1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:20 PM 16,363 active 1,443 known exploited

Catalog summary

16,363

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:20 PM 16,363 active 1,443 known exploited

Catalog summary

16,363

Active CVEs

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,201–4,250 of 16,363 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59269Low
    Privilege Escalation via Active Directory LDAP injection in Pinniped Supervisor can be executed by an attacker who can edit LDAP Group DN entries
    CVSS 3.8
    VMware/Pinnipedgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-57111High
    Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin
    CVSS 7.5
    Apache Software Foundation/Apache Helix RESTgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-6910Medium
    Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    safistudio/Bookero.pl – system rezerwacji onlinegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-8996Medium
    Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function
    CVSS 6.5
    revmakx/Backup and Staging by WP Time Capsulegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-13771Medium
    Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute
    CVSS 6.4
    ivole/Customer Reviews for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-13080Medium
    WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter
    CVSS 6.6
    getwpfunnels/WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsellgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  7. CVE-2026-7558Medium
    Age Verification & Identity Verification by Token of Trust <= 4.0.2 - Missing Authorization to Unauthenticated Information Exposure via 'tot_export_table' Parameter
    CVSS 5.3
    tokenoftrust/Age Verification & Identity Verification by Token of Trustgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-15000High
    Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values
    CVSS 7.2
    rnzo/Connect Contact Form 7 and Mailchimpgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  9. CVE-2026-14343Medium
    Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  10. CVE-2026-12170Medium
    AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute
    CVSS 6.4
    acyba/AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  11. CVE-2026-13253Medium
    Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute
    CVSS 6.4
    wpxpo/Post Grid Gutenberg Blocks – PostXgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-4653Medium
    Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter
    CVSS 6.4
    bouncingsprout/Block, Suspend, Report for BuddyPressgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-47840High
    LDAP StartTLS unconditionally disables hostname verification
    CVSS 7.5
    CloudFoundry Foundation/Cf-deployment, CloudFoundry Foundation/UAAgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  14. CVE-2026-47831High
    Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force Attacks
    CVSS 7.7
    Cloud Foundry Foundation/bosh-windows-stemcell-buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  15. CVE-2026-47830High
    Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable Overwrite
    CVSS 8.5
    Cloud Foundry Foundation/bosh-windows-stemcell-buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  16. CVE-2026-47829High
    Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director
    CVSS 7.8
    CloudFoundry Foundation/bosh-cligeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  17. CVE-2026-47828High
    Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution via Man-in-the-Middle Credential Replay
    CVSS 8.9
    BOSH-Ecosystem / BOSH (bosh-cli)/bosh-cligeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  18. CVE-2026-12517Medium
    Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint
    CVSS 5.3
    Unknown/Fediverse Embedsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  19. CVE-2026-12516Medium
    Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy
    CVSS 5.3
    Unknown/Fediverse Embedsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  20. CVE-2026-12270Medium
    Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endpoints
    CVSS 6.5
    Unknown/Everest Formsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  21. CVE-2026-11875Medium
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access via Session Cookie Forgery
    CVSS 5.3
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-11869Medium
    WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request
    CVSS 5.3
    Unknown/WP DSGVO Tools (GDPR)generic
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  23. CVE-2026-11571High
    Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts
    CVSS 7.5
    Unknown/Everest Formsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  24. CVE-2026-47826Critical
    blobs.yaml Path Traversal Allows File Writes
    CVSS 9.1
    CloudFoundry Foundation/BOSH CLI toolgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  25. CVE-2026-5523High
    Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form
    CVSS 8.8
    Divi Engine/Divi Form Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  26. CVE-2026-41857High
    BOSH CLI Shell Injection
    CVSS 7.1
    CloudFoundry BOSH/BOSH CLIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-15138Medium
    tumf mcp-text-editor text_editor.py _validate_file_path path traversal
    CVSS 6.3
    tumf/mcp-text-editorgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-15137High
    code-projects Interview Management System View.php sql injection
    CVSS 7.3
    code-projects/Interview Management Systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2025-45422High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  30. CVE-2025-63579High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  31. CVE-2026-31267Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  32. CVE-2026-38076High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-39243Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-39245Medium
    CISA ADP Vulnrichment
    CVSS 6.2
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-39246High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-51597Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-51598Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-51599Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-51600High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-51601High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-51602High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-51603High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-51604High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-51605High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-51606High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-51923High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-51924High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-51925High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-51926High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-15135High
    code-projects Online Food Order System edit_food_items.php sql injection
    CVSS 7.3
    code-projects/Online Food Order Systemgeneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 85 of 328
Previous8384858687Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,201–4,250 of 16,363 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59269Low
    Privilege Escalation via Active Directory LDAP injection in Pinniped Supervisor can be executed by an attacker who can edit LDAP Group DN entries
    CVSS 3.8
    VMware/Pinnipedgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-57111High
    Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin
    CVSS 7.5
    Apache Software Foundation/Apache Helix RESTgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-6910Medium
    Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    safistudio/Bookero.pl – system rezerwacji onlinegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-8996Medium
    Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function
    CVSS 6.5
    revmakx/Backup and Staging by WP Time Capsulegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-13771Medium
    Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute
    CVSS 6.4
    ivole/Customer Reviews for WooCommercegeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-13080Medium
    WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter
    CVSS 6.6
    getwpfunnels/WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsellgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  7. CVE-2026-7558Medium
    Age Verification & Identity Verification by Token of Trust <= 4.0.2 - Missing Authorization to Unauthenticated Information Exposure via 'tot_export_table' Parameter
    CVSS 5.3
    tokenoftrust/Age Verification & Identity Verification by Token of Trustgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-15000High
    Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values
    CVSS 7.2
    rnzo/Connect Contact Form 7 and Mailchimpgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  9. CVE-2026-14343Medium
    Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes
    CVSS 6.4
    codename065/Download Managergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  10. CVE-2026-12170Medium
    AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute
    CVSS 6.4
    acyba/AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  11. CVE-2026-13253Medium
    Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute
    CVSS 6.4
    wpxpo/Post Grid Gutenberg Blocks – PostXgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-4653Medium
    Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter
    CVSS 6.4
    bouncingsprout/Block, Suspend, Report for BuddyPressgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-47840High
    LDAP StartTLS unconditionally disables hostname verification
    CVSS 7.5
    CloudFoundry Foundation/Cf-deployment, CloudFoundry Foundation/UAAgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  14. CVE-2026-47831High
    Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force Attacks
    CVSS 7.7
    Cloud Foundry Foundation/bosh-windows-stemcell-buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  15. CVE-2026-47830High
    Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable Overwrite
    CVSS 8.5
    Cloud Foundry Foundation/bosh-windows-stemcell-buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  16. CVE-2026-47829High
    Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director
    CVSS 7.8
    CloudFoundry Foundation/bosh-cligeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  17. CVE-2026-47828High
    Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution via Man-in-the-Middle Credential Replay
    CVSS 8.9
    BOSH-Ecosystem / BOSH (bosh-cli)/bosh-cligeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  18. CVE-2026-12517Medium
    Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint
    CVSS 5.3
    Unknown/Fediverse Embedsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  19. CVE-2026-12516Medium
    Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy
    CVSS 5.3
    Unknown/Fediverse Embedsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  20. CVE-2026-12270Medium
    Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endpoints
    CVSS 6.5
    Unknown/Everest Formsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  21. CVE-2026-11875Medium
    WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access via Session Cookie Forgery
    CVSS 5.3
    Unknown/WP Support Plus Responsive Ticket Systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-11869Medium
    WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request
    CVSS 5.3
    Unknown/WP DSGVO Tools (GDPR)generic
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  23. CVE-2026-11571High
    Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts
    CVSS 7.5
    Unknown/Everest Formsgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  24. CVE-2026-47826Critical
    blobs.yaml Path Traversal Allows File Writes
    CVSS 9.1
    CloudFoundry Foundation/BOSH CLI toolgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  25. CVE-2026-5523High
    Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form
    CVSS 8.8
    Divi Engine/Divi Form Buildergeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  26. CVE-2026-41857High
    BOSH CLI Shell Injection
    CVSS 7.1
    CloudFoundry BOSH/BOSH CLIgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-15138Medium
    tumf mcp-text-editor text_editor.py _validate_file_path path traversal
    CVSS 6.3
    tumf/mcp-text-editorgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-15137High
    code-projects Interview Management System View.php sql injection
    CVSS 7.3
    code-projects/Interview Management Systemgeneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2025-45422High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  30. CVE-2025-63579High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  31. CVE-2026-31267Medium
    CISA ADP Vulnrichment
    CVSS 5.7
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  32. CVE-2026-38076High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-39243Medium
    CISA ADP Vulnrichment
    CVSS 5.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-39245Medium
    CISA ADP Vulnrichment
    CVSS 6.2
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-39246High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-51597Critical
    CISA ADP Vulnrichment
    CVSS 9.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-51598Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-51599Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  39. CVE-2026-51600High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-51601High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  41. CVE-2026-51602High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  42. CVE-2026-51603High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-51604High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  44. CVE-2026-51605High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-51606High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 9, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-51923High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-51924High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-51925High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-51926High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 9, 2026First seen at HOL Jul 10, 2026Updated Jul 10, 2026View HOL analysis
  50. CVE-2026-15135High
    code-projects Online Food Order System edit_food_items.php sql injection
    CVSS 7.3
    code-projects/Online Food Order Systemgeneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 85 of 328
Previous8384858687Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard