1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:15 PM 16,362 active 1,443 known exploited

Catalog summary

16,362

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:15 PM 16,362 active 1,443 known exploited

Catalog summary

16,362

Active CVEs

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,151–4,200 of 16,362 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12593High
    Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem
    CVSS 8.7
    Qt/Axiviongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  2. CVE-2026-15184Low
    GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
    CVSS 3.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-15182Medium
    GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
    CVSS 5.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-9253High
    WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter
    CVSS 7.2
    loopus/WP Cost Estimation & Payment Forms Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-58307Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  6. CVE-2026-12590Low
    body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
    CVSS 3.7
    body-parser/body-parsergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  7. CVE-2026-50644High
    SQL Injection in SOPlanning Audit Retention Configuration
    CVSS 8.6
    SOPlanning/SOPlanninggeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  8. CVE-2026-58306Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  9. CVE-2026-58305Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  10. CVE-2026-58304Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  11. CVE-2026-58303Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  12. CVE-2026-12428Medium
    Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Author+) Arbitrary ACF Field Value Disclosure via 'id' Parameter
    CVSS 6.5
    gamaup/Blocks for ACF Fields — Display Custom Fields in the Block Editorgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-9021Medium
    Easy Invoice <= 2.1.19 - Unauthenticated Arbitrary Quote Accept/Decline and Invoice Creation via easy_invoice_accept_quote / easy_invoice_decline_quote AJAX Actions
    CVSS 5.3
    matrixaddons/Easy Invoice – Invoice Generator, PDF Quotes & Paymentsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  14. CVE-2026-9237Medium
    Employee, Leave and Recruitment Management System <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Job Deletion via crewhrm_singleJobAction AJAX Action
    CVSS 4.3
    crewhrm/Employee, Leave and Recruitment Management System – Crew HRMgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-9235Medium
    DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions
    CVSS 4.3
    dhlparcel/DHL eCommerce (Benelux) for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-14372High
    Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter
    CVSS 7.1
    bitpressadmin/Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  17. CVE-2026-4275High
    Divi Torque Lite <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint
    CVSS 8.8
    badhonrocks/Divi Torque Lite – Divi Modules for the Divi Builder & Themegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  18. CVE-2026-4298Medium
    DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
    CVSS 4.3
    mlfactory/DSGVO All in one for WPgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  19. CVE-2026-9028Medium
    CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter
    CVSS 5.3
    corvusinfo/CorvusPay WooCommerce Payment Gatewaygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  20. CVE-2026-9027Medium
    CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint
    CVSS 5.3
    corvusinfo/CorvusPay WooCommerce Payment Gatewaygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-13441High
    EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_event_type_background_color' Parameter
    CVSS 7.2
    metagauss/EventPrime – Events Calendar, Bookings and Ticketsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-9240Medium
    Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX action
    CVSS 4.3
    iscpcolissimo/Colissimo shipping methods for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  23. CVE-2026-56289Medium
    Loop with Unreachable Exit Condition in GNU patch
    CVSS 5.5
    GNU/patchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-56288Medium
    NULL Pointer Dereference in GNU patch
    CVSS 5.5
    GNU/patchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-56460Medium
    HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability
    CVSS 6.5
    HCLSoftware/HCL DevOps Deploy / HCL Launchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-2342Critical
    XSS in Oceanicsoft's ValeApp
    CVSS 9.3
    OceanicSoft Informatics Systems Ltd./ValeAppgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  27. CVE-2026-1989High
    IDOR in PAVO Inc.'s PAVO Pay
    CVSS 7.5
    PAVO Financial Technology Solutions Inc./PAVO Paygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-56458Medium
    HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
    CVSS 5.4
    HCLSoftware/HCL DevOps Deploygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  29. CVE-2026-1365Medium
    Information Disclosure in Sayax's OSOS
    CVSS 6.5
    Sayax Energy Technologies Inc./OSOSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  30. CVE-2026-12433Medium
    Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter
    CVSS 4.3
    themefic/Hydra Booking — Appointment Scheduling & Booking Calendargeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2026-15158Critical
    Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
    CVSS 9.8
    creativethemeshq/Blocksy Companiongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2026-5955Critical
    SQLi in Inrove Software's BiEticaret
    CVSS 9.8
    Inrove Software and Internet Services/BiEticaretgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  33. CVE-2026-56459Medium
    HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure
    CVSS 6.2
    HCLSoftware/HCL DevOps Deploy / HCL Launchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-5793Medium
    XSS in Inrove Software's BiEticaret
    CVSS 6.1
    Inrove Software and Internet Services/BiEticaretgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  35. CVE-2026-14342Medium
    Mail Mint <= 1.24.2 - Authenticated (Administrator+) SQL Injection via 'contact_ids' Parameter
    CVSS 4.9
    getwpfunnels/Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emailsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  36. CVE-2026-8848High
    Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation
    CVSS 7.2
    danieliser/Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  37. CVE-2026-14245Critical
    miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter
    CVSS 9.8
    cyberlord92/miniOrange OTP Login, Verification and SMS Notificationsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  38. CVE-2026-12418Medium
    User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter
    CVSS 5.3
    wedevs/User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registrationgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-11359Medium
    Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation
    CVSS 4.3
    metagauss/Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integrationgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  40. CVE-2026-13450Medium
    GamiPress <= 7.9.4 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter
    CVSS 5.3
    rubengc/GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  41. CVE-2026-13011Medium
    ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter
    CVSS 6.5
    wedevs/ERP: Complete HR, Accounting & CRM Suite Built for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-13334Medium
    Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter
    CVSS 6.1
    kitae-park/Mang Board WPgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  43. CVE-2026-12406Medium
    User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter
    CVSS 5.3
    wedevs/User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registrationgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  44. CVE-2026-33390High
    Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
    CVSS 8.1
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-31985High
    Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0
    CVSS 8.1
    Nozomi Networks/Remote Collectorgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  46. CVE-2026-31984High
    DoS through oversized audit log entries in Guardian/CMC before 26.2.0
    CVSS 7.5
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-31983Medium
    Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
    CVSS 5.3
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  48. CVE-2026-31982High
    Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
    CVSS 7.1
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  49. CVE-2026-31981Medium
    HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
    CVSS 5.9
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  50. CVE-2026-59269Low
    Privilege Escalation via Active Directory LDAP injection in Pinniped Supervisor can be executed by an attacker who can edit LDAP Group DN entries
    CVSS 3.8
    VMware/Pinnipedgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 84 of 328
Previous8283848586Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,151–4,200 of 16,362 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-12593High
    Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem
    CVSS 8.7
    Qt/Axiviongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  2. CVE-2026-15184Low
    GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
    CVSS 3.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-15182Medium
    GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
    CVSS 5.3
    GNU/LibreDWGgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-9253High
    WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter
    CVSS 7.2
    loopus/WP Cost Estimation & Payment Forms Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-58307Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  6. CVE-2026-12590Low
    body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
    CVSS 3.7
    body-parser/body-parsergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  7. CVE-2026-50644High
    SQL Injection in SOPlanning Audit Retention Configuration
    CVSS 8.6
    SOPlanning/SOPlanninggeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  8. CVE-2026-58306Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  9. CVE-2026-58305Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  10. CVE-2026-58304Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  11. CVE-2026-58303Medium
    CISA ADP Vulnrichment
    CVSS 6.1
    Samsung Open Source/Escargotgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  12. CVE-2026-12428Medium
    Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Author+) Arbitrary ACF Field Value Disclosure via 'id' Parameter
    CVSS 6.5
    gamaup/Blocks for ACF Fields — Display Custom Fields in the Block Editorgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-9021Medium
    Easy Invoice <= 2.1.19 - Unauthenticated Arbitrary Quote Accept/Decline and Invoice Creation via easy_invoice_accept_quote / easy_invoice_decline_quote AJAX Actions
    CVSS 5.3
    matrixaddons/Easy Invoice – Invoice Generator, PDF Quotes & Paymentsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  14. CVE-2026-9237Medium
    Employee, Leave and Recruitment Management System <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Job Deletion via crewhrm_singleJobAction AJAX Action
    CVSS 4.3
    crewhrm/Employee, Leave and Recruitment Management System – Crew HRMgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-9235Medium
    DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions
    CVSS 4.3
    dhlparcel/DHL eCommerce (Benelux) for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-14372High
    Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter
    CVSS 7.1
    bitpressadmin/Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  17. CVE-2026-4275High
    Divi Torque Lite <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint
    CVSS 8.8
    badhonrocks/Divi Torque Lite – Divi Modules for the Divi Builder & Themegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  18. CVE-2026-4298Medium
    DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
    CVSS 4.3
    mlfactory/DSGVO All in one for WPgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  19. CVE-2026-9028Medium
    CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter
    CVSS 5.3
    corvusinfo/CorvusPay WooCommerce Payment Gatewaygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  20. CVE-2026-9027Medium
    CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint
    CVSS 5.3
    corvusinfo/CorvusPay WooCommerce Payment Gatewaygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-13441High
    EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_event_type_background_color' Parameter
    CVSS 7.2
    metagauss/EventPrime – Events Calendar, Bookings and Ticketsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-9240Medium
    Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX action
    CVSS 4.3
    iscpcolissimo/Colissimo shipping methods for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  23. CVE-2026-56289Medium
    Loop with Unreachable Exit Condition in GNU patch
    CVSS 5.5
    GNU/patchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-56288Medium
    NULL Pointer Dereference in GNU patch
    CVSS 5.5
    GNU/patchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-56460Medium
    HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability
    CVSS 6.5
    HCLSoftware/HCL DevOps Deploy / HCL Launchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-2342Critical
    XSS in Oceanicsoft's ValeApp
    CVSS 9.3
    OceanicSoft Informatics Systems Ltd./ValeAppgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  27. CVE-2026-1989High
    IDOR in PAVO Inc.'s PAVO Pay
    CVSS 7.5
    PAVO Financial Technology Solutions Inc./PAVO Paygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-56458Medium
    HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
    CVSS 5.4
    HCLSoftware/HCL DevOps Deploygeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  29. CVE-2026-1365Medium
    Information Disclosure in Sayax's OSOS
    CVSS 6.5
    Sayax Energy Technologies Inc./OSOSgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  30. CVE-2026-12433Medium
    Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter
    CVSS 4.3
    themefic/Hydra Booking — Appointment Scheduling & Booking Calendargeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2026-15158Critical
    Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
    CVSS 9.8
    creativethemeshq/Blocksy Companiongeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2026-5955Critical
    SQLi in Inrove Software's BiEticaret
    CVSS 9.8
    Inrove Software and Internet Services/BiEticaretgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  33. CVE-2026-56459Medium
    HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure
    CVSS 6.2
    HCLSoftware/HCL DevOps Deploy / HCL Launchgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-5793Medium
    XSS in Inrove Software's BiEticaret
    CVSS 6.1
    Inrove Software and Internet Services/BiEticaretgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  35. CVE-2026-14342Medium
    Mail Mint <= 1.24.2 - Authenticated (Administrator+) SQL Injection via 'contact_ids' Parameter
    CVSS 4.9
    getwpfunnels/Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emailsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  36. CVE-2026-8848High
    Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation
    CVSS 7.2
    danieliser/Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  37. CVE-2026-14245Critical
    miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter
    CVSS 9.8
    cyberlord92/miniOrange OTP Login, Verification and SMS Notificationsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  38. CVE-2026-12418Medium
    User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter
    CVSS 5.3
    wedevs/User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registrationgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-11359Medium
    Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation
    CVSS 4.3
    metagauss/Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integrationgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  40. CVE-2026-13450Medium
    GamiPress <= 7.9.4 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter
    CVSS 5.3
    rubengc/GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  41. CVE-2026-13011Medium
    ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter
    CVSS 6.5
    wedevs/ERP: Complete HR, Accounting & CRM Suite Built for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-13334Medium
    Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter
    CVSS 6.1
    kitae-park/Mang Board WPgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  43. CVE-2026-12406Medium
    User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter
    CVSS 5.3
    wedevs/User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registrationgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  44. CVE-2026-33390High
    Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
    CVSS 8.1
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  45. CVE-2026-31985High
    Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0
    CVSS 8.1
    Nozomi Networks/Remote Collectorgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  46. CVE-2026-31984High
    DoS through oversized audit log entries in Guardian/CMC before 26.2.0
    CVSS 7.5
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  47. CVE-2026-31983Medium
    Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
    CVSS 5.3
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  48. CVE-2026-31982High
    Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
    CVSS 7.1
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  49. CVE-2026-31981Medium
    HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
    CVSS 5.9
    Nozomi Networks/CMC, Nozomi Networks/Guardiangeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  50. CVE-2026-59269Low
    Privilege Escalation via Active Directory LDAP injection in Pinniped Supervisor can be executed by an attacker who can edit LDAP Group DN entries
    CVSS 3.8
    VMware/Pinnipedgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 84 of 328
Previous8283848586Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard