Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 13 February 2026

RSS

145 vulnerabilities published on 13 February 2026

Severity:
TON Virtual Machine allows corrupted state to cause unexpected behavior
CVE-2025-70956
A bug in the TON Virtual Machine can cause it to behave unexpectedly if a specific condition occurs. This can lead to a denial of service within a contract. Update to version 2025.04 or later to fix t...
7.5
TON Virtual Machine crashes due to unexpected smart contract execution
CVE-2025-70955
A weakness in the way TON Virtual Machine handles certain smart contract instructions can cause the system to run out of memory, leading to a crash of the validator node and a disruption to the TON bl...
7.5
TON Blockchain crashes if malicious transaction is sent
CVE-2025-70954
A flaw in the TON Blockchain's virtual machine can cause the entire network to become unavailable if a malicious transaction is sent. This could be done by an attacker to disrupt the network. To fix t...
7.5
Vim's NetBeans integration vulnerable to malicious command input
CVE-2026-26269
Vim's integration with NetBeans has a security flaw that can be exploited by a malicious NetBeans server. This could allow the server to execute unauthorized commands on the Vim system. Update to Vim ...
7.5
BACnet Stack: Unvalidated File Paths Allow Arbitrary File Writing
CVE-2026-21878
The BACnet Stack library for embedded systems doesn't check file paths, allowing hackers to write files to any directory. This could lead to unauthorized access or data tampering. Update to version 1....
7.5
free5GC v4.0.1: Malformed Input Triggers Denial of Service
CVE-2025-70123
A security issue in free5GC v4.0.1 can cause a denial of service to remote attackers. This happens when the system incorrectly handles a specific type of request, leading to service degradation. To st...
7.5
Free5GC UPF Crashes When Processing Malformed PFCP Request
CVE-2025-70122
A security issue affects the free5GC UPF component. An attacker could send a specially crafted message, causing the system to crash. Upgrade to a fixed version of free5GC to prevent this issue.
7.5
Free5GC v4.0.1 Crashes When Processing Specific Mobile Identity Request
CVE-2025-70121
A security weakness in the free5GC system can cause it to crash when receiving a specific type of request. This can prevent the system from functioning, making it unavailable to users. To protect agai...
7.5
Red Hat osbuild-composer Security Update - Potential Data Exposure
RHSA-2026:2686
A security update is available for osbuild-composer, a tool used in Red Hat's build process. If left unpatched, a potential security issue could allow unauthorized access to sensitive data. Update you...
7.5
Red Hat osbuild-composer Security Update Leaves System Open to Unauthorized Access
RHSA-2026:2685
A critical security issue has been found in the osbuild-composer tool, which is used to build and compose operating systems. If exploited, an attacker could gain unauthorized access to the system, pot...
7.5
OpenSourcePOS v3.4.1: Malicious AJAX Response Can Execute Unwanted Code
CVE-2025-70093
OpenSourcePOS version 3.4.1 has a security weakness that lets hackers inject malicious code into the system. This could allow them to take control of your point of sale system. You should update to th...
7.4
Apache Avro Java SDK can be Tricked into Running Malicious Code
CVE-2025-33042 GHSA-rp46-r563-jrc7
An attacker can manipulate Avro schemas to inject malicious code into your system. This affects all versions of Apache Avro Java SDK up to 1.11.4 and version 1.12.0. To fix this, update to version 1.1...
6.9
Perl WWW::OAuth uses insecure random number generator
CVE-2025-40905
WWW::OAuth for Perl may generate weak encryption keys, compromising the security of authentication and authorization processes. This could allow an attacker to intercept or manipulate sensitive inform...
7.3
PixelYourSite PRO plugin for WordPress allows attackers to inject malicious code
CVE-2026-1844
The PixelYourSite PRO plugin for WordPress has a security flaw that lets attackers inject malicious code into website pages. This means that if a user visits a page with the injected code, it could ru...
7.2
PixelYourSite Plugin for WordPress Allows Malicious Code Injection
CVE-2026-1841
The PixelYourSite plugin for WordPress has a security flaw that allows attackers to inject malicious code into pages, which can be executed when users visit those pages. This can lead to unauthorized ...
7.2
sqlparse: Formatting Long Tuple Lists Can Cause Crashes
GHSA-27jp-wm6q-gp25
The sqlparse library can crash when formatting a long list of tuples. This can happen when querying databases with complex data. Affected users should update sqlparse to the latest version to prevent ...
6.9
OpenShift 18.0: Python library allows remote code execution
RHSA-2026:1959
A security update for OpenShift 18.0 affects a library used by the platform. If exploited, this vulnerability could allow an attacker to execute arbitrary code on the system. Red Hat has released a pa...
6.5
Yokogawa Vnet/IP Interface Package Allows Malicious Packet Crashing
CVE-2025-48023
The Yokogawa Vnet/IP Interface Package in certain versions may crash if it receives specially designed packets. This could lead to downtime or require a restart of the affected system. If you're using...
6.0
Yokogawa Vnet/IP Interface Package: Malicious Packets Can Crash Software
CVE-2025-48022
A vulnerability in the Yokogawa Vnet/IP Interface Package can cause a critical software component to crash if it receives a specially designed packet. This affects certain versions of the package used...
6.0
Yokogawa Vnet/IP Interface Package Can Crash with Malicious Packets
CVE-2025-48021
A flaw in the Vnet/IP software stack of certain Yokogawa products can cause them to crash if they receive specially designed network traffic. This could disrupt normal operation of these products. Aff...
6.0
Yokogawa Vnet/IP Interface Package may crash on malicious packet reception
CVE-2025-48020
The Vnet/IP Interface Package, used in Yokogawa's CENTUM VP R6 and R7 systems, may crash if it receives a specially crafted packet. This could disrupt system operation. Update the Vnet/IP software to ...
6.0
Yokogawa Vnet/IP Interface Software Stopped by Malicious Packets
CVE-2025-48019
A security issue in Yokogawa's Vnet/IP Interface Package can allow an attacker to crash the software by sending specially crafted network packets. If this happens, the affected system may become unava...
6.0
rPGP Fails to Detect Tampered Encrypted Data
GHSA-c7ph-f7jm-xv4w
rPGP's encrypted data protection may not work as expected, potentially exposing sensitive information if an unauthorized person accesses it. This is because rPGP doesn't always detect when encrypted d...
6.3
Cloudflare Agents: Malicious Links Can Steal User Chat History
GHSA-w5cr-2qhr-jqc5
A security issue in Cloudflare Agents' AI Playground site allows attackers to create malicious links that steal user chat history and access sensitive information. To fix this, update to Cloudflare Ag...
6.2
IObit Unlocker v1.3.0.11 Can Be Crashed by Malicious Input
CVE-2025-66676
A weakness in IObit Unlocker version 1.3.0.11 can be exploited by an attacker to crash the program, making it unavailable to use. This could potentially allow an attacker to disrupt the normal functio...
6.2