1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:15 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 11:15 AM 16,235 active 1,443 known exploited

Catalog summary

16,235

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 401–450 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14225Low
    Easy Appointments <= 3.12.26 - Contributor+ Shortcode Allowlist Bypass
    CVSS 2.7
    Unknown/Easy Appointmentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-14842Medium
    Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass
    CVSS 5.3
    Unknown/Events Made Easygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-19061Low
    Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList data authenticity
    CVSS 3.7
    Insta/InstaKNXServiceAppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  4. CVE-2026-71446Medium
    Stored Cross-Site Scripting in AIL Framework Domain Screenshot View
    CVSS 6.9
    ail-project/ail-frameworkgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-70635High
    TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index
    CVSS 7.1
    timescale/timescaledbgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-70634High
    TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator
    CVSS 8.1
    timescale/timescaledbgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-14812Critical
    Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
    CVSS 10.0
    Unknown/Premium SEOgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2026-13399High
    Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order
    CVSS 7.5
    Unknown/Payment Plugins for PayPal WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-70633Medium
    TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Iterator
    CVSS 6.5
    timescale/timescaledbgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-14306Medium
    Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass
    CVSS 4.3
    Unknown/Tutor LMSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-71445High
    Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-framework
    CVSS 8.2
    ail-project/ail-frameworkgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-12584High
    Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
    CVSS 7.5
    Unknown/Payment Gateway for Redsys & WooCommerce Litegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-11361Medium
    Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
    CVSS 5.9
    Unknown/Formidable Formsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-10599High
    Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
    CVSS 7.5
    Unknown/Integrate PhonePe with WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-19060Medium
    FoundationAgents MetaGPT code injection
    CVSS 5.3
    FoundationAgents/MetaGPTgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-11976Critical
    MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
    CVSS 10.0
    Unknown/MonsterInsights Progeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-71327High
    Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
    CVSS 7.6
    github.com/traefik/traefik/v3, traefik/traefikgeneric · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-5336Medium
    Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure
    CVSS 6.8
    Unknown/DataPress (Dataverse Integration)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-71326Low
    Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
    CVSS 2.1
    github.com/traefik/traefik/v3, traefik/traefikgeneric · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  20. CVE-2026-18487Medium
    Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()
    CVSS 5.4
    GNOME/Epiphanygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-7406High
    BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products
    CVSS 7.8
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +2generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-19059Low
    FoundationAgents MetaGPT editor.py read path traversal
    CVSS 3.3
    FoundationAgents/MetaGPTgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-71325Medium
    Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
    CVSS 4.8
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-7405Medium
    TIF File Parsing Out-of-Bounds Read in certain Autodesk products
    CVSS 5.5
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +2generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-11803High
    PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit
    CVSS 7.8
    Autodesk/Revitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-8325High
    PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit
    CVSS 7.8
    Autodesk/Revitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  27. CVE-2026-1289High
    PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit
    CVSS 7.8
    Autodesk/Revitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  28. CVE-2026-71324High
    Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
    CVSS 7.0
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2026-43632High
    llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints
    CVSS 8.1
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  30. CVE-2026-43631High
    llama.cpp b7492–b9060 Use-After-Free RCE via llama-server
    CVSS 8.1
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-43630Medium
    llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
    CVSS 6.5
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  32. CVE-2026-43629High
    llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore
    CVSS 8.1
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  33. CVE-2026-43628High
    llama.cpp b3978–b9058 Integer Underflow via DRY Sampler
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  34. CVE-2026-19058Medium
    FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection
    CVSS 5.3
    FoundationAgents/MetaGPTgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  35. CVE-2026-43627High
    llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  36. CVE-2026-70640High
    llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp
    CVSS 7.0
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-53983High
    Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL
    CVSS 8.6
    Efstratios Goudelis/Ground Stationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-70639Medium
    llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cpp
    CVSS 5.5
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-7867High
    Udisks2: udisks2: local privilege escalation via as-user option spoofing
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  40. CVE-2026-70638High
    llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  41. CVE-2026-53984Critical
    Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Data Injection via Socket.IO database_backup full_restore Action
    CVSS 9.1
    Efstratios Goudelis/Ground Stationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-19054Medium
    Lspace-io lspace-server Repositories File API repository.ts deleteFile path traversal
    CVSS 5.3
    Lspace-io/lspace-servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  43. CVE-2026-43622High
    llama.cpp b1886–b7445 Double Free via llama-android.cpp
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  44. CVE-2026-53985High
    Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO
    CVSS 7.5
    Efstratios Goudelis/Ground Stationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-5423High
    Subscription Authentication Bypass via Unverified connectionParams.jwt
    CVSS 8.2
    neo4j/graphqlgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  46. CVE-2026-18258High
    Authorization Bypass Through User-Controlled Key in eScriptorium
    CVSS 8.8
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-18277High
    Missing Authorization in eScriptorium
    CVSS 7.1
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-18359High
    Server-Side Request Forgery (SSRF) in eScriptorium
    CVSS 8.5
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-18275Medium
    Authorization Bypass Through User-Controlled Key in eScriptorium
    CVSS 6.5
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-18276Medium
    Missing Authorization in eScriptorium
    CVSS 4.3
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 9 of 325
Previous7891011Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 401–450 of 16,235 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14225Low
    Easy Appointments <= 3.12.26 - Contributor+ Shortcode Allowlist Bypass
    CVSS 2.7
    Unknown/Easy Appointmentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  2. CVE-2026-14842Medium
    Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass
    CVSS 5.3
    Unknown/Events Made Easygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  3. CVE-2026-19061Low
    Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList data authenticity
    CVSS 3.7
    Insta/InstaKNXServiceAppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  4. CVE-2026-71446Medium
    Stored Cross-Site Scripting in AIL Framework Domain Screenshot View
    CVSS 6.9
    ail-project/ail-frameworkgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  5. CVE-2026-70635High
    TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index
    CVSS 7.1
    timescale/timescaledbgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  6. CVE-2026-70634High
    TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator
    CVSS 8.1
    timescale/timescaledbgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  7. CVE-2026-14812Critical
    Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
    CVSS 10.0
    Unknown/Premium SEOgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  8. CVE-2026-13399High
    Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order
    CVSS 7.5
    Unknown/Payment Plugins for PayPal WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  9. CVE-2026-70633Medium
    TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Iterator
    CVSS 6.5
    timescale/timescaledbgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  10. CVE-2026-14306Medium
    Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass
    CVSS 4.3
    Unknown/Tutor LMSgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  11. CVE-2026-71445High
    Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-framework
    CVSS 8.2
    ail-project/ail-frameworkgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  12. CVE-2026-12584High
    Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
    CVSS 7.5
    Unknown/Payment Gateway for Redsys & WooCommerce Litegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  13. CVE-2026-11361Medium
    Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
    CVSS 5.9
    Unknown/Formidable Formsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  14. CVE-2026-10599High
    Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
    CVSS 7.5
    Unknown/Integrate PhonePe with WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  15. CVE-2026-19060Medium
    FoundationAgents MetaGPT code injection
    CVSS 5.3
    FoundationAgents/MetaGPTgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  16. CVE-2026-11976Critical
    MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
    CVSS 10.0
    Unknown/MonsterInsights Progeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  17. CVE-2026-71327High
    Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
    CVSS 7.6
    github.com/traefik/traefik/v3, traefik/traefikgeneric · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  18. CVE-2026-5336Medium
    Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure
    CVSS 6.8
    Unknown/DataPress (Dataverse Integration)generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  19. CVE-2026-71326Low
    Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
    CVSS 2.1
    github.com/traefik/traefik/v3, traefik/traefikgeneric · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  20. CVE-2026-18487Medium
    Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()
    CVSS 5.4
    GNOME/Epiphanygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-7406High
    BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products
    CVSS 7.8
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +2generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  22. CVE-2026-19059Low
    FoundationAgents MetaGPT editor.py read path traversal
    CVSS 3.3
    FoundationAgents/MetaGPTgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  23. CVE-2026-71325Medium
    Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
    CVSS 4.8
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  24. CVE-2026-7405Medium
    TIF File Parsing Out-of-Bounds Read in certain Autodesk products
    CVSS 5.5
    Autodesk/AutoCAD, Autodesk/AutoCAD LT +2generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  25. CVE-2026-11803High
    PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit
    CVSS 7.8
    Autodesk/Revitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  26. CVE-2026-8325High
    PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit
    CVSS 7.8
    Autodesk/Revitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  27. CVE-2026-1289High
    PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit
    CVSS 7.8
    Autodesk/Revitgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026 Fix availableView HOL analysis
  28. CVE-2026-71324High
    Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
    CVSS 7.0
    github.com/traefik/traefik, github.com/traefik/traefik/v2 +2generic · go
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  29. CVE-2026-43632High
    llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints
    CVSS 8.1
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  30. CVE-2026-43631High
    llama.cpp b7492–b9060 Use-After-Free RCE via llama-server
    CVSS 8.1
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  31. CVE-2026-43630Medium
    llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
    CVSS 6.5
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  32. CVE-2026-43629High
    llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore
    CVSS 8.1
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  33. CVE-2026-43628High
    llama.cpp b3978–b9058 Integer Underflow via DRY Sampler
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  34. CVE-2026-19058Medium
    FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection
    CVSS 5.3
    FoundationAgents/MetaGPTgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  35. CVE-2026-43627High
    llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  36. CVE-2026-70640High
    llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp
    CVSS 7.0
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  37. CVE-2026-53983High
    Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL
    CVSS 8.6
    Efstratios Goudelis/Ground Stationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-70639Medium
    llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cpp
    CVSS 5.5
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  39. CVE-2026-7867High
    Udisks2: udisks2: local privilege escalation via as-user option spoofing
    CVSS 7.8
    Affected software not mappedEcosystem not listed
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  40. CVE-2026-70638High
    llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  41. CVE-2026-53984Critical
    Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Data Injection via Socket.IO database_backup full_restore Action
    CVSS 9.1
    Efstratios Goudelis/Ground Stationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  42. CVE-2026-19054Medium
    Lspace-io lspace-server Repositories File API repository.ts deleteFile path traversal
    CVSS 5.3
    Lspace-io/lspace-servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  43. CVE-2026-43622High
    llama.cpp b1886–b7445 Double Free via llama-android.cpp
    CVSS 7.8
    ggml-org/llama.cppgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 7, 2026View HOL analysis
  44. CVE-2026-53985High
    Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO
    CVSS 7.5
    Efstratios Goudelis/Ground Stationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  45. CVE-2026-5423High
    Subscription Authentication Bypass via Unverified connectionParams.jwt
    CVSS 8.2
    neo4j/graphqlgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  46. CVE-2026-18258High
    Authorization Bypass Through User-Controlled Key in eScriptorium
    CVSS 8.8
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-18277High
    Missing Authorization in eScriptorium
    CVSS 7.1
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-18359High
    Server-Side Request Forgery (SSRF) in eScriptorium
    CVSS 8.5
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-18275Medium
    Authorization Bypass Through User-Controlled Key in eScriptorium
    CVSS 6.5
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-18276Medium
    Missing Authorization in eScriptorium
    CVSS 4.3
    Scripta/eScriptoriumgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 9 of 325
Previous7891011Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard