Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 15 February 2026

RSS

33 vulnerabilities published on 15 February 2026

Severity:
Open5GS: Remote attackers may cause memory corruption
CVE-2026-2521
A security weakness in Open5GS, a software used by telecommunications companies, can be exploited by remote attackers to cause memory corruption. This can potentially lead to crashes or other security...
5.5
eNet SMART HOME server 2.2.1 and 2.3.1: Unauthorized User Access
CVE-2026-26369
A user with limited access can gain extra powers on the eNet SMART HOME server by sending a special request. This allows them to control settings and devices that they shouldn't be able to access. Upd...
9.3
eNet SMART HOME server has easy-to-guess admin passwords
CVE-2026-26366
The eNet SMART HOME server comes with default passwords that don't get changed after setup, allowing anyone to access sensitive home settings and controls without permission. This is a serious securit...
9.3
CleanTalk WordPress Plugin Allows Unauthorized Plugin Installation
CVE-2026-1490
The CleanTalk plugin for WordPress has a security flaw that could let attackers install and activate any plugin without permission. This is a risk because it could allow them to install malicious plug...
9.8
Bosch Infotainment ECU allows attackers to send malicious car messages
CVE-2025-32058
A security flaw in some Infotainment ECUs made by Bosch allows an attacker to execute code on the system controlling car messages, potentially allowing them to send malicious messages to other car sys...
9.3
eNet SMART HOME Server Password Reset Flaw Allows Unauthorized Access
CVE-2026-26368
An attacker can use a feature meant for password reset to take over any account, including admin accounts, without knowing the current password. This can happen if the attacker logs in with a lower-le...
8.7
Nissan Leaf Infotainment System Can Be Hacked Remotely
CVE-2025-32062
The Nissan Leaf's infotainment system, made by Bosch and containing a Bluetooth stack from Alps Alpine, has a security weakness. An attacker could send a special message to the system, potentially all...
8.8
Nissan Leaf Infotainment System Allows Remote Code Execution
CVE-2025-32061
The Infotainment system in some Nissan Leaf vehicles can be hacked remotely, potentially allowing an attacker to take control of the vehicle's computer system with complete access. This is due to a fl...
8.8
Nissan Infotainment System Bluetooth Security Risk: Remote Code Execution
CVE-2025-32059
The Nissan Infotainment System's Bluetooth connection is vulnerable to a security risk that could allow an attacker to take control of the system with complete access. This could happen if a hacker se...
8.8
Ecwid Ecommerce Shopping Cart plugin allows attackers to gain admin access
CVE-2026-1750
If an attacker with low-level permissions updates a user profile, they may gain full control over an online store. This affects all versions of the Ecwid Ecommerce Shopping Cart plugin for WordPress u...
8.8
Micca KE700 System Allows Unauthorized Vehicle Access
CVE-2026-2540
The Micca KE700 system has a flaw that can be exploited by an attacker who sends two previously captured codes in a specific order. This can allow the attacker to unlock or lock doors without permissi...
8.4
eNet SMART HOME server allows unauthorized account deletion
CVE-2026-26367
Any authenticated user can delete other accounts except the admin account by sending a specific request. This could allow an attacker to lock out other users or disrupt the system. Update the SMART HO...
7.1
Open5GS: Remote denial-of-service attack possible through GTP2 parsing flaw
CVE-2026-2517
A flaw has been found in Open5GS versions up to 2.7.6 that could allow a remote attacker to crash the system. This vulnerability affects the way Open5GS handles certain network traffic, which could le...
5.5
Unidocs ezPDF DRM Reader and ezPDF Reader 32-bit: Uncontrolled Search Path
CVE-2026-2516
A flaw in the ezPDF DRM Reader and ezPDF Reader 32-bit on certain versions allows an attacker to gain unauthorized access to your system. This can happen if an attacker has physical access to your com...
7.3
BOSCH Infotainment ECU Misconfigures Firewall and SSH Server
CVE-2025-32063
A misconfiguration in BOSCH's Infotainment ECU can allow unauthorized access to a vehicle's internal systems. This is particularly concerning for owners of Nissan Leaf ZE1 models from 2020, as it may ...
6.8
Nissan Leaf ZE1 lacks kernel module signature verification
CVE-2025-32060
The Nissan Leaf ZE1 2020 model is missing a crucial security check that prevents malicious kernel modules from being loaded. This allows an attacker who already has certain privileges to gain even mor...
6.7
Adobe Acrobat Reader Allows Remote Code Execution via Malicious PDF
BELL-CVE-2026-26007
Adobe Acrobat Reader, a popular tool for viewing and editing PDF files, contains a vulnerability that could allow attackers to execute malicious code on a user's computer. If exploited, this flaw coul...
6.5
Element Pack Addons for Elementor plugin allows unauthorized file access
CVE-2026-1793
The Element Pack Addons for Elementor plugin for WordPress has a security flaw that allows attackers with contributor-level access to read sensitive information from your server. This is a serious iss...
6.5
Micca KE700 System Has Weak Rolling Code Authentication
CVE-2026-2541
The Micca KE700 system's weak password system makes it easy for an attacker to guess the code and unlock a vehicle. This is because the system only uses 64 possible combinations, making it a simple ta...
6.4
OPNsense 19.1 allows attackers to inject malicious scripts via user input
CVE-2019-25377
OPNsense firewall software has a security weakness that allows hackers to inject malicious code into the system using a specific user input field. This could allow a hacker to access sensitive informa...
4.8
OPNsense 19.1 Allows Attackers to Inject Malicious Scripts in Users' Browsers
CVE-2019-25376
A security issue in OPNsense 19.1 allows hackers to inject malicious code into users' browsers without needing a password. This can happen when a user visits a website that sends a special request to ...
5.1
OPNsense: Unauthenticated Attackers Can Inject Malicious Scripts via Mailserver Input
CVE-2019-25375
OPNsense 19.1 has a security flaw that lets attackers inject malicious code into users' browsers without needing a password. This can happen when an attacker sends a specific type of request to the sy...
5.1
OPNsense 19.1 Allows Malicious Script Injection via VPN Settings
CVE-2019-25374
OPNsense 19.1 has a security weakness that lets hackers inject malicious scripts into users' web browsers. This can happen when an attacker sends a specific type of request to the OPNsense web interfa...
5.1
OPNsense 19.1: Malicious scripts can be injected via traceroute input
CVE-2019-25372
OPNsense 19.1 has a weakness that allows hackers to inject malicious code into a user's web browser. This can happen when a user visits a specially crafted website or clicks a link. To fix this, updat...
5.1
OPNsense 19.1 allows attackers to inject malicious scripts in users' browsers
CVE-2019-25371
OPNsense 19.1 has a security flaw that lets hackers inject malicious code into users' browsers through the diag_ping.php page. This could allow them to steal sensitive information or take control of u...
5.1