1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:35 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 3:35 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

8,462

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,551–4,600 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57244High
    Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-57247High
    Foxit PDF Editor/Reader Field Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-57250High
    Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-57256High
    Foxit Editor/Reader List Box Format Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-57257Medium
    Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB Read
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-57258Medium
    Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  7. CVE-2026-57260High
    Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-12378High
    BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
    CVSS 8.1
    Unknown/Appointment Booking Calendar Plugin and Scheduling Plugingeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  9. CVE-2026-9695Critical
    Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026
    CVSS 9.8
    Dassault Systèmes/DELMIA Aprisogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  10. CVE-2026-10570Medium
    Sympl Repeater for ACF and Elementor <= 2.3 - Authenticated (Author+) Stored Cross-Site Scripting via ACF Repeater Field Values
    CVSS 6.4
    idocoh/Sympl Repeater for ACF and Elementorgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  11. CVE-2026-14500Medium
    Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' Parameter
    CVSS 5.3
    sayantandas20/Bulk Order Update for WooCommercegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  12. CVE-2026-14489High
    WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter
    CVSS 8.8
    globalprogramming/WHMCS Bridgegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  13. CVE-2026-9731Medium
    Wp Js Detect <= 1.0.9 - Cross-Site Request Forgery to Plugin Settings Update
    CVSS 4.3
    wpkuf/Wp Js Detectgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2026-12153Critical
    WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action
    CVSS 9.8
    rabilal/WP Learn Managergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  15. CVE-2026-12041Medium
    Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting
    CVSS 4.4
    chatra/Chatra Live Chat + ChatBot + Cart Savergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  16. CVE-2026-9700High
    Eventer <= 4.4.2 - Unauthenticated SQL Injection via 'code' Parameter
    CVSS 7.5
    joe007/Eventergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  17. CVE-2026-12097Medium
    User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification
    CVSS 5.3
    saadiqbal/User Managementgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-11798Medium
    Social Share, Social Login and Social Comments Plugin <= 7.14.5 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter
    CVSS 6.1
    the_champ/Social Share, Social Login and Social Comments Plugin – Super Socializergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  19. CVE-2026-14495High
    DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token
    CVSS 8.8
    wpdo5ea/DoLogin Securitygeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-57895High
    CISA ADP Vulnrichment
    CVSS 8.5
    Fuji Electric Co.,Ltd./Pupsmangeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  21. CVE-2026-56437High
    CISA ADP Vulnrichment
    CVSS 8.4
    Fuji Electric Co.,Ltd./Pupsmangeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-14487Critical
    Simple Coherent Form <= 2.4.13 - Unauthenticated Arbitrary File Deletion via 'id' Parameter
    CVSS 9.1
    tombgtn/Simple Coherent Formgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-9701Critical
    Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
    CVSS 9.8
    joe007/Eventergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  24. CVE-2026-14482High
    多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'value' Parameters
    CVSS 8.8
    shen2/多说社会化评论框generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  25. CVE-2026-14158High
    Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter
    CVSS 8.8
    totalbounty/Widget Logic Visualgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2026-9842High
    Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities
    CVSS 7.5
    pixelgrade/Backstage – Customizer Demo Accessgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  27. CVE-2026-14244High
    Jssor Slider by jssor.com <= 3.1.24 - Unauthenticated Arbitrary File Read via 'url' Parameter
    CVSS 7.5
    jssor/Jssor Slider by jssor.comgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-55438Medium
    Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
    CVSS 5.8
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-55437Medium
    Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
    CVSS 5.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-55436High
    Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
    CVSS 7.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-55433Medium
    Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
    CVSS 5.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-55432Medium
    Coder's sub-agent app registration bypasses template port-sharing policy enforcement
    CVSS 5.4
    coder/coder, github.com/coder/coder +1generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-60002High
    CISA ADP Vulnrichment
    CVSS 7.7
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  34. CVE-2026-60001Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  35. CVE-2026-56843Critical
    CISA ADP Vulnrichment
    CVSS 9.9
    Webpros/Pleskgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-60000Low
    CISA ADP Vulnrichment
    CVSS 3.7
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-59999Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  38. CVE-2026-59998Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  39. CVE-2026-55431High
    Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
    CVSS 7.7
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-59997Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  41. CVE-2026-59996Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  42. CVE-2026-59995Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  43. CVE-2026-55430Medium
    Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
    CVSS 5.8
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  44. CVE-2026-55429High
    Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
    CVSS 8.7
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-24697High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-24698High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-24699High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-24700High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-31309Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 16, 2026View HOL analysis
  50. CVE-2026-35552High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 92 of 328
Previous9091929394Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,462

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,551–4,600 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57244High
    Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-57247High
    Foxit PDF Editor/Reader Field Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  3. CVE-2026-57250High
    Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-57256High
    Foxit Editor/Reader List Box Format Use-After-Free Vulnerability
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-57257Medium
    Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB Read
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-57258Medium
    Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
    CVSS 6.1
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  7. CVE-2026-57260High
    Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)
    CVSS 7.8
    Foxit Software Inc./Foxit PDF Editor, Foxit Software Inc./Foxit PDF Readergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-12378High
    BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
    CVSS 8.1
    Unknown/Appointment Booking Calendar Plugin and Scheduling Plugingeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  9. CVE-2026-9695Critical
    Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026
    CVSS 9.8
    Dassault Systèmes/DELMIA Aprisogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  10. CVE-2026-10570Medium
    Sympl Repeater for ACF and Elementor <= 2.3 - Authenticated (Author+) Stored Cross-Site Scripting via ACF Repeater Field Values
    CVSS 6.4
    idocoh/Sympl Repeater for ACF and Elementorgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  11. CVE-2026-14500Medium
    Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' Parameter
    CVSS 5.3
    sayantandas20/Bulk Order Update for WooCommercegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  12. CVE-2026-14489High
    WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter
    CVSS 8.8
    globalprogramming/WHMCS Bridgegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  13. CVE-2026-9731Medium
    Wp Js Detect <= 1.0.9 - Cross-Site Request Forgery to Plugin Settings Update
    CVSS 4.3
    wpkuf/Wp Js Detectgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  14. CVE-2026-12153Critical
    WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action
    CVSS 9.8
    rabilal/WP Learn Managergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  15. CVE-2026-12041Medium
    Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting
    CVSS 4.4
    chatra/Chatra Live Chat + ChatBot + Cart Savergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  16. CVE-2026-9700High
    Eventer <= 4.4.2 - Unauthenticated SQL Injection via 'code' Parameter
    CVSS 7.5
    joe007/Eventergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  17. CVE-2026-12097Medium
    User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification
    CVSS 5.3
    saadiqbal/User Managementgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  18. CVE-2026-11798Medium
    Social Share, Social Login and Social Comments Plugin <= 7.14.5 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter
    CVSS 6.1
    the_champ/Social Share, Social Login and Social Comments Plugin – Super Socializergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  19. CVE-2026-14495High
    DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token
    CVSS 8.8
    wpdo5ea/DoLogin Securitygeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  20. CVE-2026-57895High
    CISA ADP Vulnrichment
    CVSS 8.5
    Fuji Electric Co.,Ltd./Pupsmangeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  21. CVE-2026-56437High
    CISA ADP Vulnrichment
    CVSS 8.4
    Fuji Electric Co.,Ltd./Pupsmangeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  22. CVE-2026-14487Critical
    Simple Coherent Form <= 2.4.13 - Unauthenticated Arbitrary File Deletion via 'id' Parameter
    CVSS 9.1
    tombgtn/Simple Coherent Formgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  23. CVE-2026-9701Critical
    Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
    CVSS 9.8
    joe007/Eventergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  24. CVE-2026-14482High
    多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'value' Parameters
    CVSS 8.8
    shen2/多说社会化评论框generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  25. CVE-2026-14158High
    Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter
    CVSS 8.8
    totalbounty/Widget Logic Visualgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2026-9842High
    Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities
    CVSS 7.5
    pixelgrade/Backstage – Customizer Demo Accessgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  27. CVE-2026-14244High
    Jssor Slider by jssor.com <= 3.1.24 - Unauthenticated Arbitrary File Read via 'url' Parameter
    CVSS 7.5
    jssor/Jssor Slider by jssor.comgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  28. CVE-2026-55438Medium
    Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
    CVSS 5.8
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  29. CVE-2026-55437Medium
    Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
    CVSS 5.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  30. CVE-2026-55436High
    Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
    CVSS 7.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  31. CVE-2026-55433Medium
    Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
    CVSS 5.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  32. CVE-2026-55432Medium
    Coder's sub-agent app registration bypasses template port-sharing policy enforcement
    CVSS 5.4
    coder/coder, github.com/coder/coder +1generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  33. CVE-2026-60002High
    CISA ADP Vulnrichment
    CVSS 7.7
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  34. CVE-2026-60001Medium
    CISA ADP Vulnrichment
    CVSS 6.5
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  35. CVE-2026-56843Critical
    CISA ADP Vulnrichment
    CVSS 9.9
    Webpros/Pleskgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-60000Low
    CISA ADP Vulnrichment
    CVSS 3.7
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  37. CVE-2026-59999Medium
    CISA ADP Vulnrichment
    CVSS 5.9
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  38. CVE-2026-59998Medium
    CISA ADP Vulnrichment
    CVSS 4.8
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  39. CVE-2026-55431High
    Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
    CVSS 7.7
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-59997Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  41. CVE-2026-59996Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  42. CVE-2026-59995Medium
    CISA ADP Vulnrichment
    CVSS 4.2
    OpenBSD/OpenSSHgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  43. CVE-2026-55430Medium
    Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
    CVSS 5.8
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  44. CVE-2026-55429High
    Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
    CVSS 8.7
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 8, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  45. CVE-2026-24697High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  46. CVE-2026-24698High
    CISA ADP Vulnrichment
    CVSS 8.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  47. CVE-2026-24699High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-24700High
    CISA ADP Vulnrichment
    CVSS 7.2
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  49. CVE-2026-31309Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 16, 2026View HOL analysis
  50. CVE-2026-35552High
    CISA ADP Vulnrichment
    CVSS 8.1
    n/a/n/ageneric
    PublishedJul 8, 2026First seen at HOL Jul 9, 2026Updated Jul 9, 2026View HOL analysis
Page 92 of 328
Previous9091929394Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard