1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 6:05 PM 16,344 active 1,443 known exploited

Catalog summary

16,344

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 6:05 PM 16,344 active 1,443 known exploited

Catalog summary

16,344

Active CVEs

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,701–3,750 of 16,344 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-10770Medium
    Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042
    CVSS 6.1
    Drupal/Anti-Spam by CleanTalkgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  2. CVE-2026-52747High
    ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
    CVSS 8.6
    owasp-modsecurity/ModSecuritygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-10769Medium
    Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041
    CVSS 5.4
    Drupal/Commerce Coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  4. CVE-2026-10768Critical
    LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
    CVSS 9.8
    Drupal/LocalGov Workflowsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-52761Medium
    ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture
    CVSS 5.8
    owasp-modsecurity/ModSecuritygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-55882High
    Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
    CVSS 8.3
    github.com/tilt-dev/tilt, tilt-dev/tiltgeneric · go
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-49213High
    TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution
    CVSS 8.1
    baptisteArno/typebot.iogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-59155Medium
    Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API
    CVSS 6.9
    nezhahq/nezhageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-55852High
    Frappe: TarSlip RCE in Package Import
    CVSS 8.6
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-42219Medium
    Frappe: Path Traversal via /backups Route
    CVSS 6.9
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-49394High
    Frappe: Auth. bypass via update_page
    CVSS 7.1
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-48127Medium
    Frappe: Arbitrary Attachment Injection via add_attachments and upload_file
    CVSS 5.3
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-41482High
    Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator
    CVSS 7.1
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-47199Low
    Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE
    CVSS 2.3
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-58503Medium
    Frappe: Unauthenticated User Enumeration via reset_password
    CVSS 6.9
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-47422Medium
    Frappe: Unrestricted API access to save_report
    CVSS 5.3
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-57584High
    Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS
    CVSS 8.7
    phalcon/cphalcongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-54736High
    Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
    CVSS 8.2
    phalcon/cphalcongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-55664Medium
    Grist: Insufficient access control in the /forms endpoint exposes table metadata
    CVSS 4.3
    gristlabs/grist-coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-55659High
    Grist: XSS through unsafe value interpolation in server-rendered pages
    CVSS 7.7
    gristlabs/grist-coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-45203High
    GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-57574High
    Misskey: TOTP tokens can be reused
    CVSS 7.4
    misskey-dev/misskeygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-45196High
    GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-58499High
    Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
    CVSS 8.2
    EverMind-AI/EverOSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-7639High
    GPU DDK - Page UAF read in PMMETA_PROTECT heap memory
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-55213High
    h2o: musl libc stack overflow (QPACK)
    CVSS 7.5
    h2o/h2ogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-57230Medium
    OpenReplay: Authenticated ClickHouse SQL injection via session search
    CVSS 5.4
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-41154High
    GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-55881High
    OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint
    CVSS 7.1
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-34196High
    GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-55880High
    OpenReplay: Cross-user IDOR in notes and dashboard widgets
    CVSS 7.1
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-55879Critical
    OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover
    CVSS 9.3
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-55229High
    Gotenberg: SSRF via LibreOffice document processing
    CVSS 7.5
    github.com/gotenberg/gotenberg/v8, gotenberg/gotenberggeneric · go
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  34. CVE-2026-55405High
    LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
    CVSS 7.6
    dev.langchain4j:langchain4j-mariadb, dev.langchain4j:langchain4j-pgvector +1generic · maven
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  35. CVE-2026-12761Critical
    miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow
    CVSS 9.8
    cyberlord92/miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-13039Medium
    Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API
    CVSS 5.3
    arraytics/Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-57217High
    RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
    CVSS 7.0
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-57221Medium
    RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
    CVSS 5.3
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57215High
    RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
    CVSS 8.8
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57218Medium
    RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure
    CVSS 6.5
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57216Medium
    RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
    CVSS 6.8
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57220High
    RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
    CVSS 7.5
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57214High
    RabbitMQ: Stored XSS in RabbitMQ management UI
    CVSS 7.1
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57211Medium
    RabbitMQ: UNC SSRF affecting the management UI on Windows
    CVSS 6.5
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57212High
    RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size
    CVSS 7.7
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-55233High
    OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream
    CVSS 7.5
    openresty/openrestygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-55377High
    Logto: Account Center MFA management step-up bypass via WebAuthn registration verification
    CVSS 8.1
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-55370Medium
    Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)
    CVSS 6.4
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-55789High
    Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
    CVSS 8.5
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-54714Medium
    Logto: XSS via unescaped RelayState in SAML auto-submit form
    CVSS 6.1
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
Page 75 of 327
Previous7374757677Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,701–3,750 of 16,344 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-10770Medium
    Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042
    CVSS 6.1
    Drupal/Anti-Spam by CleanTalkgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  2. CVE-2026-52747High
    ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
    CVSS 8.6
    owasp-modsecurity/ModSecuritygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-10769Medium
    Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041
    CVSS 5.4
    Drupal/Commerce Coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  4. CVE-2026-10768Critical
    LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
    CVSS 9.8
    Drupal/LocalGov Workflowsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  5. CVE-2026-52761Medium
    ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture
    CVSS 5.8
    owasp-modsecurity/ModSecuritygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-55882High
    Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
    CVSS 8.3
    github.com/tilt-dev/tilt, tilt-dev/tiltgeneric · go
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-49213High
    TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution
    CVSS 8.1
    baptisteArno/typebot.iogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-59155Medium
    Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API
    CVSS 6.9
    nezhahq/nezhageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-55852High
    Frappe: TarSlip RCE in Package Import
    CVSS 8.6
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-42219Medium
    Frappe: Path Traversal via /backups Route
    CVSS 6.9
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-49394High
    Frappe: Auth. bypass via update_page
    CVSS 7.1
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-48127Medium
    Frappe: Arbitrary Attachment Injection via add_attachments and upload_file
    CVSS 5.3
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-41482High
    Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator
    CVSS 7.1
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-47199Low
    Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE
    CVSS 2.3
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-58503Medium
    Frappe: Unauthenticated User Enumeration via reset_password
    CVSS 6.9
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-47422Medium
    Frappe: Unrestricted API access to save_report
    CVSS 5.3
    frappe/frappegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-57584High
    Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS
    CVSS 8.7
    phalcon/cphalcongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-54736High
    Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
    CVSS 8.2
    phalcon/cphalcongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-55664Medium
    Grist: Insufficient access control in the /forms endpoint exposes table metadata
    CVSS 4.3
    gristlabs/grist-coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-55659High
    Grist: XSS through unsafe value interpolation in server-rendered pages
    CVSS 7.7
    gristlabs/grist-coregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-45203High
    GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-57574High
    Misskey: TOTP tokens can be reused
    CVSS 7.4
    misskey-dev/misskeygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-45196High
    GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  24. CVE-2026-58499High
    Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
    CVSS 8.2
    EverMind-AI/EverOSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-7639High
    GPU DDK - Page UAF read in PMMETA_PROTECT heap memory
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-55213High
    h2o: musl libc stack overflow (QPACK)
    CVSS 7.5
    h2o/h2ogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-57230Medium
    OpenReplay: Authenticated ClickHouse SQL injection via session search
    CVSS 5.4
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-41154High
    GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-55881High
    OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint
    CVSS 7.1
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-34196High
    GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem
    CVSS 7.8
    Imagination Technologies/Graphics DDKgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-55880High
    OpenReplay: Cross-user IDOR in notes and dashboard widgets
    CVSS 7.1
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-55879Critical
    OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover
    CVSS 9.3
    openreplay/openreplaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-55229High
    Gotenberg: SSRF via LibreOffice document processing
    CVSS 7.5
    github.com/gotenberg/gotenberg/v8, gotenberg/gotenberggeneric · go
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  34. CVE-2026-55405High
    LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
    CVSS 7.6
    dev.langchain4j:langchain4j-mariadb, dev.langchain4j:langchain4j-pgvector +1generic · maven
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  35. CVE-2026-12761Critical
    miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow
    CVSS 9.8
    cyberlord92/miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-13039Medium
    Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API
    CVSS 5.3
    arraytics/Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-57217High
    RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
    CVSS 7.0
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-57221Medium
    RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
    CVSS 5.3
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57215High
    RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
    CVSS 8.8
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57218Medium
    RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure
    CVSS 6.5
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57216Medium
    RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
    CVSS 6.8
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57220High
    RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
    CVSS 7.5
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57214High
    RabbitMQ: Stored XSS in RabbitMQ management UI
    CVSS 7.1
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57211Medium
    RabbitMQ: UNC SSRF affecting the management UI on Windows
    CVSS 6.5
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57212High
    RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size
    CVSS 7.7
    rabbitmq/rabbitmq-servergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-55233High
    OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream
    CVSS 7.5
    openresty/openrestygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-55377High
    Logto: Account Center MFA management step-up bypass via WebAuthn registration verification
    CVSS 8.1
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-55370Medium
    Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)
    CVSS 6.4
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-55789High
    Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
    CVSS 8.5
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-54714Medium
    Logto: XSS via unescaped RelayState in SAML auto-submit form
    CVSS 6.1
    logto-io/logtogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
Page 75 of 327
Previous7374757677Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard