1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 2:30 AM 16,371 active 1,443 known exploited

Catalog summary

16,371

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 2:30 AM 16,371 active 1,443 known exploited

Catalog summary

16,371

Active CVEs

8,462

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,501–4,550 of 16,371 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15033Medium
    christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection
    CVSS 6.3
    christopherthielen/check-peer-dependenciesgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  2. CVE-2026-6740Medium
    Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute
    CVSS 6.4
    posimyththemes/Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Buildergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  3. CVE-2026-6820High
    VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field
    CVSS 7.2
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  4. CVE-2026-12002Medium
    Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter
    CVSS 4.7
    smub/Smash Balloon Social Photo Feed – Easy Social Feeds Plugingeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  5. CVE-2026-5459Medium
    User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite
    CVSS 5.3
    wedevs/User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registrationgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  6. CVE-2026-6459Medium
    Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup
    CVSS 6.4
    wpdevteam/Essential Addons for Elementor – Popular Elementor Templates & Widgetsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-5356High
    LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
    CVSS 7.5
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  8. CVE-2026-14454Critical
    Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
    CVSS 9.8
    TONYC/Imagergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  9. CVE-2026-8315Medium
    Stored XSS in Webbeyaz's Mediküm Web
    CVSS 5.4
    Webbeyaz Web Design/Mediküm Webgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  10. CVE-2026-8310Medium
    Reflected XSS in Webbeyaz's Mediküm Web
    CVSS 6.1
    Webbeyaz Web Design/Mediküm Webgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  11. CVE-2026-8307Critical
    SQLi in Webbeyaz's Mediküm Web
    CVSS 9.8
    Webbeyaz Web Design/Mediküm Webgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-41042Critical
    Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
    CVSS 9.1
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-3688High
    WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite
    CVSS 8.1
    wclovers/WCFM Membership – WooCommerce Memberships for Multivendor Marketplacegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2026-6742Medium
    Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute
    CVSS 6.4
    mdempfle/Advanced iFramegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  15. CVE-2025-14785Medium
    Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode
    CVSS 6.4
    seedprod/Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Modegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  16. CVE-2026-6854High
    My Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters
    CVSS 7.5
    joedolson/My Calendar – Accessible Event Managergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  17. CVE-2026-14250Medium
    Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter
    CVSS 6.3
    themehunk/TH Login Registrationgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-12936Medium
    Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Parameter
    CVSS 4.9
    devitemsllc/Recurio – Ultimate Subscription for WooCommercegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  19. CVE-2026-6230High
    Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter
    CVSS 7.5
    tainacan/Tainacangeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-6818High
    VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter
    CVSS 7.2
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  21. CVE-2026-15041Low
    389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-56003High
    libXfont2 computeProps Property Buffer Heap Buffer Overflow
    CVSS 8.5
    X.Org/libXfont2generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  23. CVE-2026-56002High
    libXfont2 PCF Font Parsing Heap Buffer Overflow
    CVSS 8.5
    X.Org/libXfont2generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  24. CVE-2026-56001High
    libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
    CVSS 8.5
    X.Org/libXfont2generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  25. CVE-2026-6280Medium
    Improper Access Control in Nomysoft Informatics' Nomysem
    CVSS 6.5
    NOMYSOFT Informatics Education and Consulting Inc./Nomysemgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2026-55999High
    xorg-server / xwayland glamor font atlas Heap Buffer Overflow
    CVSS 8.5
    X.Org/xorg-server, X.Org/xwaylandgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  27. CVE-2026-13126High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-13127High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2026-13128High
    Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  30. CVE-2026-57239High
    Foxit PDF Editor/Reader Local Privilege Escalation
    CVSS 8.2
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2026-57240High
    Foxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2026-13129High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  33. CVE-2026-57238High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  34. CVE-2026-57241Medium
    Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  35. CVE-2026-57242High
    Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  36. CVE-2026-57243Medium
    Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  37. CVE-2026-57245High
    Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  38. CVE-2026-57246High
    Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-57248High
    Foxit PDF Editor/Reader Annotation Improper Release Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  40. CVE-2026-57249High
    Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  41. CVE-2026-57251High
    Foxit PDF Editor/Reader Cloud Appearance Buffer Overflow Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-56000Critical
    xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
    CVSS 9.0
    X.Org/xorg-x11-server, X.Org/xwaylandgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  43. CVE-2026-57253Medium
    Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  44. CVE-2026-57252High
    Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  45. CVE-2026-57254High
    Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  46. CVE-2026-57255Medium
    Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  47. CVE-2026-57259Medium
    Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
    CVSS 6.5
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-57237High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-57244High
    Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2026-57247High
    Foxit PDF Editor/Reader Field Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
Page 91 of 328
Previous8990919293Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,462

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,501–4,550 of 16,371 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-15033Medium
    christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection
    CVSS 6.3
    christopherthielen/check-peer-dependenciesgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  2. CVE-2026-6740Medium
    Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute
    CVSS 6.4
    posimyththemes/Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Buildergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  3. CVE-2026-6820High
    VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field
    CVSS 7.2
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  4. CVE-2026-12002Medium
    Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter
    CVSS 4.7
    smub/Smash Balloon Social Photo Feed – Easy Social Feeds Plugingeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  5. CVE-2026-5459Medium
    User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite
    CVSS 5.3
    wedevs/User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registrationgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  6. CVE-2026-6459Medium
    Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup
    CVSS 6.4
    wpdevteam/Essential Addons for Elementor – Popular Elementor Templates & Widgetsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  7. CVE-2026-5356High
    LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
    CVSS 7.5
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  8. CVE-2026-14454Critical
    Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
    CVSS 9.8
    TONYC/Imagergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  9. CVE-2026-8315Medium
    Stored XSS in Webbeyaz's Mediküm Web
    CVSS 5.4
    Webbeyaz Web Design/Mediküm Webgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  10. CVE-2026-8310Medium
    Reflected XSS in Webbeyaz's Mediküm Web
    CVSS 6.1
    Webbeyaz Web Design/Mediküm Webgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  11. CVE-2026-8307Critical
    SQLi in Webbeyaz's Mediküm Web
    CVSS 9.8
    Webbeyaz Web Design/Mediküm Webgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-41042Critical
    Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
    CVSS 9.1
    Apache Software Foundation/Apache Gravitinogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  13. CVE-2026-3688High
    WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite
    CVSS 8.1
    wclovers/WCFM Membership – WooCommerce Memberships for Multivendor Marketplacegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2026-6742Medium
    Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute
    CVSS 6.4
    mdempfle/Advanced iFramegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  15. CVE-2025-14785Medium
    Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode
    CVSS 6.4
    seedprod/Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Modegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  16. CVE-2026-6854High
    My Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters
    CVSS 7.5
    joedolson/My Calendar – Accessible Event Managergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  17. CVE-2026-14250Medium
    Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter
    CVSS 6.3
    themehunk/TH Login Registrationgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-12936Medium
    Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Parameter
    CVSS 4.9
    devitemsllc/Recurio – Ultimate Subscription for WooCommercegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  19. CVE-2026-6230High
    Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter
    CVSS 7.5
    tainacan/Tainacangeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-6818High
    VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter
    CVSS 7.2
    e4jvikwp/VikBooking Hotel Booking Engine & PMSgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  21. CVE-2026-15041Low
    389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-56003High
    libXfont2 computeProps Property Buffer Heap Buffer Overflow
    CVSS 8.5
    X.Org/libXfont2generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  23. CVE-2026-56002High
    libXfont2 PCF Font Parsing Heap Buffer Overflow
    CVSS 8.5
    X.Org/libXfont2generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  24. CVE-2026-56001High
    libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
    CVSS 8.5
    X.Org/libXfont2generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  25. CVE-2026-6280Medium
    Improper Access Control in Nomysoft Informatics' Nomysem
    CVSS 6.5
    NOMYSOFT Informatics Education and Consulting Inc./Nomysemgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2026-55999High
    xorg-server / xwayland glamor font atlas Heap Buffer Overflow
    CVSS 8.5
    X.Org/xorg-server, X.Org/xwaylandgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  27. CVE-2026-13126High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  28. CVE-2026-13127High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2026-13128High
    Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  30. CVE-2026-57239High
    Foxit PDF Editor/Reader Local Privilege Escalation
    CVSS 8.2
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2026-57240High
    Foxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  32. CVE-2026-13129High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  33. CVE-2026-57238High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  34. CVE-2026-57241Medium
    Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  35. CVE-2026-57242High
    Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  36. CVE-2026-57243Medium
    Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  37. CVE-2026-57245High
    Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  38. CVE-2026-57246High
    Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  39. CVE-2026-57248High
    Foxit PDF Editor/Reader Annotation Improper Release Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  40. CVE-2026-57249High
    Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  41. CVE-2026-57251High
    Foxit PDF Editor/Reader Cloud Appearance Buffer Overflow Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  42. CVE-2026-56000Critical
    xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
    CVSS 9.0
    X.Org/xorg-x11-server, X.Org/xwaylandgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  43. CVE-2026-57253Medium
    Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  44. CVE-2026-57252High
    Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  45. CVE-2026-57254High
    Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  46. CVE-2026-57255Medium
    Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  47. CVE-2026-57259Medium
    Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
    CVSS 6.5
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  48. CVE-2026-57237High
    Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-57244High
    Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  50. CVE-2026-57247High
    Foxit PDF Editor/Reader Field Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
Page 91 of 328
Previous8990919293Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard