Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-25319 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Cross-Site Request Forgery (CSRF) vulnerability in wpzita Zita Elementor Site Library zita-site-library allows Cross Site Request Forgery.This issue affects Zita Elementor Site Library: from n/a through <= 1.6.6.
|
|||||
| CVE-2026-25314 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in WP Messiah TOP Table Of Contents top-table-of-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TOP Table Of Contents: from n/a through <= 1.3.31.
|
|||||
| CVE-2026-25311 | 2026-02-19 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoshare for Twitter: from n/a through <= 2.3.1.
|
|||||
| CVE-2026-25308 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9.
|
|||||
| CVE-2026-25003 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Portal: from n/a through <= 1.2.1.
|
|||||
| CVE-2026-25000 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through <= 1.2.0.
|
|||||
| CVE-2026-24999 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alma: from n/a through <= 5.16.1.
|
|||||
| CVE-2026-24392 | 2026-02-19 | N/A | 5.9 MEDIUM | ||
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nabil Lemsieh HurryTimer hurrytimer allows Stored XSS.This issue affects HurryTimer: from n/a through <= 2.14.2.
|
|||||
| CVE-2026-24375 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4.
|
|||||
| CVE-2026-23804 | 2026-02-19 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1.
|
|||||
| CVE-2026-23549 | 2026-02-19 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.
|
|||||
| CVE-2026-23544 | 2026-02-19 | N/A | 8.8 HIGH | ||
|
Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.
|
|||||
| CVE-2026-23542 | 2026-02-19 | N/A | 9.8 CRITICAL | ||
|
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10.
|
|||||
| CVE-2026-1355 | 1 Github | 1 Enterprise Server | 2026-02-19 | N/A | 6.5 MEDIUM |
|
A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing authorization check in the repository migration upload endpoint. By supplying the migration identifier, an attacker could overwrite or replace a victim’s migration archive, potentially causing victims to download attacker-controlled repository data during migration restores or automated imports. An ...
Show More |
|||||
| CVE-2023-53957 | 1 Kimai | 1 Kimai | 2026-02-19 | N/A | 9.8 CRITICAL |
|
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
|
|||||
| CVE-2019-25317 | 1 Kimai | 1 Kimai | 2026-02-19 | N/A | 6.4 MEDIUM |
|
Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.
|
|||||
| CVE-2026-25933 | 1 Arduino | 1 App Lab | 2026-02-19 | N/A | 6.8 MEDIUM |
|
Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from insufficient sanitization and validation of input data received from connected hardware devices, specifically in the _info.Serial and _info.Address metadata fields. The problem occurs during device information handling. When a board is connected, the application collects identifying attributes to est ...
Show More |
|||||
| CVE-2026-24740 | 1 Amirraminfar | 1 Dozzle | 2026-02-19 | N/A | 9.9 CRITICAL |
|
Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restricted by label filters (for example, `label=env=dev`) to obtain an interactive root shell in out‑of‑scope containers (for example, `env=prod`) on the same agent host by directly targeting their container IDs. Version 9.0.3 contains a patch for the issue.
|
|||||
| CVE-2025-67706 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-02-19 | N/A | 5.6 MEDIUM |
|
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories.
However, the server’s architecture enforces controls that restrict uploaded files to non‑executable storage locations and prevent modification or replacement of existing application components or system configurations. Uploaded files cannot be executed, leveraged to escalate p ...
Show More |
|||||
| CVE-2025-64724 | 2 Apple, Arduino | 2 Macos, Arduino Ide | 2026-02-19 | N/A | 7.3 HIGH |
|
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the application, the malicious code executes with that user's privileges, enabling privilege escalation and unauthorized access to sensitive data. The fix is included starting from the `2.3.7` release.
|
|||||
| CVE-2025-64723 | 2 Apple, Arduino | 2 Macos, Arduino Ide | 2026-02-19 | N/A | 4.4 MEDIUM |
|
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the application process, gaining access to all TCC (Transparency, Consent, and Control) permissions granted to the application. The fix is included starting from the `2.3.7 ` release.
|
|||||
| CVE-2026-22243 | 1 Egroupware | 1 Egroupware | 2026-02-19 | N/A | 8.8 HIGH |
|
EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260113, specifically in the `Nextmatch` filter processing. The flaw allows authenticated attackers to inject arbitrary SQL commands into the `WHERE` clause of database queries. This is achieved by exploiting a PHP type juggling issue where JSON decoding converts numeric strings into integers, bypassing the `is_int()` secur ...
Show More |
|||||
| CVE-2025-13981 | 1 Artificial Intelligence Project | 1 Artificial Intelligence | 2026-02-19 | N/A | 4.4 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS).This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.7, from 1.1.0 before 1.1.7, from 1.2.0 before 1.2.4.
|
|||||
| CVE-2026-25410 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in tstephenson WP-CORS wp-cors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CORS: from n/a through <= 0.2.2.
|
|||||
| CVE-2026-25385 | 2026-02-19 | N/A | 5.5 MEDIUM | ||
|
Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL Shortify: from n/a through <= 1.12.3.
|
|||||
| CVE-2026-25378 | 2026-02-19 | N/A | 7.6 HIGH | ||
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Blind SQL Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.4.
|
|||||
| CVE-2026-25374 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in raratheme Spa and Salon spa-and-salon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spa and Salon: from n/a through <= 1.3.2.
|
|||||
| CVE-2026-25367 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in NooTheme CitiLights noo-citilights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CitiLights: from n/a through < 3.7.2.
|
|||||
| CVE-2026-25337 | 2026-02-19 | N/A | 5.4 MEDIUM | ||
|
Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n/a through <= 1.1.5.
|
|||||
| CVE-2026-25335 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <= 5.0.0.
|
|||||
| CVE-2026-25332 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Endless Posts Navigation: from n/a through <= 2.2.9.
|
|||||
| CVE-2026-25320 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Contact Form DB: from n/a through <= 2.1.3.
|
|||||
| CVE-2026-25318 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through <= 2.9.
|
|||||
| CVE-2026-25310 | 2026-02-19 | N/A | 4.9 MEDIUM | ||
|
Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.This issue affects Extend Link: from n/a through <= 2.0.0.
|
|||||
| CVE-2025-13982 | 1 Innoraft | 1 Login Time Restriction | 2026-02-19 | N/A | 8.1 HIGH |
|
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Restriction: from 0.0.0 before 1.0.3.
|
|||||
| CVE-2026-1598 | 1 Bdtask | 1 Bhojon | 2026-02-19 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknown function of the file /dashboard/home/profile of the component User Information Module. Performing a manipulation of the argument fullname results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2026-1599 | 1 Bdtask | 1 Bhojon | 2026-02-19 | 4.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder of the component Checkout. Executing a manipulation of the argument orggrandTotal/vat/service_charge/grandtotal can lead to business logic errors. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not re ...
Show More |
|||||
| CVE-2026-1600 | 1 Bdtask | 1 Bhojon | 2026-02-19 | 4.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipulation of the argument price/allprice leads to business logic errors. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2026-24413 | 2 Icinga, Microsoft | 2 Icinga, Windows | 2026-02-19 | N/A | 5.5 MEDIUM |
|
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are affected. Versions 2.13.14, 2.14.8, and 2.15.2 contains a fix. There are two possibilities to work a ...
Show More |
|||||
| CVE-2025-69749 | 1 Tale Project | 1 Tale | 2026-02-19 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code.
|
|||||