1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:20 PM 16,357 active 1,443 known exploited

Catalog summary

16,357

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:20 PM 16,357 active 1,443 known exploited

Catalog summary

16,357

Active CVEs

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,051–4,100 of 16,357 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-0276High
    Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
    CVSS 7.8
    Palo Alto Networks/Cortex XDR Broker VMgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-0277Medium
    Prisma Access Agent: Improper Certificate Validation on iOS
    CVSS 5.9
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-0278High
    Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
    CVSS 7.8
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-0279Medium
    PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
    CVSS 6.1
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Accessgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  5. CVE-2026-0280High
    PAN-OS: IPv6 Firewall Policy Bypass
    CVSS 7.2
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Accessgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-0281High
    PAN-OS: Information Disclosure Vulnerability in Management Web Interface
    CVSS 7.1
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-0282Medium
    PAN-OS: File Deletion Vulnerability in Management Web Interface
    CVSS 6.5
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  8. CVE-2026-0283High
    PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
    CVSS 7.2
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  9. CVE-2026-0284Critical
    PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
    CVSS 9.9
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  10. CVE-2026-0285Medium
    PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
    CVSS 4.9
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  11. CVE-2026-0286High
    PAN-OS: Authenticated Command Injection in CLI
    CVSS 7.2
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  12. CVE-2026-55590Medium
    CakePHP: Open redirect weakness via backslash bypass
    CVSS 6.1
    cakephp/authenticationcomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  13. CVE-2026-54695High
    Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
    CVSS 7.5
    pipecat-ai, pipecat-ai/pipecatgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  14. CVE-2026-0287High
    PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
    CVSS 7.5
    Palo Alto Networks/Cloud NGFW, Palo Alto Networks/PAN-OS +1generic
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  15. CVE-2026-49276High
    Kirby: Self cross-site scripting (self-XSS) in the writer field
    CVSS 7.4
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-54005High
    Kirby: `pages.access` permission is not checked in the `site/find` REST API route
    CVSS 7.1
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-50188Medium
    Kirby: Request header injection in `Http\Remote`
    CVSS 6.9
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-54004Medium
    Kirby: Access to files of top-level drafts is not protected by permissions
    CVSS 6.3
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  19. CVE-2026-49274Medium
    Kirby: `pages.access` permission is not checked in the pages picker for parent pages
    CVSS 5.3
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-54003Critical
    Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
    CVSS 9.1
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  21. CVE-2026-54002High
    Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
    CVSS 8.5
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-13492High
    UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field
    CVSS 8.8
    stiofansisland/UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-58198Unknown severity
    ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
    Not scoredSource severity not reported
    gunthercox/ChatterBotgeneric
    PublishedJul 9, 2026First seen at HOL Aug 6, 2026Updated Jul 9, 2026View HOL analysis
  24. CVE-2026-59149Medium
    Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
    CVSS 6.5
    mockoon/mockoongeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-59148High
    Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
    CVSS 8.8
    mockoon/mockoongeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  26. CVE-2026-55420High
    Discourse: Remote code execution via pdf uploads
    CVSS 7.5
    discourse/discoursegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  27. CVE-2026-59826Critical
    Metabase: Arbitrary Code Execution via Database Connection Detail Bypass
    CVSS 9.1
    metabase/metabasegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2026-15204Medium
    TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
    CVSS 5.3
    TOTOLINK/X5000Rgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2026-59827Critical
    Metabase: Unsafe Deserialization of H2 Query Results
    CVSS 9.9
    metabase/metabasegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-59817Medium
    Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
    CVSS 5.3
    TryGhost/Ghost, ghostgeneric · npm
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  31. CVE-2026-59734High
    Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2026-59726Critical
    Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
    CVSS 10.0
    ruvnet/ruflogeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-15202Medium
    YzmCMS Header yzmphp.php get_url cross site scripting
    CVSS 4.3
    n/a/YzmCMSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  34. CVE-2026-59720High
    Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server
    CVSS 7.5
    hoppscotch/hoppscotchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  35. CVE-2026-59721High
    Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
    CVSS 7.2
    hoppscotch/hoppscotchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  36. CVE-2026-43752Medium
    CISA ADP Vulnrichment
    CVSS 4.9
    Claris/FileMaker Servergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  37. CVE-2026-15195Medium
    apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
    CVSS 6.3
    apidevtools/json-schema-ref-parsergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  38. CVE-2026-59221High
    open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
    CVSS 7.7
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-59225Medium
    Open WebUI: Arena task endpoints can bypass underlying model access controls
    CVSS 5.4
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  40. CVE-2026-15308Critical
    Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
    CVSS 10.0
    Python Software Foundation/CPythongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-13462Unknown severity
    PayRange for Android, version 7.0.7, contains an SSL bypass vulnerability
    Not scoredSource severity not reported
    PayRange/PayRangegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-59224High
    Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
    CVSS 8.0
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-13461Critical
    PayRange version 7.0.7 contains a JavaScript injection vulnerability
    CVSS 9.6
    PayRange/PayRangegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-59212Medium
    Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
    CVSS 5.4
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-59223Medium
    Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
    CVSS 4.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-15194Low
    Open5GS AMF context.c amf_context_final use after free
    CVSS 3.3
    n/a/Open5GSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Aug 8, 2026View HOL analysis
  47. CVE-2026-59222Medium
    Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
    CVSS 6.5
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-59215Low
    Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
    CVSS 3.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-59213Low
    Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
    CVSS 3.5
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-59217Medium
    Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
    CVSS 4.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
Page 82 of 328
Previous8081828384Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,051–4,100 of 16,357 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-0276High
    Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
    CVSS 7.8
    Palo Alto Networks/Cortex XDR Broker VMgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-0277Medium
    Prisma Access Agent: Improper Certificate Validation on iOS
    CVSS 5.9
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-0278High
    Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
    CVSS 7.8
    Palo Alto Networks/Prisma Access Agentgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-0279Medium
    PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
    CVSS 6.1
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Accessgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  5. CVE-2026-0280High
    PAN-OS: IPv6 Firewall Policy Bypass
    CVSS 7.2
    Palo Alto Networks/PAN-OS, Palo Alto Networks/Prisma Accessgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  6. CVE-2026-0281High
    PAN-OS: Information Disclosure Vulnerability in Management Web Interface
    CVSS 7.1
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  7. CVE-2026-0282Medium
    PAN-OS: File Deletion Vulnerability in Management Web Interface
    CVSS 6.5
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  8. CVE-2026-0283High
    PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
    CVSS 7.2
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  9. CVE-2026-0284Critical
    PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
    CVSS 9.9
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  10. CVE-2026-0285Medium
    PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
    CVSS 4.9
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  11. CVE-2026-0286High
    PAN-OS: Authenticated Command Injection in CLI
    CVSS 7.2
    Palo Alto Networks/PAN-OSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  12. CVE-2026-55590Medium
    CakePHP: Open redirect weakness via backslash bypass
    CVSS 6.1
    cakephp/authenticationcomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  13. CVE-2026-54695High
    Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
    CVSS 7.5
    pipecat-ai, pipecat-ai/pipecatgeneric · pip
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  14. CVE-2026-0287High
    PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
    CVSS 7.5
    Palo Alto Networks/Cloud NGFW, Palo Alto Networks/PAN-OS +1generic
    PublishedJul 9, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  15. CVE-2026-49276High
    Kirby: Self cross-site scripting (self-XSS) in the writer field
    CVSS 7.4
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  16. CVE-2026-54005High
    Kirby: `pages.access` permission is not checked in the `site/find` REST API route
    CVSS 7.1
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  17. CVE-2026-50188Medium
    Kirby: Request header injection in `Http\Remote`
    CVSS 6.9
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  18. CVE-2026-54004Medium
    Kirby: Access to files of top-level drafts is not protected by permissions
    CVSS 6.3
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  19. CVE-2026-49274Medium
    Kirby: `pages.access` permission is not checked in the pages picker for parent pages
    CVSS 5.3
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  20. CVE-2026-54003Critical
    Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
    CVSS 9.1
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  21. CVE-2026-54002High
    Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
    CVSS 8.5
    getkirby/cms, getkirby/kirbycomposer · generic
    PublishedJul 9, 2026First seen at HOL Jun 19, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  22. CVE-2026-13492High
    UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field
    CVSS 8.8
    stiofansisland/UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPgeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-58198Unknown severity
    ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
    Not scoredSource severity not reported
    gunthercox/ChatterBotgeneric
    PublishedJul 9, 2026First seen at HOL Aug 6, 2026Updated Jul 9, 2026View HOL analysis
  24. CVE-2026-59149Medium
    Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
    CVSS 6.5
    mockoon/mockoongeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-59148High
    Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
    CVSS 8.8
    mockoon/mockoongeneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  26. CVE-2026-55420High
    Discourse: Remote code execution via pdf uploads
    CVSS 7.5
    discourse/discoursegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  27. CVE-2026-59826Critical
    Metabase: Arbitrary Code Execution via Database Connection Detail Bypass
    CVSS 9.1
    metabase/metabasegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  28. CVE-2026-15204Medium
    TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
    CVSS 5.3
    TOTOLINK/X5000Rgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2026-59827Critical
    Metabase: Unsafe Deserialization of H2 Query Results
    CVSS 9.9
    metabase/metabasegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-59817Medium
    Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
    CVSS 5.3
    TryGhost/Ghost, ghostgeneric · npm
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Aug 4, 2026 Fix availableView HOL analysis
  31. CVE-2026-59734High
    Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
    CVSS 8.8
    coollabsio/coolifygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2026-59726Critical
    Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
    CVSS 10.0
    ruvnet/ruflogeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-15202Medium
    YzmCMS Header yzmphp.php get_url cross site scripting
    CVSS 4.3
    n/a/YzmCMSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  34. CVE-2026-59720High
    Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server
    CVSS 7.5
    hoppscotch/hoppscotchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  35. CVE-2026-59721High
    Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
    CVSS 7.2
    hoppscotch/hoppscotchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  36. CVE-2026-43752Medium
    CISA ADP Vulnrichment
    CVSS 4.9
    Claris/FileMaker Servergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  37. CVE-2026-15195Medium
    apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
    CVSS 6.3
    apidevtools/json-schema-ref-parsergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  38. CVE-2026-59221High
    open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
    CVSS 7.7
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-59225Medium
    Open WebUI: Arena task endpoints can bypass underlying model access controls
    CVSS 5.4
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  40. CVE-2026-15308Critical
    Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
    CVSS 10.0
    Python Software Foundation/CPythongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  41. CVE-2026-13462Unknown severity
    PayRange for Android, version 7.0.7, contains an SSL bypass vulnerability
    Not scoredSource severity not reported
    PayRange/PayRangegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-59224High
    Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
    CVSS 8.0
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-13461Critical
    PayRange version 7.0.7 contains a JavaScript injection vulnerability
    CVSS 9.6
    PayRange/PayRangegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-59212Medium
    Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
    CVSS 5.4
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-59223Medium
    Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
    CVSS 4.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-15194Low
    Open5GS AMF context.c amf_context_final use after free
    CVSS 3.3
    n/a/Open5GSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Aug 8, 2026View HOL analysis
  47. CVE-2026-59222Medium
    Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
    CVSS 6.5
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-59215Low
    Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
    CVSS 3.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-59213Low
    Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
    CVSS 3.5
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-59217Medium
    Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
    CVSS 4.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
Page 82 of 328
Previous8081828384Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard