
    WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter
    CVSS 8.8
    WP Grid Builder/WP Grid Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-11426Medium
    UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter
    CVSS 6.5
    WebFactory/Under Construction Page (Pro)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-14480Critical
    OpenPLC v3 External Control of File Name or Path
    CVSS 9.9
    OpenPLC/OpenPLCgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-44383High
    Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration
    CVSS 7.5
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-42952High
    Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication Attempts
    CVSS 7.5
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-20744Critical
    Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control
    CVSS 9.8
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  8. CVE-2026-11913Critical
    Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
    CVSS 9.8
    Drupal/Mother May Igeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-11914Medium
    Composer - Critical - Unsupported - SA-CONTRIB-2026-046
    CVSS 5.9
    Drupal/Composergeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-11915Medium
    Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047
    CVSS 5.9
    Drupal/Brute force attack protectiongeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-15087Medium
    Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078
    CVSS 5.9
    Drupal/Clean RESTfulgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-15086Medium
    Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077
    CVSS 5.9
    Drupal/Raw Formatter [Meta Tag Formatter]generic
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-15089Critical
    Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079
    CVSS 9.1
    Drupal/Commerce guest registrationgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-55808Medium
    Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
    CVSS 5.4
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  15. CVE-2026-55807Low
    Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
    CVSS 3.1
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  16. CVE-2026-55806Medium
    Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
    CVSS 5.9
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-55804Medium
    Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
    CVSS 5.9
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  18. CVE-2026-55803Medium
    Drupal core - Critical - PHP object injection - SA-CORE-2026-005
    CVSS 5.9
    Drupal/Drupal coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  19. CVE-2026-15085Medium
    AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076
    CVSS 5.4
    Drupal/AI SEO/GEO Analyzergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  20. CVE-2026-15084Medium
    UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075
    CVSS 5.4
    Drupal/UI Patterns (SDC in Drupal UI)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  21. CVE-2026-15083Medium
    ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
    CVSS 4.2
    Drupal/ECA: Event - Condition - Actiongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  22. CVE-2026-15082Medium
    Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073
    CVSS 5.4
    Drupal/Siteimprove Analyticsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  23. CVE-2026-15081High
    Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072
    CVSS 7.4
    Drupal/Location Selectorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  24. CVE-2026-15080Medium
    Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071
    CVSS 4.3
    Drupal/Ray Enterprise Translationgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-15079Medium
    Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070
    CVSS 5.4
    Drupal/Login Disablegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  26. CVE-2026-58591Medium
    Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069
    CVSS 5.4
    Drupal/Colorboxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-58590Medium
    FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
    CVSS 5.4
    Drupal/FlowDropgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  28. CVE-2026-58589Medium
    FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
    CVSS 5.4
    Drupal/FlowDropgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  29. CVE-2026-58588Medium
    Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066
    CVSS 6.1
    Drupal/Drupal Canvasgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  30. CVE-2026-58587Medium
    Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065
    CVSS 6.1
    Drupal/Drupal Canvasgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  31. CVE-2026-13244High
    Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064
    CVSS 8.1
    Drupal/Tealium iQ Tag Managementgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  32. CVE-2026-13243Critical
    Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063
    CVSS 9.8
    Drupal/Salesforce Suitegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  33. CVE-2026-13242Medium
    Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
    CVSS 6.5
    Drupal/Geolocation Fieldgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  34. CVE-2026-13241Critical
    Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
    CVSS 9.8
    Drupal/Paragraphsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  35. CVE-2026-13240Critical
    Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
    CVSS 9.8
    Drupal/Paragraphsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  36. CVE-2026-13239Critical
    WissKI - Critical - Access bypass - SA-CONTRIB-2026-059
    CVSS 9.8
    Drupal/WissKIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  37. CVE-2026-13238Critical
    Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058
    CVSS 9.1
    Drupal/Commerce Realex / Global Paymentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  38. CVE-2026-13237Critical
    AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057
    CVSS 9.1
    Drupal/AI Agentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  39. CVE-2026-13236Critical
    AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056
    CVSS 9.8
    Drupal/AI Agentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  40. CVE-2026-13235Critical
    AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055
    CVSS 9.8
    Drupal/AI (Artificial Intelligence)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  41. CVE-2026-13234Medium
    AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054
    CVSS 6.1
    Drupal/AI (Artificial Intelligence)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  42. CVE-2026-13233Critical
    OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053
    CVSS 9.1
    Drupal/OpenAI Providergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  43. CVE-2026-13232Critical
    Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052
    CVSS 9.8
    Drupal/Advanced Content Feedback (aka admin_feedback)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  44. CVE-2026-13231Medium
    Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051
    CVSS 6.1
    Drupal/Advanced Content Feedback (aka admin_feedback)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-55810Critical
    Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
    CVSS 9.8
    Drupal/Plotly.js Graphinggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  46. CVE-2026-55809Critical
    Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049
    CVSS 9.8
    Drupal/Flag attendance fieldgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  47. CVE-2026-55187Medium
    Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms (follow-up to CVE-2026-27808)
    CVSS 5.8
    axllent/mailpit, github.com/axllent/mailpitgeneric · go
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  48. CVE-2026-12535Critical
    Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
    CVSS 9.8
    Drupal/Formatter Fieldgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  49. CVE-2026-11909Critical
    Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044
    CVSS 9.8
    Drupal/Examples for Developersgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  50. CVE-2026-11908Medium
    Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043
    CVSS 5.4
    Drupal/Tagifygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
Page 74 of 327
Previous7273747576Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard