1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 4:30 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 4:30 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

8,465

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,651–4,700 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-55633High
    DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  2. CVE-2026-55631High
    DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management
    CVSS 7.2
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  3. CVE-2026-53729High
    DataEase ExportCenter IDOR allows cross-user export task access
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  4. CVE-2026-44454High
    Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
    CVSS 8.1
    coder/coder, github.com/coder/coder +1generic · go
    PublishedJul 7, 2026First seen at HOL Jul 2, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  5. CVE-2026-55434Medium
    Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
    CVSS 6.5
    coder/coder, github.com/coder/coder +1generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-55417Medium
    Chevereto private profile setting leaks username on /json endpoint
    CVSS 6.9
    chevereto/chevereto, chevereto/chevereto/chevereto +1generic
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-44877Medium
    Unauthenticated Remote Disclosure of Cryptographic Secrets
    CVSS 6.5
    Hewlett Packard Enterprise (HPE)/HPE Networking Instant Ongeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-59800Critical
    9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
    CVSS 9.8
    9router, decolua/9routergeneric · npm
    PublishedJul 7, 2026First seen at HOL Jul 2, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  9. CVE-2026-7017High
    HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
    CVSS 7.1
    HAARG/HTTP::Tinygeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-55435Medium
    Suspended Coder users retain access to AI Bridge LLM proxy endpoints
    CVSS 5.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  11. CVE-2026-48952Medium
    Joomla! Core - [20260706] - XSS in com_installer
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-48947Medium
    Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints
    CVSS 6.4
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-48958High
    Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
    CVSS 8.8
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  14. CVE-2026-48950Medium
    Joomla! Core - [20260704] - XSS in com_templates
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-48955Medium
    Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
    CVSS 6.5
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-48956Medium
    Joomla! Core - [20260710] - Incorrect Access Control in com_modules
    CVSS 6.4
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  17. CVE-2026-48957High
    Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
    CVSS 8.8
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  18. CVE-2026-48951Medium
    Joomla! Core - [20260705] - XSS in various modalreturn layouts
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  19. CVE-2026-48953Medium
    Joomla! Core - [20260707] - XSS in the generic image output layout
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  20. CVE-2026-48948High
    Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
    CVSS 8.8
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-48949Medium
    Joomla! Core - [20260703] - XSS in MFA method management
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-48954Medium
    Joomla! Core - [20260708] - XSS through language overrides
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  23. CVE-2026-13019Critical
    Missing Authentication
    CVSS 9.8
    Esri/Portal for ArcGISgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  24. CVE-2026-13020High
    Weak Password Recovery Mechanism in Portal for ArcGIS
    CVSS 8.1
    Esri/Portal for ArcGISgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  25. CVE-2026-14904Medium
    RES Auth.GetUserPrivateKey Arbitrary File Read
    CVSS 6.5
    AWS/resgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2025-12799Medium
    Jastow: jastow cross-site scripting attack due to unsanitized uri
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 29, 2026View HOL analysis
  27. CVE-2026-23697High
    Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
    CVSS 8.8
    Vtiger/Vtiger CRMgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  28. CVE-2026-23698High
    Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
    CVSS 7.2
    Vtiger/Vtiger CRMgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2026-14969Medium
    389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  30. CVE-2026-14935Low
    Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-56812High
    Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
    CVSS 7.5
    phoenixframework/phoenixgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  32. CVE-2026-56811High
    Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
    CVSS 8.7
    phoenixframework/phoenixgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  33. CVE-2026-12948Medium
    Stored Cross-Site Scripting (XSS)
    CVSS 4.8
    Digi International/Digi One IA, Digi International/Digi One SP +2generic
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-12352Medium
    Incorrect Authorization
    CVSS 5.9
    Digi International/Digi One SP / SP IA / IA, Digi International/PortServer TS 1/2/4generic
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-53878Medium
    Header injection possibility since DomainNameValidator accepted newlines in input
    CVSS 6.1
    django, djangoproject/Djangogeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  36. CVE-2026-53877Medium
    Heap buffer over-read in GDALRaster
    CVSS 4.8
    django, djangoproject/Djangogeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2026-48588Low
    Potential exposure of private data via cached Set-Cookie response
    CVSS 3.1
    django, djangoproject/Djangogeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-14940Medium
    389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  39. CVE-2026-53479High
    CISA ADP Vulnrichment
    CVSS 7.2
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-44938High
    Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
    CVSS 8.8
    SUSE/Rancher, github.com/rancher/fleetgeneric · go
    PublishedJul 7, 2026First seen at HOL Jul 1, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  41. CVE-2026-53481Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-10659Medium
    NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume
    CVSS 4.7
    zephyrproject/zephyrgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-53483Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  44. CVE-2011-10043Critical
    Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded
    CVSS 9.8
    BINGOS/Module::Loadgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  45. CVE-2026-13696High
    LDAP Injection in HAVELSAN's Liman MYS
    CVSS 8.8
    HAVELSAN Inc./Liman MYSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-11348High
    Authentication Bypass in HAVELSAN's Open Source Project Liman MYS
    CVSS 8.1
    HAVELSAN Inc./Liman MYSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-11340High
    Authorization Bypass in HAVELSAN's Open Source Project Liman MYS
    CVSS 8.3
    HAVELSAN Inc./Liman MYSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-14868High
    Weak encryption mechanism for User directory
    CVSS 8.4
    arcinfo/PcVuegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  49. CVE-2026-14867Medium
    Insecure password storage in User directory
    CVSS 6.8
    arcinfo/PcVuegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-33264Critical
    Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
    CVSS 9.8
    Apache Software Foundation/Apache Airflowgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
Page 94 of 328
Previous9293949596Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,465

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,651–4,700 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-55633High
    DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  2. CVE-2026-55631High
    DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management
    CVSS 7.2
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  3. CVE-2026-53729High
    DataEase ExportCenter IDOR allows cross-user export task access
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  4. CVE-2026-44454High
    Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
    CVSS 8.1
    coder/coder, github.com/coder/coder +1generic · go
    PublishedJul 7, 2026First seen at HOL Jul 2, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  5. CVE-2026-55434Medium
    Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
    CVSS 6.5
    coder/coder, github.com/coder/coder +1generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  6. CVE-2026-55417Medium
    Chevereto private profile setting leaks username on /json endpoint
    CVSS 6.9
    chevereto/chevereto, chevereto/chevereto/chevereto +1generic
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 10, 2026View HOL analysis
  7. CVE-2026-44877Medium
    Unauthenticated Remote Disclosure of Cryptographic Secrets
    CVSS 6.5
    Hewlett Packard Enterprise (HPE)/HPE Networking Instant Ongeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2026-59800Critical
    9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
    CVSS 9.8
    9router, decolua/9routergeneric · npm
    PublishedJul 7, 2026First seen at HOL Jul 2, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  9. CVE-2026-7017High
    HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
    CVSS 7.1
    HAARG/HTTP::Tinygeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  10. CVE-2026-55435Medium
    Suspended Coder users retain access to AI Bridge LLM proxy endpoints
    CVSS 5.4
    coder/coder, github.com/coder/coder/v2generic · go
    PublishedJul 7, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  11. CVE-2026-48952Medium
    Joomla! Core - [20260706] - XSS in com_installer
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  12. CVE-2026-48947Medium
    Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints
    CVSS 6.4
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  13. CVE-2026-48958High
    Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
    CVSS 8.8
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  14. CVE-2026-48950Medium
    Joomla! Core - [20260704] - XSS in com_templates
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-48955Medium
    Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
    CVSS 6.5
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-48956Medium
    Joomla! Core - [20260710] - Incorrect Access Control in com_modules
    CVSS 6.4
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  17. CVE-2026-48957High
    Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
    CVSS 8.8
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  18. CVE-2026-48951Medium
    Joomla! Core - [20260705] - XSS in various modalreturn layouts
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  19. CVE-2026-48953Medium
    Joomla! Core - [20260707] - XSS in the generic image output layout
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  20. CVE-2026-48948High
    Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
    CVSS 8.8
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  21. CVE-2026-48949Medium
    Joomla! Core - [20260703] - XSS in MFA method management
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  22. CVE-2026-48954Medium
    Joomla! Core - [20260708] - XSS through language overrides
    CVSS 6.1
    Joomla! Project/Joomla! CMSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026View HOL analysis
  23. CVE-2026-13019Critical
    Missing Authentication
    CVSS 9.8
    Esri/Portal for ArcGISgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  24. CVE-2026-13020High
    Weak Password Recovery Mechanism in Portal for ArcGIS
    CVSS 8.1
    Esri/Portal for ArcGISgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  25. CVE-2026-14904Medium
    RES Auth.GetUserPrivateKey Arbitrary File Read
    CVSS 6.5
    AWS/resgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  26. CVE-2025-12799Medium
    Jastow: jastow cross-site scripting attack due to unsanitized uri
    CVSS 6.5
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 29, 2026View HOL analysis
  27. CVE-2026-23697High
    Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
    CVSS 8.8
    Vtiger/Vtiger CRMgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  28. CVE-2026-23698High
    Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
    CVSS 7.2
    Vtiger/Vtiger CRMgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026View HOL analysis
  29. CVE-2026-14969Medium
    389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
    CVSS 4.4
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  30. CVE-2026-14935Low
    Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check
    CVSS 3.7
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  31. CVE-2026-56812High
    Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
    CVSS 7.5
    phoenixframework/phoenixgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  32. CVE-2026-56811High
    Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
    CVSS 8.7
    phoenixframework/phoenixgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  33. CVE-2026-12948Medium
    Stored Cross-Site Scripting (XSS)
    CVSS 4.8
    Digi International/Digi One IA, Digi International/Digi One SP +2generic
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-12352Medium
    Incorrect Authorization
    CVSS 5.9
    Digi International/Digi One SP / SP IA / IA, Digi International/PortServer TS 1/2/4generic
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-53878Medium
    Header injection possibility since DomainNameValidator accepted newlines in input
    CVSS 6.1
    django, djangoproject/Djangogeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  36. CVE-2026-53877Medium
    Heap buffer over-read in GDALRaster
    CVSS 4.8
    django, djangoproject/Djangogeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  37. CVE-2026-48588Low
    Potential exposure of private data via cached Set-Cookie response
    CVSS 3.1
    django, djangoproject/Djangogeneric · pip · pypi
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  38. CVE-2026-14940Medium
    389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
    CVSS 5.3
    Affected software not mappedEcosystem not listed
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026View HOL analysis
  39. CVE-2026-53479High
    CISA ADP Vulnrichment
    CVSS 7.2
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  40. CVE-2026-44938High
    Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
    CVSS 8.8
    SUSE/Rancher, github.com/rancher/fleetgeneric · go
    PublishedJul 7, 2026First seen at HOL Jul 1, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  41. CVE-2026-53481Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  42. CVE-2026-10659Medium
    NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume
    CVSS 4.7
    zephyrproject/zephyrgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  43. CVE-2026-53483Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    Dell/PowerProtect Data Domaingeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
  44. CVE-2011-10043Critical
    Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded
    CVSS 9.8
    BINGOS/Module::Loadgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  45. CVE-2026-13696High
    LDAP Injection in HAVELSAN's Liman MYS
    CVSS 8.8
    HAVELSAN Inc./Liman MYSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  46. CVE-2026-11348High
    Authentication Bypass in HAVELSAN's Open Source Project Liman MYS
    CVSS 8.1
    HAVELSAN Inc./Liman MYSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  47. CVE-2026-11340High
    Authorization Bypass in HAVELSAN's Open Source Project Liman MYS
    CVSS 8.3
    HAVELSAN Inc./Liman MYSgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 7, 2026 Fix availableView HOL analysis
  48. CVE-2026-14868High
    Weak encryption mechanism for User directory
    CVSS 8.4
    arcinfo/PcVuegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  49. CVE-2026-14867Medium
    Insecure password storage in User directory
    CVSS 6.8
    arcinfo/PcVuegeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  50. CVE-2026-33264Critical
    Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
    CVSS 9.8
    Apache Software Foundation/Apache Airflowgeneric
    PublishedJul 7, 2026First seen at HOL Jul 7, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
Page 94 of 328
Previous9293949596Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard