1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:20 PM 16,357 active 1,443 known exploited

Catalog summary

16,357

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 10:20 PM 16,357 active 1,443 known exploited

Catalog summary

16,357

Active CVEs

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,101–4,150 of 16,357 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59216High
    Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
    CVSS 7.7
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-15193Medium
    AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
    CVSS 5.3
    AidanPark/openclaw-androidgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-59219High
    Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
    CVSS 7.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  4. CVE-2026-15192Medium
    mettle sendportal APIv1 Webhooks mailjet missing authentication
    CVSS 6.5
    mettle/sendportalgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-59715Low
    Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
    CVSS 3.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-59220Medium
    Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
    CVSS 6.5
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-59226Low
    Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
    CVSS 3.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-15191Medium
    mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
    CVSS 6.3
    mettle/sendportalgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  9. CVE-2026-59227Medium
    Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
    CVSS 4.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  10. CVE-2026-59218Medium
    Open WebUI: Account enumeration via observable login timing discrepancy
    CVSS 5.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  11. CVE-2026-59214High
    Open WebUI: Stored web worker XSS via Pyodide
    CVSS 7.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2026-15190High
    SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-59209High
    n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
    CVSS 7.1
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  14. CVE-2026-59206High
    n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
    CVSS 7.1
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-15189Medium
    aerostackdev aerostack-mcp mcp-whatsapp upload_media server-side request forgery
    CVSS 6.3
    aerostackdev/aerostack-mcpgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-59208High
    n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
    CVSS 7.6
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-59207High
    n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
    CVSS 7.1
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  18. CVE-2026-42486Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-23562Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  20. CVE-2026-15188Medium
    manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmployeeProfileAPIView access control
    CVSS 6.3
    manjurulhoque/django-job-portalgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-11404High
    Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing
    CVSS 7.5
    Cesanta/Mongoosegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 28, 2026 Fix availableView HOL analysis
  22. CVE-2026-23561Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-23560Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  24. CVE-2026-23559Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  25. CVE-2026-61474Medium
    MISP: Improper sharing group authorization check when adding attributes
    CVSS 5.3
    misp/mispgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  26. CVE-2026-23556Critical
    oxenstored keeps quota related use counts across domain destruction
    CVSS 9.4
    Xen/oxenstoredgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  27. CVE-2025-58151Critical
    varstored: TOCTOU issues with mapped guest memory
    CVSS 9.4
    Xen/varstoredgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2025-58146Critical
    XAPI UTF-8 string handling
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2025-27464Critical
    WinPVDrivers: Excessive permissions on user-exposed devices
    CVSS 9.4
    Xen/Windows PV driversgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  30. CVE-2026-15187Medium
    enquirer Public Package API Enquirer.set prototype pollution
    CVSS 4.3
    n/a/enquirergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2025-27463Critical
    WinPVDrivers: Excessive permissions on user-exposed devices
    CVSS 9.4
    Xen/Windows PV driversgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2025-27462Critical
    WinPVDrivers: Excessive permissions on user-exposed devices
    CVSS 9.4
    Xen/Windows PV driversgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  33. CVE-2026-54801High
    CISA ADP Vulnrichment
    CVSS 7.2
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  34. CVE-2026-54800Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  35. CVE-2026-54799Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  36. CVE-2026-54798Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-5005Medium
    Stored XSS in Twiser's OKRs & Goals
    CVSS 5.4
    Twiser Informatics Technology Consulting, Trade and Education Inc./OKRs & Goalsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-60095Medium
    Vinchin Backup & Recovery 9.0.0.86562 Stack Buffer Overflow via ModuleHandShake
    CVSS 6.5
    Vinchin/Backup & Recovery 9.0generic
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-60094Medium
    Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server
    CVSS 6.5
    Vinchin/Backup & Recovery 9.0generic
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-4256High
    LDAP Injection in PEAKUP's PassGate
    CVSS 8.2
    PEAKUP Technology Inc./PassGategeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  41. CVE-2026-15186Medium
    macrozheng mall Portal Endpoint create resource injection
    CVSS 6.3
    macrozheng/mallgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-12879Medium
    Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
    CVSS 5.9
    Google Cloud/Apigeegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  43. CVE-2026-14261Critical
    CVE-2026-14261
    CVSS 9.1
    Xerte/Xerte Online Toolsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  44. CVE-2026-12116Critical
    CVE-2026-12116
    CVSS 9.8
    Xerte/Xerte Online Toolsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  45. CVE-2026-15185Low
    GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  46. CVE-2026-12593High
    Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem
    CVSS 8.7
    Qt/Axiviongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-15184Low
    GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
    CVSS 3.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-15182Medium
    GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
    CVSS 5.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-9253High
    WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter
    CVSS 7.2
    loopus/WP Cost Estimation & Payment Forms Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2026-58307Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
Page 83 of 328
Previous8182838485Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,101–4,150 of 16,357 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59216High
    Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
    CVSS 7.7
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-15193Medium
    AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
    CVSS 5.3
    AidanPark/openclaw-androidgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-59219High
    Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
    CVSS 7.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  4. CVE-2026-15192Medium
    mettle sendportal APIv1 Webhooks mailjet missing authentication
    CVSS 6.5
    mettle/sendportalgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-59715Low
    Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
    CVSS 3.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-59220Medium
    Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
    CVSS 6.5
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-59226Low
    Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
    CVSS 3.1
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-15191Medium
    mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
    CVSS 6.3
    mettle/sendportalgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  9. CVE-2026-59227Medium
    Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
    CVSS 4.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  10. CVE-2026-59218Medium
    Open WebUI: Account enumeration via observable login timing discrepancy
    CVSS 5.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  11. CVE-2026-59214High
    Open WebUI: Stored web worker XSS via Pyodide
    CVSS 7.3
    open-webui/open-webuigeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  12. CVE-2026-15190High
    SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
    CVSS 7.3
    SourceCodester/Simple and Nice Shopping Cart Scriptgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-59209High
    n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
    CVSS 7.1
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  14. CVE-2026-59206High
    n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
    CVSS 7.1
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-15189Medium
    aerostackdev aerostack-mcp mcp-whatsapp upload_media server-side request forgery
    CVSS 6.3
    aerostackdev/aerostack-mcpgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-59208High
    n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
    CVSS 7.6
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-59207High
    n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
    CVSS 7.1
    n8n-io/n8ngeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  18. CVE-2026-42486Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-23562Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  20. CVE-2026-15188Medium
    manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmployeeProfileAPIView access control
    CVSS 6.3
    manjurulhoque/django-job-portalgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-11404High
    Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing
    CVSS 7.5
    Cesanta/Mongoosegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 28, 2026 Fix availableView HOL analysis
  22. CVE-2026-23561Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-23560Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  24. CVE-2026-23559Critical
    Multiple RBAC issues in XAPI
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  25. CVE-2026-61474Medium
    MISP: Improper sharing group authorization check when adding attributes
    CVSS 5.3
    misp/mispgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  26. CVE-2026-23556Critical
    oxenstored keeps quota related use counts across domain destruction
    CVSS 9.4
    Xen/oxenstoredgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  27. CVE-2025-58151Critical
    varstored: TOCTOU issues with mapped guest memory
    CVSS 9.4
    Xen/varstoredgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2025-58146Critical
    XAPI UTF-8 string handling
    CVSS 9.4
    Xen/XAPIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2025-27464Critical
    WinPVDrivers: Excessive permissions on user-exposed devices
    CVSS 9.4
    Xen/Windows PV driversgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  30. CVE-2026-15187Medium
    enquirer Public Package API Enquirer.set prototype pollution
    CVSS 4.3
    n/a/enquirergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2025-27463Critical
    WinPVDrivers: Excessive permissions on user-exposed devices
    CVSS 9.4
    Xen/Windows PV driversgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2025-27462Critical
    WinPVDrivers: Excessive permissions on user-exposed devices
    CVSS 9.4
    Xen/Windows PV driversgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  33. CVE-2026-54801High
    CISA ADP Vulnrichment
    CVSS 7.2
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  34. CVE-2026-54800Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  35. CVE-2026-54799Medium
    CISA ADP Vulnrichment
    CVSS 6.7
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  36. CVE-2026-54798Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    Siemens/CPCI85 Central Processing/Communication, Siemens/SICORE Base systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-5005Medium
    Stored XSS in Twiser's OKRs & Goals
    CVSS 5.4
    Twiser Informatics Technology Consulting, Trade and Education Inc./OKRs & Goalsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-60095Medium
    Vinchin Backup & Recovery 9.0.0.86562 Stack Buffer Overflow via ModuleHandShake
    CVSS 6.5
    Vinchin/Backup & Recovery 9.0generic
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-60094Medium
    Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server
    CVSS 6.5
    Vinchin/Backup & Recovery 9.0generic
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-4256High
    LDAP Injection in PEAKUP's PassGate
    CVSS 8.2
    PEAKUP Technology Inc./PassGategeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  41. CVE-2026-15186Medium
    macrozheng mall Portal Endpoint create resource injection
    CVSS 6.3
    macrozheng/mallgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-12879Medium
    Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
    CVSS 5.9
    Google Cloud/Apigeegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  43. CVE-2026-14261Critical
    CVE-2026-14261
    CVSS 9.1
    Xerte/Xerte Online Toolsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  44. CVE-2026-12116Critical
    CVE-2026-12116
    CVSS 9.8
    Xerte/Xerte Online Toolsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  45. CVE-2026-15185Low
    GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  46. CVE-2026-12593High
    Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem
    CVSS 8.7
    Qt/Axiviongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-15184Low
    GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
    CVSS 3.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-15182Medium
    GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
    CVSS 5.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-9253High
    WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter
    CVSS 7.2
    loopus/WP Cost Estimation & Payment Forms Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2026-58307Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
Page 83 of 328
Previous8182838485Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard