1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:15 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:15 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 351–400 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64665High
    Statamic: Account takeover via OAuth email matching without email-verification check
    CVSS 8.1
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-64664Medium
    Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
    CVSS 4.3
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-45414High
    Decidim: JWT-backed authentication can be replayed across organizations
    CVSS 8.5
    decidim, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-70557Medium
    diboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses Password Hashes and Salts
    CVSS 6.5
    diboot/diboot-coregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-19068Medium
    itsourcecode Hospital Management System treatmentdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-71433Medium
    LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
    CVSS 5.3
    langchain-ai/langgraph, langchain-ai/langgraph-checkpoint-postgres +3generic · pip
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-5857High
    Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments
    CVSS 8.1
    Contiki-NG/Contiki-NGgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-5856High
    Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID Validation
    CVSS 7.1
    Contiki-NG/Contiki-NGgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-48071Medium
    OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-tenant lockout
    CVSS 5.8
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  10. CVE-2026-19067Medium
    itsourcecode Hospital Management System treatment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  11. CVE-2026-64655Low
    GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
    CVSS 2.1
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  12. CVE-2026-5855High
    Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_read
    CVSS 7.5
    Contiki-NG/Contiki-NGgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-19066Medium
    SourceCodester Online Examination & Learning Management System view_students.php authorization
    CVSS 4.3
    SourceCodester/Online Examination & Learning Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-41861Medium
    Arbitrary Root File Write via Path Traversal in BOSH agent
    CVSS 4.2
    CloudFoundry Foundation/BOSHgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-64654Medium
    GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
    CVSS 5.3
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-48080High
    OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deployment
    CVSS 8.0
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-65400High
    CISA ADP Vulnrichment
    CVSS 7.1
    Apple/macOSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-19065Medium
    SourceCodester Online Examination & Learning Management System upload_files.php unrestricted upload
    CVSS 6.3
    SourceCodester/Online Examination & Learning Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-19111High
    Insecure direct object reference in Strands Agents Tools memory tool namespace isolation
    CVSS 8.1
    AWS/strands-agents-toolsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-64653Medium
    GitHub CLI: Unescaped variable components in request URLs could allow path traversal
    CVSS 5.1
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-64652Low
    GitHub CLI: Partial token disclosure in `gh auth status` output
    CVSS 3.3
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-68480Unknown severity
    x86/bugs: Make Safe-RET robust against interrupt injection
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-63725High
    sysPass FileBackupService Authenticated OS Command Injection via Backup Path
    CVSS 7.2
    nuxsmin/sysPassgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-3418Critical
    Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution
    CVSS 9.1
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +5generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-3415High
    XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service
    CVSS 8.7
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +4generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  26. CVE-2025-14561Critical
    Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
    CVSS 9.0
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +4generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2025-12317Medium
    Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges
    CVSS 5.0
    WSO2/WSO2 Enterprise Integrator, WSO2/WSO2 Identity Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2025-6508Medium
    User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended Requests
    CVSS 4.3
    WSO2/WSO2 API Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2024-6541Medium
    Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products
    CVSS 6.8
    WSO2/WSO2 API Manager, WSO2/WSO2 Enterprise Integrator +2generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19064Medium
    SourceCodester Online Examination & Learning Management System view.php authorization
    CVSS 4.3
    SourceCodester/Online Examination & Learning Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-64677Medium
    Anki's local HTTP server is vulnerable to directory traversal attacks
    CVSS 5.9
    ankitects/ankigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  32. CVE-2025-15674Low
    Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
    CVSS 2.7
    Unknown/Passstergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-16620High
    WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
    CVSS 7.5
    Unknown/WPC Name Your Price for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-16619High
    miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
    CVSS 7.5
    Unknown/miniOrange 2FAgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-19062High
    chiuwingyan house selectall.action sql injection
    CVSS 7.3
    chiuwingyan/housegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-16067Medium
    Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
    CVSS 5.3
    Unknown/Event Booking Manager for WooCommerce (Pro)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2026-15256Medium
    Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
    CVSS 4.8
    Unknown/Ninja Formsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-17032Critical
    Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
    CVSS 9.8
    Unknown/google-maps-easy-pro, Unknown/supsystic-gallery-pro +1generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-13342Medium
    Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
    CVSS 5.3
    Unknown/Security Optimizergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-15149Medium
    WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
    CVSS 5.3
    Unknown/WP Hotel Bookinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-15208Medium
    RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
    CVSS 5.3
    Unknown/RegistrationMagicgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-15147Medium
    Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
    CVSS 5.3
    Unknown/Five Star Restaurant Reservationsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-10524High
    CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
    CVSS 7.5
    Unknown/CoCartgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-71447Medium
    Stored Cross-Site Scripting in Chat and Forum Translation Controls in ail-framework
    CVSS 6.9
    ail-project/ail-frameworkgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  45. CVE-2026-14936Medium
    Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
    CVSS 5.3
    Unknown/Simple Membershipgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-14831Medium
    Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass
    CVSS 5.3
    Unknown/Easy Bookinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-19127Medium
    Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions
    CVSS 6.5
    GitroomHQ/postiz-appgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-12901Medium
    GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification
    CVSS 5.9
    Unknown/GetPaidgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-12501Medium
    WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification
    CVSS 5.3
    Unknown/WP Travel Enginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-15152Medium
    WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass
    CVSS 5.3
    Unknown/WP Hotel Bookinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 8 of 325
Previous678910Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 351–400 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64665High
    Statamic: Account takeover via OAuth email matching without email-verification check
    CVSS 8.1
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  2. CVE-2026-64664Medium
    Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
    CVSS 4.3
    statamic/cmscomposer · generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-45414High
    Decidim: JWT-backed authentication can be replayed across organizations
    CVSS 8.5
    decidim, decidim/decidimgeneric · rubygems
    PublishedAug 6, 2026First seen at HOL Jul 13, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  4. CVE-2026-70557Medium
    diboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses Password Hashes and Salts
    CVSS 6.5
    diboot/diboot-coregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-19068Medium
    itsourcecode Hospital Management System treatmentdetail.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-71433Medium
    LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
    CVSS 5.3
    langchain-ai/langgraph, langchain-ai/langgraph-checkpoint-postgres +3generic · pip
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  7. CVE-2026-5857High
    Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments
    CVSS 8.1
    Contiki-NG/Contiki-NGgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  8. CVE-2026-5856High
    Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID Validation
    CVSS 7.1
    Contiki-NG/Contiki-NGgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-48071Medium
    OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-tenant lockout
    CVSS 5.8
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  10. CVE-2026-19067Medium
    itsourcecode Hospital Management System treatment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  11. CVE-2026-64655Low
    GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
    CVSS 2.1
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  12. CVE-2026-5855High
    Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_read
    CVSS 7.5
    Contiki-NG/Contiki-NGgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-19066Medium
    SourceCodester Online Examination & Learning Management System view_students.php authorization
    CVSS 4.3
    SourceCodester/Online Examination & Learning Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  14. CVE-2026-41861Medium
    Arbitrary Root File Write via Path Traversal in BOSH agent
    CVSS 4.2
    CloudFoundry Foundation/BOSHgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  15. CVE-2026-64654Medium
    GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
    CVSS 5.3
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-48080High
    OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deployment
    CVSS 8.0
    open-reception/appointment-booking-softwaregeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  17. CVE-2026-65400High
    CISA ADP Vulnrichment
    CVSS 7.1
    Apple/macOSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-19065Medium
    SourceCodester Online Examination & Learning Management System upload_files.php unrestricted upload
    CVSS 6.3
    SourceCodester/Online Examination & Learning Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  19. CVE-2026-19111High
    Insecure direct object reference in Strands Agents Tools memory tool namespace isolation
    CVSS 8.1
    AWS/strands-agents-toolsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  20. CVE-2026-64653Medium
    GitHub CLI: Unescaped variable components in request URLs could allow path traversal
    CVSS 5.1
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  21. CVE-2026-64652Low
    GitHub CLI: Partial token disclosure in `gh auth status` output
    CVSS 3.3
    cli/cligeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  22. CVE-2026-68480Unknown severity
    x86/bugs: Make Safe-RET robust against interrupt injection
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  23. CVE-2026-63725High
    sysPass FileBackupService Authenticated OS Command Injection via Backup Path
    CVSS 7.2
    nuxsmin/sysPassgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  24. CVE-2026-3418Critical
    Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution
    CVSS 9.1
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +5generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-3415High
    XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service
    CVSS 8.7
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +4generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  26. CVE-2025-14561Critical
    Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
    CVSS 9.0
    WSO2/WSO2 API Control Plane, WSO2/WSO2 API Manager +4generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  27. CVE-2025-12317Medium
    Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges
    CVSS 5.0
    WSO2/WSO2 Enterprise Integrator, WSO2/WSO2 Identity Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  28. CVE-2025-6508Medium
    User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended Requests
    CVSS 4.3
    WSO2/WSO2 API Managergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2024-6541Medium
    Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products
    CVSS 6.8
    WSO2/WSO2 API Manager, WSO2/WSO2 Enterprise Integrator +2generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  30. CVE-2026-19064Medium
    SourceCodester Online Examination & Learning Management System view.php authorization
    CVSS 4.3
    SourceCodester/Online Examination & Learning Management Systemgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-64677Medium
    Anki's local HTTP server is vulnerable to directory traversal attacks
    CVSS 5.9
    ankitects/ankigeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  32. CVE-2025-15674Low
    Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
    CVSS 2.7
    Unknown/Passstergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  33. CVE-2026-16620High
    WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
    CVSS 7.5
    Unknown/WPC Name Your Price for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  34. CVE-2026-16619High
    miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
    CVSS 7.5
    Unknown/miniOrange 2FAgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  35. CVE-2026-19062High
    chiuwingyan house selectall.action sql injection
    CVSS 7.3
    chiuwingyan/housegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  36. CVE-2026-16067Medium
    Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
    CVSS 5.3
    Unknown/Event Booking Manager for WooCommerce (Pro)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2026-15256Medium
    Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
    CVSS 4.8
    Unknown/Ninja Formsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-17032Critical
    Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
    CVSS 9.8
    Unknown/google-maps-easy-pro, Unknown/supsystic-gallery-pro +1generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  39. CVE-2026-13342Medium
    Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
    CVSS 5.3
    Unknown/Security Optimizergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  40. CVE-2026-15149Medium
    WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
    CVSS 5.3
    Unknown/WP Hotel Bookinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  41. CVE-2026-15208Medium
    RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
    CVSS 5.3
    Unknown/RegistrationMagicgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-15147Medium
    Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
    CVSS 5.3
    Unknown/Five Star Restaurant Reservationsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  43. CVE-2026-10524High
    CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
    CVSS 7.5
    Unknown/CoCartgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  44. CVE-2026-71447Medium
    Stored Cross-Site Scripting in Chat and Forum Translation Controls in ail-framework
    CVSS 6.9
    ail-project/ail-frameworkgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  45. CVE-2026-14936Medium
    Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
    CVSS 5.3
    Unknown/Simple Membershipgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-14831Medium
    Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass
    CVSS 5.3
    Unknown/Easy Bookinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-19127Medium
    Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions
    CVSS 6.5
    GitroomHQ/postiz-appgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-12901Medium
    GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification
    CVSS 5.9
    Unknown/GetPaidgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  49. CVE-2026-12501Medium
    WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification
    CVSS 5.3
    Unknown/WP Travel Enginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  50. CVE-2026-15152Medium
    WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass
    CVSS 5.3
    Unknown/WP Hotel Bookinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
Page 8 of 325
Previous678910Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard