1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings
HOL Guard on Nick Launches

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings
HOL Guard on Nick Launches

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:15 PM 16,352 active 1,443 known exploited

Catalog summary

16,352

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:15 PM 16,352 active 1,443 known exploited

Catalog summary

16,352

Active CVEs

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,851–3,900 of 16,352 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-61431Medium
    PraisonAI before 4.6.78 Path Traversal via ContextGatherer
    CVSS 5.5
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  2. CVE-2026-60091High
    PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url
    CVSS 7.2
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  3. CVE-2026-60089Medium
    PraisonAI before 1.6.78 Path Traversal via config.toml
    CVSS 5.5
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  4. CVE-2026-60086Medium
    PraisonAI before 4.6.78 Prompt Injection Defense Bypass
    CVSS 5.3
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-58661Medium
    n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
    CVSS 5.3
    n8n/n8ngeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-57994Medium
    phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints
    CVSS 5.3
    phpMyFAQ/phpMyFAQgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-57961Low
    phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function
    CVSS 2.7
    phpMyFAQ/phpMyFAQgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  8. CVE-2026-56765Critical
    Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
    CVSS 9.8
    Vikunja/Vikunjageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  9. CVE-2026-56373Low
    ImageMagick - Use-After-Free Write in PDB Decoder
    CVSS 3.7
    ImageMagick/ImageMagickgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  10. CVE-2026-56366Low
    ImageMagick - Memory Leak in META Reader APP1JPEG Error Path
    CVSS 3.3
    ImageMagick/ImageMagickgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-56354Medium
    n8n - Cross-Site Scripting and Open Redirect in Form Node
    CVSS 4.1
    n8n/n8ngeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  12. CVE-2026-56335Medium
    Capgo - Channel Configuration Mutation via Write-Scoped API Keys
    CVSS 6.5
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-56329Medium
    Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding
    CVSS 6.4
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-56312Medium
    Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint
    CVSS 6.5
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-56309Medium
    Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint
    CVSS 5.4
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-56305High
    Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
    CVSS 8.3
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-56279High
    Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint
    CVSS 7.5
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-56254High
    capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution
    CVSS 7.0
    capacitor-updater/capacitor-updatergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  19. CVE-2026-22659High
    FlaskBB Authorization Bypass via Topic ID Manipulation
    CVSS 8.1
    flaskbb/flaskbbgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  20. CVE-2026-22660High
    FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
    CVSS 7.2
    flaskbb/flaskbbgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  21. CVE-2026-56813Low
    Cookie attribute injection in Plug.Conn.Cookies.encode/2
    CVSS 2.1
    elixir-plug/pluggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-54470Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Dell/Unisphere for PowerMaxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-54469High
    CISA ADP Vulnrichment
    CVSS 8.8
    Dell/Unisphere for PowerMaxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  24. CVE-2026-54468Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Dell/Unisphere for PowerMaxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  25. CVE-2026-56688Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Dell/PowerFlex Managergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  26. CVE-2026-53363Unknown severity
    xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-56689High
    CISA ADP Vulnrichment
    CVSS 7.7
    Dell/PowerFlex Managergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  28. CVE-2026-56690High
    CISA ADP Vulnrichment
    CVSS 8.5
    Dell/PowerFlex Managergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  29. CVE-2026-56814Medium
    Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
    CVSS 6.9
    elixir-plug/pluggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  30. CVE-2026-58225Low
    SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service
    CVSS 2.1
    elixir-ecto/postgrexgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  31. CVE-2026-14461Medium
    Out-of-bound read in mtr
    CVSS 5.1
    BitWizard/mtrgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  32. CVE-2026-15028Low
    Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
    CVSS 3.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-11990Medium
    KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint
    CVSS 5.3
    iqonicdesign/KiviCare – Clinic & Patient Management System (EHR)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-13247Medium
    Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
    CVSS 6.4
    logichunt/Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcasegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  35. CVE-2026-12918Medium
    Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recipients' Parameter
    CVSS 4.9
    getwpfunnels/Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emailsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  36. CVE-2026-13710Medium
    Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget
    CVSS 6.4
    jegtheme/Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-13010Medium
    JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute
    CVSS 6.5
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-9857Medium
    Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions
    CVSS 4.3
    saskaita123/Invoice123generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-15378Critical
    Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)
    CVSS 9.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  40. CVE-2026-41879High
    Weak password hashing in R-SOFT DMS
    CVSS 8.2
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  41. CVE-2026-41878High
    Insecure Direct Object Reference in R-SOFT DMS
    CVSS 7.1
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  42. CVE-2026-41880Critical
    OS Command Injection in R-SOFT DMS
    CVSS 9.0
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  43. CVE-2026-41877Medium
    Stored XSS in R-SOFT DMS
    CVSS 5.1
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-41876High
    OS Command Injection in R-SOFT DMS
    CVSS 8.7
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-9838Medium
    ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter
    CVSS 6.1
    room34/ICS Calendargeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-15026Medium
    Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
    CVSS 4.3
    carazo/Import and export users and customersgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-11992Medium
    Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation
    CVSS 4.3
    easyappointments/Easy Appointmentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2025-11977Medium
    HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
    CVSS 6.6
    happyforms/Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Formsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-12955Medium
    Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action
    CVSS 4.3
    wplegalpages/Cookie Banner for GDPR / CCPA – WPLP Cookie Consentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-6440Medium
    GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
    CVSS 4.3
    sovlix/GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conferencegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
Page 78 of 328
Previous7677787980Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,851–3,900 of 16,352 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-61431Medium
    PraisonAI before 4.6.78 Path Traversal via ContextGatherer
    CVSS 5.5
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  2. CVE-2026-60091High
    PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url
    CVSS 7.2
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  3. CVE-2026-60089Medium
    PraisonAI before 1.6.78 Path Traversal via config.toml
    CVSS 5.5
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  4. CVE-2026-60086Medium
    PraisonAI before 4.6.78 Prompt Injection Defense Bypass
    CVSS 5.3
    MervinPraison/PraisonAIgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  5. CVE-2026-58661Medium
    n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
    CVSS 5.3
    n8n/n8ngeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-57994Medium
    phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints
    CVSS 5.3
    phpMyFAQ/phpMyFAQgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  7. CVE-2026-57961Low
    phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function
    CVSS 2.7
    phpMyFAQ/phpMyFAQgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  8. CVE-2026-56765Critical
    Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
    CVSS 9.8
    Vikunja/Vikunjageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  9. CVE-2026-56373Low
    ImageMagick - Use-After-Free Write in PDB Decoder
    CVSS 3.7
    ImageMagick/ImageMagickgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  10. CVE-2026-56366Low
    ImageMagick - Memory Leak in META Reader APP1JPEG Error Path
    CVSS 3.3
    ImageMagick/ImageMagickgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  11. CVE-2026-56354Medium
    n8n - Cross-Site Scripting and Open Redirect in Form Node
    CVSS 4.1
    n8n/n8ngeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  12. CVE-2026-56335Medium
    Capgo - Channel Configuration Mutation via Write-Scoped API Keys
    CVSS 6.5
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-56329Medium
    Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding
    CVSS 6.4
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-56312Medium
    Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint
    CVSS 6.5
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-56309Medium
    Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint
    CVSS 5.4
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-56305High
    Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
    CVSS 8.3
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-56279High
    Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint
    CVSS 7.5
    Capgo/Capgogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-56254High
    capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution
    CVSS 7.0
    capacitor-updater/capacitor-updatergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  19. CVE-2026-22659High
    FlaskBB Authorization Bypass via Topic ID Manipulation
    CVSS 8.1
    flaskbb/flaskbbgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  20. CVE-2026-22660High
    FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
    CVSS 7.2
    flaskbb/flaskbbgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  21. CVE-2026-56813Low
    Cookie attribute injection in Plug.Conn.Cookies.encode/2
    CVSS 2.1
    elixir-plug/pluggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-54470Medium
    CISA ADP Vulnrichment
    CVSS 5.3
    Dell/Unisphere for PowerMaxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  23. CVE-2026-54469High
    CISA ADP Vulnrichment
    CVSS 8.8
    Dell/Unisphere for PowerMaxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  24. CVE-2026-54468Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Dell/Unisphere for PowerMaxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  25. CVE-2026-56688Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    Dell/PowerFlex Managergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  26. CVE-2026-53363Unknown severity
    xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-56689High
    CISA ADP Vulnrichment
    CVSS 7.7
    Dell/PowerFlex Managergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  28. CVE-2026-56690High
    CISA ADP Vulnrichment
    CVSS 8.5
    Dell/PowerFlex Managergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  29. CVE-2026-56814Medium
    Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
    CVSS 6.9
    elixir-plug/pluggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  30. CVE-2026-58225Low
    SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service
    CVSS 2.1
    elixir-ecto/postgrexgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  31. CVE-2026-14461Medium
    Out-of-bound read in mtr
    CVSS 5.1
    BitWizard/mtrgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  32. CVE-2026-15028Low
    Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
    CVSS 3.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-11990Medium
    KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint
    CVSS 5.3
    iqonicdesign/KiviCare – Clinic & Patient Management System (EHR)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-13247Medium
    Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
    CVSS 6.4
    logichunt/Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcasegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  35. CVE-2026-12918Medium
    Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recipients' Parameter
    CVSS 4.9
    getwpfunnels/Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emailsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  36. CVE-2026-13710Medium
    Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget
    CVSS 6.4
    jegtheme/Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-13010Medium
    JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute
    CVSS 6.5
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-9857Medium
    Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions
    CVSS 4.3
    saskaita123/Invoice123generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-15378Critical
    Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)
    CVSS 9.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  40. CVE-2026-41879High
    Weak password hashing in R-SOFT DMS
    CVSS 8.2
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  41. CVE-2026-41878High
    Insecure Direct Object Reference in R-SOFT DMS
    CVSS 7.1
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  42. CVE-2026-41880Critical
    OS Command Injection in R-SOFT DMS
    CVSS 9.0
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  43. CVE-2026-41877Medium
    Stored XSS in R-SOFT DMS
    CVSS 5.1
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  44. CVE-2026-41876High
    OS Command Injection in R-SOFT DMS
    CVSS 8.7
    R-SOFT SERWIS/DMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-9838Medium
    ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter
    CVSS 6.1
    room34/ICS Calendargeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-15026Medium
    Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
    CVSS 4.3
    carazo/Import and export users and customersgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-11992Medium
    Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation
    CVSS 4.3
    easyappointments/Easy Appointmentsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2025-11977Medium
    HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
    CVSS 6.6
    happyforms/Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Formsgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-12955Medium
    Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action
    CVSS 4.3
    wplegalpages/Cookie Banner for GDPR / CCPA – WPLP Cookie Consentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-6440Medium
    GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
    CVSS 4.3
    sovlix/GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conferencegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
Page 78 of 328
Previous7677787980Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard