Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 13 February 2026
RSS145 vulnerabilities published on 13 February 2026
Severity:
MojoPortal CMS allows attackers to run malicious commands via zip file
CVE-2025-69770
MojoPortal CMS v2.9.0.1 has a security issue where attackers can upload a special zip file to the /DesignTools/SkinList.aspx endpoint, allowing them to execute commands on the server. This could lead ...
10.0
Hyland OnBase Workflow Timer Service exposes files to unauthorized access
CVE-2026-26221
Hyland OnBase's Workflow Timer Service may allow an attacker to access and modify sensitive files on the server. This could potentially lead to unauthorized data exposure or even allow an attacker to ...
10.0
Cursor Code Editor versions before 2.5 allow malicious Git commands
CVE-2026-26268
Old versions of Cursor Code Editor had a security weakness that could allow an attacker to run malicious code in the editor's environment. This could happen if a malicious user was able to write to th...
9.9
Caido Web Security Tool Fails to Block Unallowed Network Access
CVE-2026-24853
Caido, a web security tool, previously allowed unauthorized access to its internal network by accepting fake information about the user's connection. This could let attackers bypass security checks. U...
9.8
Known: Password Reset Token Leaked, Allowing Account Takeover
CVE-2026-26273
GHSA-78wq-6gcv-w28r
A security flaw in Known software version 1.6.2 allows anyone to steal a password reset token, giving them access to any account. This can happen if the email address of the account owner is known. To...
9.8
PrestaShop Advanced Popup Creator: Remote SQL Attack Risk via Popup Controller
CVE-2025-69633
An unauthenticated attacker can access and manipulate data in the PrestaShop store by injecting malicious SQL code into the Advanced Popup Creator module. This module is used in PrestaShop versions 1....
9.8
Calero VeraSMART: Malicious Code Can Run on Server
CVE-2026-26335
Calero VeraSMART versions before 2022 R1 store sensitive configuration data in a predictable location, allowing an attacker who gains access to the server to execute malicious code. This creates a ris...
9.3
Calero VeraSMART exposes sensitive data and files on an open port
CVE-2026-26333
Old versions of Calero VeraSMART are leaving a critical port open to the internet, allowing anyone to read and write files, including sensitive data like passwords and encryption keys. This could be u...
10.0
BeyondTrust Remote Support and PRA: Unauthenticated Command Execution
CVE-2026-1731
Attackers can access and control your computer without a password. This can lead to unauthorized data theft or system crashes. Update your BeyondTrust software to fix this issue.
9.9
KEV
LavaLite CMS 10.1.0 Allows Low-Privilege Users to Access Admin Panel
CVE-2025-70866
A security flaw in LavaLite CMS 10.1.0 lets users with limited permissions log in to the admin area without proper authorization. This could allow them to make changes to the site's settings or data. ...
8.8
Starfish Review Plugin Allows Attackers to Gain Administrator Access
CVE-2025-15157
The Starfish Review Generation & Marketing plugin for WordPress is vulnerable to unauthorized changes. An attacker with a basic account can update settings to allow anyone to create an administrator a...
8.8
FlexCity/Kiosk: Malicious User Can Access Sensitive Areas
CVE-2026-1618
A vulnerability in FlexCity/Kiosk allows an attacker to bypass security checks and potentially access areas of the system that should only be accessible by authorized users. This could allow an attack...
8.8
FlexCity/Kiosk Allows Unauthorized Access to Critical Functions
CVE-2025-14349
A security issue in FlexCity/Kiosk software allows users to access sensitive features without proper authorization. This could lead to unauthorized changes or data manipulation. Update to version 1.0....
8.8
rPGP crashes when parsing deeply nested messages
GHSA-8h58-w33p-wq3g
rPGP versions before 0.19.0 can crash if it receives a message with many nested layers. This could allow an attacker to make rPGP applications crash. Update to rPGP 0.19.0 to fix this issue.
8.7
rPGP Crashes on Malicious PGP Key
GHSA-7587-4wv6-m68m
The rPGP software can crash if it receives a specially crafted PGP key. This can happen if an attacker sends a malicious key to the application. To fix this, update to the latest version of rPGP, whic...
8.7
FlexCity/Kiosk: Unauthorized Access to Trusted Data
CVE-2026-1619
A security issue in FlexCity/Kiosk software allows an attacker to gain access to sensitive information that they shouldn't have access to. This affects all versions of FlexCity/Kiosk prior to 1.0.36. ...
8.3
Yokogawa Vnet/IP Interface Package Denial-of-Service and Code Execution
CVE-2025-1924
A security issue has been discovered in Yokogawa's Vnet/IP Interface Package, which could allow an attacker to send a malicious packet and disrupt communication or run unauthorized programs on affecte...
6.0
Wildfly Elytron CLI authentication vulnerable to brute force attacks
CVE-2025-23368
GHSA-qhp6-6p8p-2rqh
The Wildfly Elytron integration does not limit failed login attempts, making it easier for attackers to try multiple login combinations. This can lead to unauthorized access to your system. To protect...
8.1
BACnet Stack Can Crash Embedded Systems with Malicious Requests
CVE-2026-26264
A flaw in the BACnet Stack library for embedded systems can cause a system crash if it receives a specially crafted network message. This can happen when a device receives a malformed message that inc...
7.8
lakeFS allows unauthorized access to files outside designated storage
CVE-2026-26187
GHSA-699m-4v95-rmpm
Authenticated users can read and write files in other namespaces or sibling directories due to vulnerabilities in the local block adapter. This means sensitive information can be accessed or modified ...
8.1
Calero VeraSMART Stores Passwords in Readable Format
CVE-2026-26334
Calero VeraSMART versions before 2026 R1 store passwords in a way that makes them easily accessible to anyone with local access to the system. This allows an attacker to get the passwords and use them...
8.5
ADB Explorer on Windows allows malicious code to run remotely
CVE-2026-26208
ADB Explorer, a tool for interacting with Android devices on Windows, contains a security flaw that lets hackers run code on your computer from a distance. This means an attacker could potentially tak...
7.8
Tandoor Recipes Cookmate Import Feature Allows Unauthorized Server Access
CVE-2026-25991
A security issue in Tandoor Recipes before version 2.5.1 allows anyone who uses the Cookmate import feature to potentially access internal or external websites without permission, which could reveal s...
7.7
Apache HTTP Server May Accept Untrusted Server Identities
CVE-2025-9293
Apache HTTP Server may not properly verify the identity of servers during secure connections. This can allow an attacker to intercept or modify sensitive information if they can intercept the connecti...
7.7
TON Lite Server crashes if given certain input
CVE-2025-70957
A bug in the TON Lite Server before version 2024.09 can cause it to use up all its processing power, making it unavailable to legitimate users. This can happen when the server is given a special type ...
7.5