Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 13 February 2026
RSS145 vulnerabilities published on 13 February 2026
Severity:
WordPress allows unauthorized access to posts
CVE-2025-47915
A flaw in WordPress allows an attacker to access and view posts that were previously rejected or marked as private. This could happen if an administrator hasn't properly configured the plugin that han...
Apache HTTP Server: Unintended Configuration Option Overwrites
CVE-2024-34157
Apache HTTP Server configuration files contain a reserved setting that can be accidentally enabled, potentially exposing sensitive data. This could happen if a non-technical user or a script mistakenl...
Apache HTTP Server Discloses Password Disclosure Risk
CVE-2024-34154
Apache HTTP Server can accidentally expose user passwords when handling form submissions. This can happen when a user submits a form with a password field, but the form is rejected due to validation e...
Adobe Acrobat: Unvalidated input in error messages
CVE-2023-45291
Adobe Acrobat's error handling can be tricked into revealing sensitive information. This could allow an attacker to learn more about the system and potentially exploit it. Update to the latest version...
Polymarket Client SDK Crate Found to Steal Credentials
GHSA-p5vf-5754-x7p3
A fake version of the Polymarket Client SDK was uploaded to a public repository. It tried to steal sensitive login information from local files. This has been removed, but users should double-check th...
hpke-rs and hpke-rs-rust-crypto: Critical Security Fixes
GHSA-g433-pq76-6cmf
Two important libraries used for secure data encryption have been updated to fix critical security flaws. The issues could have allowed unauthorized access to encrypted data. To stay secure, update hp...
Adobe Flash Player Unused Vulnerability
CVE-2025-36552
Adobe Flash Player is not affected by this vulnerability, but it was previously listed as a potential issue. This has been corrected, and there is no actual risk to Adobe Flash Player users. No action...
Adobe Flash Player: Unpatched Vulnerability
CVE-2025-36545
Adobe Flash Player has an unpatched weakness that could be exploited by attackers. This means that hackers might be able to take control of your computer if you use the software. Update Adobe Flash Pl...
CVE Rejected: Unused Vulnerability
CVE-2025-36542
This vulnerability was mistakenly reported and has been removed from the list of known vulnerabilities. It does not pose any actual risk to users.
Mozilla Firefox: Unpatched Vulnerability Removed From Database
CVE-2025-36538
A previously reported vulnerability in Mozilla Firefox has been removed from the vulnerability database because it was never actually a real issue. This means there is nothing to worry about. No actio...
Apache HTTP Server: Unused vulnerability report
CVE-2025-36534
A vulnerability report has been mistakenly listed for the Apache HTTP Server. This means it was never a real issue and doesn't affect the software. You don't need to take any action.
Unused Vulnerability in Microsoft Windows
CVE-2025-36532
A previously reported vulnerability in Microsoft Windows was found to be non-existent. This means that there is no actual security risk to worry about. No action is required.
WordPress Plugin Not Vulnerable
CVE-2025-36526
A previously reported vulnerability in a WordPress plugin has been deemed not valid. This means there is no actual security risk to worry about. No action is required from users.
Adobe Flash Player Unused Vulnerability
CVE-2025-36524
Adobe Flash Player is no longer supported and should not be used. This issue affects older versions of Flash Player, and using them can put your system at risk of exploitation. Adobe recommends upgrad...
Adobe Flash Player Multiple Unspecified Vulnerabilities
CVE-2025-36523
Multiple security issues have been found in Adobe Flash Player, but the exact details are not available. This means that Adobe has not publicly disclosed the nature of the vulnerabilities. Business ow...
Adobe Flash Player: Unpatched vulnerability discovered, no fix available
CVE-2025-36517
Adobe Flash Player has a known security weakness that hasn't been addressed yet. This means that attackers might be able to exploit this weakness to compromise your system. We recommend removing or di...
Adobe Flash Player: Unsubstantiated Security Claim
CVE-2025-35997
Adobe Flash Player's security claim for a specific feature is not supported, but there's no concrete evidence of a vulnerability. This means it's not a confirmed security issue, but it's worth monitor...
Unmaintained Software: Potential Security Risks Remain
CVE-2025-35993
This software is no longer updated or maintained, leaving potential security issues unresolved. This means that any vulnerabilities discovered in the software may not be fixed, putting users at risk. ...
Adobe Flash Player: Unpatched Vulnerability in Unused Product
CVE-2025-35976
An unused version of Adobe Flash Player has a security weakness that could be exploited, but since it's no longer supported, users don't need to worry about it. If you're still using this outdated sof...
Apache HTTP Server Configuration File Parsing Error
CVE-2025-35962
An error in the Apache HTTP Server's configuration file parser can allow an attacker to execute arbitrary code on the server. This can happen when a malicious user submits a specially crafted configur...
Adobe Acrobat and Reader Unaffected by Unused Vulnerability
CVE-2025-35961
No action is required as this vulnerability is no longer being tracked due to being unused and has been withdrawn by the relevant authority. This means it is not a current risk to Adobe Acrobat and Re...
Apache HTTP Server: Unaffected by a Rejected CVE
CVE-2025-35960
Apache HTTP Server is not affected by a vulnerability that was previously reported, but the report has been withdrawn. This means you don't need to take any action. You can continue to use Apache as u...
CVE Rejected: Unused Vulnerability Report
CVE-2025-32734
This vulnerability report has been cancelled because it was never actually found in the software. You don't need to take any action to fix it. It was a mistake to list it as a potential issue in the f...
Unused Vulnerability Entry Removed
CVE-2025-32733
The vulnerability entry for this CVE ID has been removed because it was never actually identified in a software product. This means there's no risk to worry about, but it's good to know the record was...
Apache HTTP Server: Unaffected by Unused Vulnerability
CVE-2025-32090
This vulnerability was reported but later determined to be a mistake and not actually present in the Apache HTTP Server. No action is required. The Apache HTTP Server is not affected by this issue.