1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 7:05 PM 16,350 active 1,443 known exploited

Catalog summary

16,350

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 7:05 PM 16,350 active 1,443 known exploited

Catalog summary

16,350

Active CVEs

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,801–3,850 of 16,350 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-1667High
    SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()
    CVSS 7.2
    cifi/GEO Plugin by Squirrly SEOgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  2. CVE-2026-58493Medium
    grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction
    CVSS 5.1
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-58492Critical
    grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolation
    CVSS 9.2
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  4. CVE-2026-55890Medium
    Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()
    CVSS 4.8
    getgrav/gravcomposer · generic
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  5. CVE-2026-15377Medium
    Eleveo Call Recording Software sendlogfile improper authorization
    CVSS 4.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-55885Medium
    Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
    CVSS 6.8
    getgrav/gravcomposer · generic
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-53653High
    Grav: Unauthenticated denial of service via unbounded image derivative dimensions
    CVSS 8.7
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  8. CVE-2026-54919High
    cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends
    CVSS 7.4
    yhirose/cpp-httplibgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  9. CVE-2026-39903High
    Simple Machines Forum Authorization Bypass via AttachmentApprove.php
    CVSS 7.1
    SimpleMachines/SMFgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 28, 2026View HOL analysis
  10. CVE-2026-59180Low
    Apprise forwards configured auth headers across cross-origin HTTP redirects
    CVSS 3.1
    caronc/apprisegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  11. CVE-2026-55687High
    ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsing
    CVSS 7.5
    espressif/esp-idfgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2026-54063High
    Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
    CVSS 7.5
    github.com/xuri/excelize/v2, qax-os/excelizegeneric · go
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-59162High
    Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
    CVSS 7.5
    qax-os/excelizegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026View HOL analysis
  14. CVE-2026-59161High
    Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
    CVSS 8.7
    qax-os/excelizegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026View HOL analysis
  15. CVE-2026-59154Medium
    Wekan: Checklist direct DDP updates can write checklist data into private boards
    CVSS 4.3
    wekan/wekangeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  16. CVE-2026-15376Medium
    Eleveo Call Recording Software statisticReportAction.do improper authorization
    CVSS 6.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-53657High
    Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
    CVSS 8.2
    lima-vm/limageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  18. CVE-2026-56675High
    9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
    CVSS 8.3
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-55638High
    9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
    CVSS 8.6
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  20. CVE-2026-55641High
    9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
    CVSS 8.2
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-56676High
    9router: Image prefetch DNS rebinding allows SSRF to internal services
    CVSS 7.4
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-55500Critical
    9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover
    CVSS 9.9
    9router, decolua/9routergeneric · npm
    PublishedJul 10, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-15143Critical
    Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)
    CVSS 9.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  24. CVE-2026-55501High
    9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
    CVSS 7.3
    9router, decolua/9routergeneric · npm
    PublishedJul 10, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  25. CVE-2026-15375Medium
    Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
    CVSS 4.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  26. CVE-2026-54149High
    MaxKB MCP tool import validation bypass allows post-authentication remote code execution
    CVSS 8.8
    1Panel-dev/MaxKBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  27. CVE-2026-15374Medium
    Eleveo Call Recording Software Group roleAddAction.do improper authorization
    CVSS 6.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-33382High
    Denial of service via unbounded request body size
    CVSS 7.5
    Grafana/Grafana OSSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 29, 2026View HOL analysis
  29. CVE-2026-54000High
    osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows)
    CVSS 7.0
    osquery/osquerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  30. CVE-2026-54001High
    osquery: Heap buffer overflow via `authenticode` table (Windows)
    CVSS 7.0
    osquery/osquerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  31. CVE-2026-15373Medium
    Eleveo Call Recording Software userAddAction.do improper authorization
    CVSS 6.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-46388Medium
    osquery: Unprivileged users can temporarily read file carve contents
    CVSS 4.4
    osquery/osquerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-61492Low
    CISA ADP Vulnrichment
    CVSS 3.5
    JetBrains/YouTrackgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-59796High
    CISA ADP Vulnrichment
    CVSS 8.1
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  35. CVE-2026-59795High
    CISA ADP Vulnrichment
    CVSS 8.1
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-59794High
    CISA ADP Vulnrichment
    CVSS 7.3
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  37. CVE-2026-59793High
    CISA ADP Vulnrichment
    CVSS 8.8
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-59792Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    JetBrains/IntelliJ IDEAgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-59791Low
    CISA ADP Vulnrichment
    CVSS 3.5
    JetBrains/YouTrackgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-38059High
    ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function
    CVSS 7.5
    ST Engineering iDirect/3315-Series, ST Engineering iDirect/9-Series Terminals +1generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-38057High
    ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery
    CVSS 8.1
    ST Engineering iDirect/3315-Series, ST Engineering iDirect/9-Series Terminals +1generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-29519High
    Lucee CFML Server Reflected XSS via URL Path Parsing
    CVSS 8.2
    lucee/Luceegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  43. CVE-2026-61456Medium
    Grav before 1.0.3 Stored XSS via SVG Upload API
    CVSS 4.6
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-61455Medium
    Grav before 2.0.1 Decompression Bomb via ZipArchiver
    CVSS 6.5
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-61450Medium
    Grav before 2.0.2 Config Exfiltration via offsetGet Filter
    CVSS 6.5
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-61444Critical
    PraisonAI before 4.6.78 Code Injection via f-string
    CVSS 9.1
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-61441Medium
    PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies
    CVSS 6.5
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  48. CVE-2026-61437High
    PraisonAI before 1.6.78 Remote Code Execution via tools.py
    CVSS 7.8
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-61434High
    PraisonAI before 4.6.78 Allowlist Bypass via find -exec
    CVSS 8.8
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  50. CVE-2026-61432Medium
    PraisonAI FastContext before 1.6.78 Path Traversal
    CVSS 5.7
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
Page 77 of 327
Previous7576777879Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,801–3,850 of 16,350 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-1667High
    SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()
    CVSS 7.2
    cifi/GEO Plugin by Squirrly SEOgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  2. CVE-2026-58493Medium
    grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction
    CVSS 5.1
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-58492Critical
    grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolation
    CVSS 9.2
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  4. CVE-2026-55890Medium
    Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()
    CVSS 4.8
    getgrav/gravcomposer · generic
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  5. CVE-2026-15377Medium
    Eleveo Call Recording Software sendlogfile improper authorization
    CVSS 4.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-55885Medium
    Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
    CVSS 6.8
    getgrav/gravcomposer · generic
    PublishedJul 10, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  7. CVE-2026-53653High
    Grav: Unauthenticated denial of service via unbounded image derivative dimensions
    CVSS 8.7
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  8. CVE-2026-54919High
    cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends
    CVSS 7.4
    yhirose/cpp-httplibgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  9. CVE-2026-39903High
    Simple Machines Forum Authorization Bypass via AttachmentApprove.php
    CVSS 7.1
    SimpleMachines/SMFgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 28, 2026View HOL analysis
  10. CVE-2026-59180Low
    Apprise forwards configured auth headers across cross-origin HTTP redirects
    CVSS 3.1
    caronc/apprisegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  11. CVE-2026-55687High
    ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsing
    CVSS 7.5
    espressif/esp-idfgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2026-54063High
    Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
    CVSS 7.5
    github.com/xuri/excelize/v2, qax-os/excelizegeneric · go
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-59162High
    Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
    CVSS 7.5
    qax-os/excelizegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026View HOL analysis
  14. CVE-2026-59161High
    Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
    CVSS 8.7
    qax-os/excelizegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026View HOL analysis
  15. CVE-2026-59154Medium
    Wekan: Checklist direct DDP updates can write checklist data into private boards
    CVSS 4.3
    wekan/wekangeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  16. CVE-2026-15376Medium
    Eleveo Call Recording Software statisticReportAction.do improper authorization
    CVSS 6.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-53657High
    Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
    CVSS 8.2
    lima-vm/limageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  18. CVE-2026-56675High
    9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
    CVSS 8.3
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-55638High
    9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
    CVSS 8.6
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  20. CVE-2026-55641High
    9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
    CVSS 8.2
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-56676High
    9router: Image prefetch DNS rebinding allows SSRF to internal services
    CVSS 7.4
    decolua/9routergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-55500Critical
    9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover
    CVSS 9.9
    9router, decolua/9routergeneric · npm
    PublishedJul 10, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-15143Critical
    Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)
    CVSS 9.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  24. CVE-2026-55501High
    9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
    CVSS 7.3
    9router, decolua/9routergeneric · npm
    PublishedJul 10, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  25. CVE-2026-15375Medium
    Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
    CVSS 4.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  26. CVE-2026-54149High
    MaxKB MCP tool import validation bypass allows post-authentication remote code execution
    CVSS 8.8
    1Panel-dev/MaxKBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  27. CVE-2026-15374Medium
    Eleveo Call Recording Software Group roleAddAction.do improper authorization
    CVSS 6.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-33382High
    Denial of service via unbounded request body size
    CVSS 7.5
    Grafana/Grafana OSSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 29, 2026View HOL analysis
  29. CVE-2026-54000High
    osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows)
    CVSS 7.0
    osquery/osquerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  30. CVE-2026-54001High
    osquery: Heap buffer overflow via `authenticode` table (Windows)
    CVSS 7.0
    osquery/osquerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  31. CVE-2026-15373Medium
    Eleveo Call Recording Software userAddAction.do improper authorization
    CVSS 6.3
    Eleveo/Call Recording Softwaregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-46388Medium
    osquery: Unprivileged users can temporarily read file carve contents
    CVSS 4.4
    osquery/osquerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-61492Low
    CISA ADP Vulnrichment
    CVSS 3.5
    JetBrains/YouTrackgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-59796High
    CISA ADP Vulnrichment
    CVSS 8.1
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  35. CVE-2026-59795High
    CISA ADP Vulnrichment
    CVSS 8.1
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-59794High
    CISA ADP Vulnrichment
    CVSS 7.3
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  37. CVE-2026-59793High
    CISA ADP Vulnrichment
    CVSS 8.8
    JetBrains/TeamCitygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-59792Critical
    CISA ADP Vulnrichment
    CVSS 9.6
    JetBrains/IntelliJ IDEAgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-59791Low
    CISA ADP Vulnrichment
    CVSS 3.5
    JetBrains/YouTrackgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-38059High
    ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function
    CVSS 7.5
    ST Engineering iDirect/3315-Series, ST Engineering iDirect/9-Series Terminals +1generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-38057High
    ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery
    CVSS 8.1
    ST Engineering iDirect/3315-Series, ST Engineering iDirect/9-Series Terminals +1generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-29519High
    Lucee CFML Server Reflected XSS via URL Path Parsing
    CVSS 8.2
    lucee/Luceegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  43. CVE-2026-61456Medium
    Grav before 1.0.3 Stored XSS via SVG Upload API
    CVSS 4.6
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-61455Medium
    Grav before 2.0.1 Decompression Bomb via ZipArchiver
    CVSS 6.5
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-61450Medium
    Grav before 2.0.2 Config Exfiltration via offsetGet Filter
    CVSS 6.5
    getgrav/gravgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  46. CVE-2026-61444Critical
    PraisonAI before 4.6.78 Code Injection via f-string
    CVSS 9.1
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-61441Medium
    PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies
    CVSS 6.5
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  48. CVE-2026-61437High
    PraisonAI before 1.6.78 Remote Code Execution via tools.py
    CVSS 7.8
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  49. CVE-2026-61434High
    PraisonAI before 4.6.78 Allowlist Bypass via find -exec
    CVSS 8.8
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  50. CVE-2026-61432Medium
    PraisonAI FastContext before 1.6.78 Path Traversal
    CVSS 5.7
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
Page 77 of 327
Previous7576777879Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard