1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 9:10 PM 16,356 active 1,443 known exploited

Catalog summary

16,356

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 9:10 PM 16,356 active 1,443 known exploited

Catalog summary

16,356

Active CVEs

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,951–4,000 of 16,356 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15292Medium
    Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute
    CVSS 6.4
    tibouille/Sudoku Shortcodegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  2. CVE-2026-15291High
    Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
    CVSS 7.5
    themeatelier/ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Formgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  3. CVE-2026-15290High
    Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection
    CVSS 7.5
    ultimatemember/Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugingeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  4. CVE-2026-15289Medium
    Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'
    CVSS 5.9
    wpdevart/Booking calendar, Appointment Booking Systemgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  5. CVE-2026-15288High
    SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation
    CVSS 7.5
    brainstormforce/SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculatorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  6. CVE-2026-15287Medium
    rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection
    CVSS 6.5
    rtcamp/rtMedia for WordPress, BuddyPress and bbPressgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-15286Medium
    Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication
    CVSS 4.3
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  8. CVE-2026-15285Medium
    The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
    CVSS 6.4
    posimyththemes/The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommercegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  9. CVE-2026-15284Medium
    King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter
    CVSS 6.4
    kingaddons/King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  10. CVE-2026-15302Medium
    ARMember <= 4.0.27 - Directory Traversal via X-FILENAME
    CVSS 5.3
    reputeinfosystems/ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  11. CVE-2026-15283Medium
    WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Site Scripting
    CVSS 4.4
    wpvividplugins/WPvivid Backup for MainWPgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2026-15282Critical
    Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    tenteeglobal/Instant Appointmentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-15331Medium
    zhayujie CowAgent Skill Installation service.py _add_package path traversal
    CVSS 5.4
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  14. CVE-2026-15330High
    zhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgery
    CVSS 7.3
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  15. CVE-2026-11818Medium
    WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API
    CVSS 5.4
    arraytics/WPCafe – Restaurant Menu, Online Food Ordering & Table Booking Systemgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  16. CVE-2026-11392Medium
    WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters
    CVSS 6.1
    thimpress/WP Hotel Bookinggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-13430High
    Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import
    CVSS 7.2
    wpazleen/Post Export Import with Mediageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  18. CVE-2026-15070High
    Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter
    CVSS 8.8
    wordpresschef/Salon Booking System – Free Versiongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-15329Medium
    zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure
    CVSS 4.3
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  20. CVE-2026-15326Low
    halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal
    CVSS 3.8
    halo-dev/halogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-54423High
    CVE Program Container
    CVSS 8.2
    OpenStack/Ironicgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-15321Low
    MyEMS Admin Backend svg.py on_post cross site scripting
    CVSS 2.4
    n/a/MyEMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-14894Critical
    Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
    CVSS 9.8
    WebRehab/Super Forms – Drag & Drop Form Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  24. CVE-2026-5069Medium
    Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'
    CVSS 5.4
    wpmanageninja/Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-15320Medium
    Sipeed PicoClaw pico.go rt.ReloadConfig authorization
    CVSS 5.4
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  26. CVE-2026-15319High
    Sipeed PicoClaw Launcher access_control.go IPAllowlist access control
    CVSS 7.3
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  27. CVE-2026-15318Medium
    Sipeed PicoClaw MQTT Channel mqtt.go authorization
    CVSS 6.3
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2026-15317Medium
    Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery
    CVSS 6.3
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2025-70796High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  30. CVE-2026-39244High
    CISA ADP Vulnrichment
    CVSS 7.5
    adm-zip, n/a/n/ageneric · npm
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  31. CVE-2026-44918Medium
    CVE Program Container
    CVSS 5.5
    OpenStack/Ironicgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  32. CVE-2026-51119Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-54771High
    Langroid: handle_message() executes user-supplied tool JSON without sender verification
    CVSS 8.1
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-54769Critical
    Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
    CVSS 10.0
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-54760Critical
    Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
    CVSS 9.3
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-15311Low
    NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
    CVSS 3.5
    NousResearch/hermes-agentgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-50181High
    Langroid: Path traversal in the file tools allows read/write outside configured current directory
    CVSS 7.1
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 2, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-50180High
    Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
    CVSS 8.7
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 2, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-55615Critical
    Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
    CVSS 9.2
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-12598High
    LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback
    CVSS 8.1
    LoginPress/LoginPress Progeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-12595High
    LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth Callback
    CVSS 8.1
    LoginPress/LoginPress Progeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-12597High
    LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback
    CVSS 8.1
    LoginPress/LoginPress Progeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-59856High
    Vim: Arbitrary Code Execution via PHP Omni-Completion
    CVSS 8.4
    vim/vimgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  44. CVE-2026-59858High
    Vim: Arbitrary Code Execution via C Omni-Completion
    CVSS 8.4
    vim/vimgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  45. CVE-2026-59857Medium
    Vim: Out-of-bounds Write in SAL Soundfolding
    CVSS 5.6
    vim/vimgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-44342Medium
    New API CSRF in email and WeChat account binding endpoints
    CVSS 5.3
    QuantumNous/new-api, github.com/QuantumNous/new-apigeneric · go
    PublishedJul 9, 2026First seen at HOL Jul 7, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-33655High
    New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
    CVSS 7.7
    QuantumNous/new-api, github.com/QuantumNous/new-apigeneric · go
    PublishedJul 9, 2026First seen at HOL Jul 7, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-57501Unknown severity
    Zen: Context-menu "Open link in glance" / "Split link in new tab" loads a page-controlled link with the System principal, bypassing the web-content scheme restriction
    Not scoredSource severity not reported
    zen-browser/desktopgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-59854Medium
    SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspace
    CVSS 4.9
    siyuan-note/siyuangeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-59853Medium
    SiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via /api/storage/getCriteria (missing publish-access filter)
    CVSS 6.5
    siyuan-note/siyuangeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
Page 80 of 328
Previous7879808182Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,457

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,951–4,000 of 16,356 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15292Medium
    Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute
    CVSS 6.4
    tibouille/Sudoku Shortcodegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  2. CVE-2026-15291High
    Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
    CVSS 7.5
    themeatelier/ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Formgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  3. CVE-2026-15290High
    Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection
    CVSS 7.5
    ultimatemember/Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugingeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  4. CVE-2026-15289Medium
    Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'
    CVSS 5.9
    wpdevart/Booking calendar, Appointment Booking Systemgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  5. CVE-2026-15288High
    SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation
    CVSS 7.5
    brainstormforce/SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculatorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  6. CVE-2026-15287Medium
    rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection
    CVSS 6.5
    rtcamp/rtMedia for WordPress, BuddyPress and bbPressgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-15286Medium
    Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication
    CVSS 4.3
    stellarwp/Kadence Blocks — Page Builder Toolkit for Gutenberg Editorgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  8. CVE-2026-15285Medium
    The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
    CVSS 6.4
    posimyththemes/The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommercegeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  9. CVE-2026-15284Medium
    King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter
    CVSS 6.4
    kingaddons/King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  10. CVE-2026-15302Medium
    ARMember <= 4.0.27 - Directory Traversal via X-FILENAME
    CVSS 5.3
    reputeinfosystems/ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  11. CVE-2026-15283Medium
    WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Site Scripting
    CVSS 4.4
    wpvividplugins/WPvivid Backup for MainWPgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2026-15282Critical
    Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
    CVSS 9.8
    tenteeglobal/Instant Appointmentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-15331Medium
    zhayujie CowAgent Skill Installation service.py _add_package path traversal
    CVSS 5.4
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  14. CVE-2026-15330High
    zhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgery
    CVSS 7.3
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  15. CVE-2026-11818Medium
    WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API
    CVSS 5.4
    arraytics/WPCafe – Restaurant Menu, Online Food Ordering & Table Booking Systemgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  16. CVE-2026-11392Medium
    WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters
    CVSS 6.1
    thimpress/WP Hotel Bookinggeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-13430High
    Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import
    CVSS 7.2
    wpazleen/Post Export Import with Mediageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  18. CVE-2026-15070High
    Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter
    CVSS 8.8
    wordpresschef/Salon Booking System – Free Versiongeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-15329Medium
    zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure
    CVSS 4.3
    zhayujie/CowAgentgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  20. CVE-2026-15326Low
    halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal
    CVSS 3.8
    halo-dev/halogeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  21. CVE-2026-54423High
    CVE Program Container
    CVSS 8.2
    OpenStack/Ironicgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-15321Low
    MyEMS Admin Backend svg.py on_post cross site scripting
    CVSS 2.4
    n/a/MyEMSgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-14894Critical
    Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
    CVSS 9.8
    WebRehab/Super Forms – Drag & Drop Form Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  24. CVE-2026-5069Medium
    Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'
    CVSS 5.4
    wpmanageninja/Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Buildergeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-15320Medium
    Sipeed PicoClaw pico.go rt.ReloadConfig authorization
    CVSS 5.4
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  26. CVE-2026-15319High
    Sipeed PicoClaw Launcher access_control.go IPAllowlist access control
    CVSS 7.3
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  27. CVE-2026-15318Medium
    Sipeed PicoClaw MQTT Channel mqtt.go authorization
    CVSS 6.3
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2026-15317Medium
    Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery
    CVSS 6.3
    Sipeed/PicoClawgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2025-70796High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  30. CVE-2026-39244High
    CISA ADP Vulnrichment
    CVSS 7.5
    adm-zip, n/a/n/ageneric · npm
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 17, 2026 Fix availableView HOL analysis
  31. CVE-2026-44918Medium
    CVE Program Container
    CVSS 5.5
    OpenStack/Ironicgeneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  32. CVE-2026-51119Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJul 10, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-54771High
    Langroid: handle_message() executes user-supplied tool JSON without sender verification
    CVSS 8.1
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  34. CVE-2026-54769Critical
    Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
    CVSS 10.0
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  35. CVE-2026-54760Critical
    Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
    CVSS 9.3
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-15311Low
    NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
    CVSS 3.5
    NousResearch/hermes-agentgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-50181High
    Langroid: Path traversal in the file tools allows read/write outside configured current directory
    CVSS 7.1
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 2, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-50180High
    Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
    CVSS 8.7
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 2, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-55615Critical
    Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
    CVSS 9.2
    langroid, langroid/langroidgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jul 6, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  40. CVE-2026-12598High
    LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback
    CVSS 8.1
    LoginPress/LoginPress Progeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-12595High
    LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth Callback
    CVSS 8.1
    LoginPress/LoginPress Progeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-12597High
    LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback
    CVSS 8.1
    LoginPress/LoginPress Progeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-59856High
    Vim: Arbitrary Code Execution via PHP Omni-Completion
    CVSS 8.4
    vim/vimgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  44. CVE-2026-59858High
    Vim: Arbitrary Code Execution via C Omni-Completion
    CVSS 8.4
    vim/vimgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 14, 2026View HOL analysis
  45. CVE-2026-59857Medium
    Vim: Out-of-bounds Write in SAL Soundfolding
    CVSS 5.6
    vim/vimgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-44342Medium
    New API CSRF in email and WeChat account binding endpoints
    CVSS 5.3
    QuantumNous/new-api, github.com/QuantumNous/new-apigeneric · go
    PublishedJul 9, 2026First seen at HOL Jul 7, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  47. CVE-2026-33655High
    New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
    CVSS 7.7
    QuantumNous/new-api, github.com/QuantumNous/new-apigeneric · go
    PublishedJul 9, 2026First seen at HOL Jul 7, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  48. CVE-2026-57501Unknown severity
    Zen: Context-menu "Open link in glance" / "Split link in new tab" loads a page-controlled link with the System principal, bypassing the web-content scheme restriction
    Not scoredSource severity not reported
    zen-browser/desktopgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-59854Medium
    SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspace
    CVSS 4.9
    siyuan-note/siyuangeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-59853Medium
    SiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via /api/storage/getCriteria (missing publish-access filter)
    CVSS 6.5
    siyuan-note/siyuangeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
Page 80 of 328
Previous7879808182Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard