1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings
HOL Guard on Nick Launches

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings
HOL Guard on Nick Launches

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:15 PM 16,352 active 1,443 known exploited

Catalog summary

16,352

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 8:15 PM 16,352 active 1,443 known exploited

Catalog summary

16,352

Active CVEs

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,901–3,950 of 16,352 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12400Medium
    FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
    CVSS 4.3
    priyanshuchaudhary/FlowForms – Conversational Form Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-6802Medium
    Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter
    CVSS 5.3
    fahadmahmood/Easy Upload Files During Checkoutgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  3. CVE-2026-1946Medium
    GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
    CVSS 4.3
    nandhiniwp/GW AI Website Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  4. CVE-2026-14475Medium
    Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter
    CVSS 4.9
    wplegalpages/Cookie Banner for GDPR / CCPA – WPLP Cookie Consentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  5. CVE-2026-12924Medium
    Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
    CVSS 6.4
    arraytics/Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  6. CVE-2026-3907Medium
    Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode
    CVSS 6.4
    prasunsen/Hostelgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-12108Medium
    Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting
    CVSS 4.4
    looswebstudio/Highlighting Code Blockgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  8. CVE-2026-15104Medium
    BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter
    CVSS 6.5
    wpdevteam/BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbotgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  9. CVE-2026-40454High
    Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data
    CVSS 7.5
    Apache Software Foundation/Apache IoTDB C++ clientgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  10. CVE-2026-40452High
    Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users
    CVSS 7.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  11. CVE-2026-40009Medium
    Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor
    CVSS 6.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-40008Critical
    Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
    CVSS 9.8
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-40007High
    Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
    CVSS 7.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-40006High
    Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
    CVSS 7.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-40005Critical
    Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
    CVSS 9.1
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-28564Critical
    Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
    CVSS 9.8
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  17. CVE-2026-13347High
    Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter
    CVSS 7.5
    templatic1/Hide My WP Litegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  18. CVE-2026-12685High
    EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor
    CVSS 7.5
    Unknown/escortwpgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-12276Medium
    LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration
    CVSS 5.3
    Unknown/LA-Studio Element Kit for Elementorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  20. CVE-2026-12123Medium
    All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter
    CVSS 6.4
    plugins360/All-in-One Video Gallerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-21057Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  22. CVE-2026-21056Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-21055High
    CISA ADP Vulnrichment
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  24. CVE-2026-21054Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-21053Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  26. CVE-2026-21052Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  27. CVE-2026-21051Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2026-21050Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  29. CVE-2026-21049High
    CISA ADP Vulnrichment
    CVSS 8.4
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  30. CVE-2026-21048High
    CISA ADP Vulnrichment
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  31. CVE-2026-21046High
    CISA ADP Vulnrichment
    CVSS 8.4
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  32. CVE-2026-21045High
    CISA ADP Vulnrichment
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-21044Medium
    CISA ADP Vulnrichment
    CVSS 5.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-21043Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  35. CVE-2026-21042High
    CISA ADP Vulnrichment
    CVSS 8.4
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  36. CVE-2026-21041Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-21040Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-21039Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-15332Medium
    zhayujie CowAgent Message Endpoint channel.py authorization
    CVSS 6.3
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-15301Medium
    BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    digiblogger/BuddyHolis TableSearchgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-15300Critical
    GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters
    CVSS 9.1
    ninjew/GEO my WPgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-15299Medium
    Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget
    CVSS 6.4
    wealcoder/Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templatesgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-15298High
    TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title
    CVSS 7.2
    pechenki/TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram botgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-15297Medium
    Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
    CVSS 6.1
    neeraj_slit/Brevo – Email, SMS, Web Push, Chat, and more.generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-15296Medium
    affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    cservit/affiliate-toolkit – Multi-Network Affiliate & Amazon Product Displaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  46. CVE-2026-15293High
    WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification
    CVSS 8.0
    joeyoungblood/WP Business Intelligence Litegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-15292Medium
    Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute
    CVSS 6.4
    tibouille/Sudoku Shortcodegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-15291High
    Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
    CVSS 7.5
    themeatelier/ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Formgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-15290High
    Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection
    CVSS 7.5
    ultimatemember/Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugingeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-15289Medium
    Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'
    CVSS 5.9
    wpdevart/Booking calendar, Appointment Booking Systemgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
Page 79 of 328
Previous7778798081Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,901–3,950 of 16,352 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12400Medium
    FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
    CVSS 4.3
    priyanshuchaudhary/FlowForms – Conversational Form Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  2. CVE-2026-6802Medium
    Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter
    CVSS 5.3
    fahadmahmood/Easy Upload Files During Checkoutgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  3. CVE-2026-1946Medium
    GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
    CVSS 4.3
    nandhiniwp/GW AI Website Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  4. CVE-2026-14475Medium
    Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter
    CVSS 4.9
    wplegalpages/Cookie Banner for GDPR / CCPA – WPLP Cookie Consentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  5. CVE-2026-12924Medium
    Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
    CVSS 6.4
    arraytics/Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  6. CVE-2026-3907Medium
    Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode
    CVSS 6.4
    prasunsen/Hostelgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-12108Medium
    Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting
    CVSS 4.4
    looswebstudio/Highlighting Code Blockgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  8. CVE-2026-15104Medium
    BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter
    CVSS 6.5
    wpdevteam/BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbotgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  9. CVE-2026-40454High
    Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data
    CVSS 7.5
    Apache Software Foundation/Apache IoTDB C++ clientgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  10. CVE-2026-40452High
    Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users
    CVSS 7.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  11. CVE-2026-40009Medium
    Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor
    CVSS 6.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  12. CVE-2026-40008Critical
    Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
    CVSS 9.8
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  13. CVE-2026-40007High
    Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
    CVSS 7.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  14. CVE-2026-40006High
    Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
    CVSS 7.5
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  15. CVE-2026-40005Critical
    Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
    CVSS 9.1
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-28564Critical
    Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
    CVSS 9.8
    Apache Software Foundation/Apache IoTDBgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  17. CVE-2026-13347High
    Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter
    CVSS 7.5
    templatic1/Hide My WP Litegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  18. CVE-2026-12685High
    EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor
    CVSS 7.5
    Unknown/escortwpgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-12276Medium
    LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration
    CVSS 5.3
    Unknown/LA-Studio Element Kit for Elementorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  20. CVE-2026-12123Medium
    All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter
    CVSS 6.4
    plugins360/All-in-One Video Gallerygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-21057Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  22. CVE-2026-21056Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-21055High
    CISA ADP Vulnrichment
    CVSS 8.5
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  24. CVE-2026-21054Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-21053Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  26. CVE-2026-21052Medium
    CISA ADP Vulnrichment
    CVSS 6.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  27. CVE-2026-21051Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2026-21050Medium
    CISA ADP Vulnrichment
    CVSS 5.1
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  29. CVE-2026-21049High
    CISA ADP Vulnrichment
    CVSS 8.4
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  30. CVE-2026-21048High
    CISA ADP Vulnrichment
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  31. CVE-2026-21046High
    CISA ADP Vulnrichment
    CVSS 8.4
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  32. CVE-2026-21045High
    CISA ADP Vulnrichment
    CVSS 8.3
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-21044Medium
    CISA ADP Vulnrichment
    CVSS 5.8
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-21043Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  35. CVE-2026-21042High
    CISA ADP Vulnrichment
    CVSS 8.4
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 11, 2026View HOL analysis
  36. CVE-2026-21041Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-21040Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-21039Medium
    CISA ADP Vulnrichment
    CVSS 6.9
    Affected software not mappedEcosystem not listed
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-15332Medium
    zhayujie CowAgent Message Endpoint channel.py authorization
    CVSS 6.3
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-15301Medium
    BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    digiblogger/BuddyHolis TableSearchgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-15300Critical
    GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters
    CVSS 9.1
    ninjew/GEO my WPgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-15299Medium
    Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget
    CVSS 6.4
    wealcoder/Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templatesgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-15298High
    TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title
    CVSS 7.2
    pechenki/TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram botgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-15297Medium
    Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
    CVSS 6.1
    neeraj_slit/Brevo – Email, SMS, Web Push, Chat, and more.generic
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-15296Medium
    affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
    CVSS 6.4
    cservit/affiliate-toolkit – Multi-Network Affiliate & Amazon Product Displaygeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  46. CVE-2026-15293High
    WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification
    CVSS 8.0
    joeyoungblood/WP Business Intelligence Litegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-15292Medium
    Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute
    CVSS 6.4
    tibouille/Sudoku Shortcodegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-15291High
    Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
    CVSS 7.5
    themeatelier/ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Formgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-15290High
    Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection
    CVSS 7.5
    ultimatemember/Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugingeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-15289Medium
    Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'
    CVSS 5.9
    wpdevart/Booking calendar, Appointment Booking Systemgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
Page 79 of 328
Previous7778798081Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard