1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 6:25 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 6:25 AM 16,373 active 1,443 known exploited

Catalog summary

16,373

Active CVEs

8,468

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,851–4,900 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14808Critical
    PROG MIS|Prog Management System - Exposure of Sensitive Information
    CVSS 9.8
    PROG MIS/Prog Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  2. CVE-2026-14807Critical
    PROG MIS|ERP App - Use of Hard-coded Credentials
    CVSS 9.8
    PROG MIS/ERP Appgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  3. CVE-2026-14802High
    react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
    CVSS 7.3
    react/create-react-appgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  4. CVE-2026-14801Low
    GPAC TeXML File load_text.c txtin_probe_duration divide by zero
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  5. CVE-2026-14800Medium
    imhamzaazam ecommerceFlask cross-site request forgery
    CVSS 4.3
    imhamzaazam/ecommerceFlaskgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  6. CVE-2026-12083High
    Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Restoration via reset-for Parameter
    CVSS 8.1
    Unknown/Admin and Site Enhancements (ASE), Unknown/admin-site-enhancements-progeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  7. CVE-2026-11962High
    FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File Operations
    CVSS 8.8
    Unknown/FileOrganizergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  8. CVE-2026-11855High
    Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version
    CVSS 8.8
    Unknown/Simple Membershipgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  9. CVE-2026-11766High
    Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile Fields
    CVSS 8.0
    Unknown/Ultimate Membergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  10. CVE-2026-10830High
    AllCoach < 1.0.2 - Unauthenticated Account Takeover
    CVSS 8.8
    Unknown/AllCoachgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  11. CVE-2024-6228High
    WANotifier < 2.6 - Subscriber+ LFI
    CVSS 7.5
    Unknown/Notifications for Forms & WordPress Actionsgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-14799Medium
    CodeAstro Ecommerce Website my_account.php sql injection
    CVSS 6.3
    CodeAstro/Ecommerce Websitegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  13. CVE-2026-14798Medium
    CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  14. CVE-2026-14797Medium
    CodeAstro Apartment Visitor Management System edit-apartment.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  15. CVE-2026-14796Medium
    CodeAstro Apartment Visitor Management System report.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  16. CVE-2026-14795Medium
    CodeAstro Apartment Visitor Management System action-visitor.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  17. CVE-2026-14794Medium
    Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization
    CVSS 4.3
    Craft/CMSgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  18. CVE-2026-14793Medium
    Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
    CVSS 4.3
    Craft/CMS, craftcms/cmscomposer · generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-14792Medium
    Formbricks Survey actions.ts access control
    CVSS 6.5
    n/a/Formbricksgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  20. CVE-2026-14791Low
    crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString cross site scripting
    CVSS 3.5
    crater-invoice-inc/cratergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  21. CVE-2026-14790Low
    GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  22. CVE-2026-14789Low
    radareorg radare2 Memory64ListStream mdmp.c stack-based overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  23. CVE-2026-14788Low
    radareorg radare2 cfile.c r_core_bin_load use after free
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  24. CVE-2026-14803Medium
    Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder
    CVSS 6.5
    SRI/Mojo::JSONgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  25. CVE-2026-14787Low
    radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  26. CVE-2026-14786Low
    radareorg radare2 str.c r_str_word_get0set integer overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  27. CVE-2026-14784Medium
    vxcontrol PentAGI Docker API client.go sandbox
    CVSS 6.3
    vxcontrol/PentAGIgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  28. CVE-2026-38973Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    n/a/n/ageneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2026-38976High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  30. CVE-2026-38979Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2026-14783Medium
    NousResearch hermes-agent skills_tool.py skill_view path traversal
    CVSS 4.3
    NousResearch/hermes-agentgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  32. CVE-2026-14778High
    SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
    CVSS 7.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  33. CVE-2026-14777Medium
    SourceCodester Onlne Examination & Learning Management System announcements.php unrestricted upload
    CVSS 6.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  34. CVE-2026-14776Medium
    SourceCodester Onlne Examination & Learning Management System Filename Extension upload_files.php pathinfo unrestricted upload
    CVSS 6.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  35. CVE-2026-14775Medium
    SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload
    CVSS 6.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  36. CVE-2026-14774Medium
    itsourcecode Hospital Management System paymentdischarge.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  37. CVE-2026-10657Low
    Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
    CVSS 3.7
    zephyrproject/zephyrgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-10656Medium
    NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers
    CVSS 4.6
    zephyrproject/zephyrgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-14773Medium
    itsourcecode Hospital Management System payment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  40. CVE-2026-14772High
    SourceCodester Class and Exam Timetabling System edit_course1.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  41. CVE-2026-14771High
    SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  42. CVE-2026-14770High
    SourceCodester Class and Exam Timetabling System edit_room.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2026-14769High
    code-projects Real State Services pay.php sql injection
    CVSS 7.3
    code-projects/Real State Servicesgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 7, 2026View HOL analysis
  44. CVE-2026-14768High
    code-projects Real State Services builderHome.php sql injection
    CVSS 7.3
    code-projects/Real State Servicesgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  45. CVE-2026-14767Medium
    CodeAstro Ecommerce Website POST Parameter confirm.php sql injection
    CVSS 6.3
    CodeAstro/Ecommerce Websitegeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  46. CVE-2026-14766Medium
    CodeAstro Apartment Visitor Management System POST Parameter search-result.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  47. CVE-2026-14764High
    code-projects Hotel and Tourism Reservation Event Management add_event.php sql injection
    CVSS 7.3
    code-projects/Hotel and Tourism Reservationgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  48. CVE-2026-14763High
    code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.php sql injection
    CVSS 7.3
    code-projects/Hotel and Tourism Reservationgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  49. CVE-2026-14762High
    code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection
    CVSS 7.3
    code-projects/Hotel and Tourism Reservationgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 7, 2026View HOL analysis
  50. CVE-2026-14761Low
    radareorg radare2 str.c r_str_append integer overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
Page 98 of 328
Previous96979899100Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,468

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,851–4,900 of 16,373 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-14808Critical
    PROG MIS|Prog Management System - Exposure of Sensitive Information
    CVSS 9.8
    PROG MIS/Prog Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  2. CVE-2026-14807Critical
    PROG MIS|ERP App - Use of Hard-coded Credentials
    CVSS 9.8
    PROG MIS/ERP Appgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  3. CVE-2026-14802High
    react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
    CVSS 7.3
    react/create-react-appgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  4. CVE-2026-14801Low
    GPAC TeXML File load_text.c txtin_probe_duration divide by zero
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  5. CVE-2026-14800Medium
    imhamzaazam ecommerceFlask cross-site request forgery
    CVSS 4.3
    imhamzaazam/ecommerceFlaskgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  6. CVE-2026-12083High
    Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Restoration via reset-for Parameter
    CVSS 8.1
    Unknown/Admin and Site Enhancements (ASE), Unknown/admin-site-enhancements-progeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  7. CVE-2026-11962High
    FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File Operations
    CVSS 8.8
    Unknown/FileOrganizergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  8. CVE-2026-11855High
    Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version
    CVSS 8.8
    Unknown/Simple Membershipgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  9. CVE-2026-11766High
    Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile Fields
    CVSS 8.0
    Unknown/Ultimate Membergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  10. CVE-2026-10830High
    AllCoach < 1.0.2 - Unauthenticated Account Takeover
    CVSS 8.8
    Unknown/AllCoachgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  11. CVE-2024-6228High
    WANotifier < 2.6 - Subscriber+ LFI
    CVSS 7.5
    Unknown/Notifications for Forms & WordPress Actionsgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  12. CVE-2026-14799Medium
    CodeAstro Ecommerce Website my_account.php sql injection
    CVSS 6.3
    CodeAstro/Ecommerce Websitegeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  13. CVE-2026-14798Medium
    CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  14. CVE-2026-14797Medium
    CodeAstro Apartment Visitor Management System edit-apartment.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  15. CVE-2026-14796Medium
    CodeAstro Apartment Visitor Management System report.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  16. CVE-2026-14795Medium
    CodeAstro Apartment Visitor Management System action-visitor.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  17. CVE-2026-14794Medium
    Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization
    CVSS 4.3
    Craft/CMSgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  18. CVE-2026-14793Medium
    Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
    CVSS 4.3
    Craft/CMS, craftcms/cmscomposer · generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Aug 6, 2026 Fix availableView HOL analysis
  19. CVE-2026-14792Medium
    Formbricks Survey actions.ts access control
    CVSS 6.5
    n/a/Formbricksgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  20. CVE-2026-14791Low
    crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString cross site scripting
    CVSS 3.5
    crater-invoice-inc/cratergeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  21. CVE-2026-14790Low
    GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference
    CVSS 3.3
    n/a/GPACgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  22. CVE-2026-14789Low
    radareorg radare2 Memory64ListStream mdmp.c stack-based overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  23. CVE-2026-14788Low
    radareorg radare2 cfile.c r_core_bin_load use after free
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  24. CVE-2026-14803Medium
    Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder
    CVSS 6.5
    SRI/Mojo::JSONgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026 Fix availableView HOL analysis
  25. CVE-2026-14787Low
    radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  26. CVE-2026-14786Low
    radareorg radare2 str.c r_str_word_get0set integer overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  27. CVE-2026-14784Medium
    vxcontrol PentAGI Docker API client.go sandbox
    CVSS 6.3
    vxcontrol/PentAGIgeneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  28. CVE-2026-38973Medium
    CISA ADP Vulnrichment
    CVSS 4.4
    n/a/n/ageneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  29. CVE-2026-38976High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  30. CVE-2026-38979Medium
    CISA ADP Vulnrichment
    CVSS 5.4
    n/a/n/ageneric
    PublishedJul 6, 2026First seen at HOL Jul 6, 2026Updated Jul 9, 2026View HOL analysis
  31. CVE-2026-14783Medium
    NousResearch hermes-agent skills_tool.py skill_view path traversal
    CVSS 4.3
    NousResearch/hermes-agentgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  32. CVE-2026-14778High
    SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
    CVSS 7.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  33. CVE-2026-14777Medium
    SourceCodester Onlne Examination & Learning Management System announcements.php unrestricted upload
    CVSS 6.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  34. CVE-2026-14776Medium
    SourceCodester Onlne Examination & Learning Management System Filename Extension upload_files.php pathinfo unrestricted upload
    CVSS 6.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  35. CVE-2026-14775Medium
    SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload
    CVSS 6.3
    SourceCodester/Onlne Examination & Learning Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 7, 2026View HOL analysis
  36. CVE-2026-14774Medium
    itsourcecode Hospital Management System paymentdischarge.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  37. CVE-2026-10657Low
    Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
    CVSS 3.7
    zephyrproject/zephyrgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  38. CVE-2026-10656Medium
    NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers
    CVSS 4.6
    zephyrproject/zephyrgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 14, 2026 Fix availableView HOL analysis
  39. CVE-2026-14773Medium
    itsourcecode Hospital Management System payment.php sql injection
    CVSS 6.3
    itsourcecode/Hospital Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 6, 2026Updated Jul 6, 2026View HOL analysis
  40. CVE-2026-14772High
    SourceCodester Class and Exam Timetabling System edit_course1.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  41. CVE-2026-14771High
    SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  42. CVE-2026-14770High
    SourceCodester Class and Exam Timetabling System edit_room.php sql injection
    CVSS 7.3
    SourceCodester/Class and Exam Timetabling Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  43. CVE-2026-14769High
    code-projects Real State Services pay.php sql injection
    CVSS 7.3
    code-projects/Real State Servicesgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 7, 2026View HOL analysis
  44. CVE-2026-14768High
    code-projects Real State Services builderHome.php sql injection
    CVSS 7.3
    code-projects/Real State Servicesgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  45. CVE-2026-14767Medium
    CodeAstro Ecommerce Website POST Parameter confirm.php sql injection
    CVSS 6.3
    CodeAstro/Ecommerce Websitegeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  46. CVE-2026-14766Medium
    CodeAstro Apartment Visitor Management System POST Parameter search-result.php sql injection
    CVSS 6.3
    CodeAstro/Apartment Visitor Management Systemgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  47. CVE-2026-14764High
    code-projects Hotel and Tourism Reservation Event Management add_event.php sql injection
    CVSS 7.3
    code-projects/Hotel and Tourism Reservationgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  48. CVE-2026-14763High
    code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.php sql injection
    CVSS 7.3
    code-projects/Hotel and Tourism Reservationgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
  49. CVE-2026-14762High
    code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection
    CVSS 7.3
    code-projects/Hotel and Tourism Reservationgeneric
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 7, 2026View HOL analysis
  50. CVE-2026-14761Low
    radareorg radare2 str.c r_str_append integer overflow
    CVSS 3.3
    radareorg/radare2generic
    PublishedJul 5, 2026First seen at HOL Jul 5, 2026Updated Jul 6, 2026View HOL analysis
Page 98 of 328
Previous96979899100Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard